While detecting malicious attacks is critical for preventing a serious security incident, ensuring internal compliance and upholding security policies are equally critical. This is where Declarations of Policy Violations (DoPV) from Clear NDR provide a powerful solution, offering continuous, real-time oversight of your organization's security posture.
Similar to a Declaration of Compromise (DoC), a DoPV is a high-confidence and high-priority incident detection event in Clear NDR. However, instead of focusing on direct security threats, DoPVs address internal compliance and security policy enforcement. They identify "unauthorized" activities that, while not necessarily malicious, still pose a significant risk to the organization.
The true power of DoPVs lies in their ability to provide security, governance, risk, and compliance personnel with a continuous and real-time understanding of significant policy violations occurring within their organizations. This moves compliance from a periodic audit to an ongoing, dynamic process.
Like DoCs, DoPVs share several fundamental characteristics:
DoPVs can trigger automated responses, just like DoCs. Making API calls, they can integrate with external systems to initiate actions such as:
By providing distinct yet complementary insights, DoPVs, alongside DoCs, create a comprehensive security posture management solution. While DoCs focus on external threats, DoPVs ensure internal adherence to security policies. This dual approach helps organizations bridge the gap between raw network data and actionable security intelligence, transforming security operations into proactive incident management and ensuring both efficiency and effectiveness in modern cybersecurity.
For a more in-depth understanding, read our full Tech Brief on Declarations of Compromise and Declarations of Policy Violations on our website: https://www.stamus-networks.com/hubfs/Library/Documents%20(PDFs)/StamusNetworks-TB-FILTERS-072025-1.pdf
To learn how analysts can pivot from a DoC to a complete package of evidence in two clicks, check out this blog entitled “Two Clicks to Evidence,” here: https://www.stamus-networks.com/blog/reduce-mean-time-to-detection-2-clicks-to-evidence-with-clear-ndr
To understand how Clear NDR can dramatically reduce the costs associated with retaining network forensic evidence, read these two docs: