Paramount DLP Lens
por Paramount Computer Systems LLC
Purview DLP risk analysis and remediation agent.
Paramount DLP Lens
Agent Tasks: What work does the agent perform?
The agent is an automation solution built on Microsoft Security Copilot designed to streamline the analysis of data loss incidents. Its primary tasks include:
- Automated Incident Analysis: Processes Critical and High-severity DLP violations using natural language prompts.
- Data Correlation: Automatically links DLP incident data with user risk profiles from Entra ID to identify repeat offenders.
- Risk Assessment: Analyzes sensitive data types (e.g., Credit Card Numbers, Emirates IDs, IP addresses etc.) and identifies the volume of exposed data.
- Compliance Mapping: Maps incidents to regulatory frameworks like GDPR or PCI DSS.
- Policy Gap Identification: Analyzes uncovered data types and recommends missing DLP policies.
- Remediation Guidance: Generates step-by-step investigation playbooks and immediate containment steps.
Input: What data does it take in?
The agent operates within the Microsoft security ecosystem and requires the following inputs:
- User Prompts: Natural language instructions specifying date ranges, severity levels, or incident types (e.g., "Analyze critical violations from the past 30 days").
- Microsoft Purview Data: Direct read access to DLP incident data, including file names, destinations, and external recipients.
- Microsoft Entra ID Data: User information used for risk profiling and identifying high-risk users.
- Credentials: Authorization credentials provided during the first-time setup.
Output: What actions and information does it return?
The agent generates a comprehensive, executive-ready written report that includes:
- Executive Summaries: Non-technical metrics, compliance impact assessments, and notable security gaps.
- Detailed Incident Tables: Sortable data featuring risk scores, involved users, policies triggered, and data destinations.
- Investigation Playbooks: Standardized, step-by-step procedures for responding to triggered incidents.
- Automation Templates: Ready-to-use PowerShell commands, Graph API commands, and KQL queries for rapid remediation.
- Communication Templates: Pre-built notification drafts for users, managers and executives.
- Regulatory Guidance: Breach notification guidance and audit-ready documentation.