Focus
Focus
Table of Contents

Close Incidents

Close one incident at a time or use Bulk Incident to close multiple incidents at once on Data Security.
With automatic remediation, Data Security performs appropriate actions and updates the category and status for incidents matching a data pattern. For other open incidents, Data Security identifies these open incidents as New.
When you assess new incidents, you might sometimes find the content of an asset or how the asset is shared does not pose a threat to your organization. In these cases, you can close the incident individually or close a group of incidents. You can select a default close (denoted by a red icon) Status category. Additionally, you can customize the incident categories to create close incident categories to suit your organization’s needs.
Data Security identified the asset as an incident because it matched one or more policy rules. Unless you change a setting (for example, changing a collaborator or domain from Untrusted or Trusted), Data Security identifies the asset as an incident again the next time it scans that asset. You should fine-tune the policy rules to ensure assets that are real threats are the only assets identified as incidents.
If you want to review the events recorded when the status of an incident closes, inspect the remediation activity logs.
Incidents are automatically closed when assets associated with them are deleted from the Office 365 and Box applications.
  • To close a group of incidents or a single incident, go to Data SecurityIncidents.
    1. Select up to 1000 incidents.
    2. Click ActionsChange Status. If you want to change the status of a single incident, you can also click on the vertical ellipses menu against the item at the right and perform the same step.
    3. Select a close Status.