Is there a best practices document from JIRA regarding securing jira cloud instance? To be specific i want to protect my instance from intrusion and want to setup the instance accordingly.
As an end user of the service, all you can do is make sure you do not give access to anyone you don't want using it. Control who you give access to and be careful with your permission schemes, making sure you only grant the right access, and be very wary of giving access to "anyone" (which allows people access without logging in)
Atlassisan handle the server-side aspects of security.
@Nic Brough -Adaptavist- Thanks for the reply. Is there a way to have additional protection in case some one gets/hacks password of a genuine user and intrudes into the system from that.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Depends. What do you want from "additonal protection"?
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
2FA or IP whitelisting or any other intrusion detection/prevention measures.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
You can do 2FA if you move Cloud authentication to an external user directory that supports SAML.
Cloud runs on https, and that's about all of the rest I can tell you without specific guidance on what you're thinking.
Whitelisting and the IDS I've done before, etc - mostly not implemented and you don't get the access you would need to add them yourself.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.