---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Get started with DLP Incident Response

# Get started with DLP Incident Response {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Review the following information before you start setting up your Data Loss Prevention Incident Response (DLP IR) application.
{#get-started-with-dlp__table_k2d_1bk_ynb__entry__2}

| Setup task | Description |
|-|-|
| Verify that you have assigned the required ServiceNow AI Platform and DLP roles. | DLP Incident Response supports the following roles: * The administrator (admin) installs the applications from the ServiceNow Store and assigns the DLP administrator (sn_dlir.admin). * sn_dlir.admin * sn_dlir.analyst {#get-started-with-dlp__ul_qrb_3ck_ynb} |
| Verify that the ServiceNow core applications that are required to support the Data Loss Prevention Incident Response application are installed and activated. | The Data Loss Prevention Incident Response plugin (com.snc.data_loss_incident) is required to support the Data Loss Prevention Incident Response product. Verify that the following Security Operations applications are installed and activated from the ServiceNow Store. If not installed, install and activate one application at a time in the following order to ensure a smooth installation: * Data Loss Prevention Incident Response (com.snc.data_loss_incident) * Security Support Common {#get-started-with-dlp__ul_g3f_bmd_yrb} For more information on setting up your ServiceNow AI Platform instance for the integration, see [Get entitlement for a Security Operations product or application](https://servicenow-prod.fluidtopics.net/ZZVMDPCDs~BwBGv0OAhjuA "The first step in installing a Security Operations application is to verify that the application or the product and its associated applications have valid ServiceNow entitlements.") or [Activate a ServiceNow Store application](https://servicenow-prod.fluidtopics.net/RFo48XO5_M32aNft7_tP2A "After an application has been given entitlement, you must activate its dependencies plugin and activate the application. This process also applies to applications downloaded to sub-production instances."). |
| Domain separation | Verify the [Domain separation and DLP Incident Response](https://servicenow-prod.fluidtopics.net/WO1Tvwg8MvWCthGE3UkdyA "You can use domain separation with DLP Incident Response to separate the data, processes, and administrative tasks into logical groupings called domains. You can then control several aspects of this separation, including which users can see and access data.") topic if you intend to separate data, processes, and administrative tasks. |
[Table 1. Checklist]

{#get-started-with-dlp__table_k2d_1bk_ynb}
**Related concepts**   

* [DLP Incident Response overview](https://servicenow-prod.fluidtopics.net/VDXSdzQ_goIzDryNdd6KWg "Learn how you can use the ServiceNow AI Platform and the Data Loss Prevention Incident Response (DLP IR) application. Manage sensitive information for your customers, such as the financial and proprietary data, health records, or social security numbers. Automate the remediation workflows with the DLP Incident Response application.")

