The Atlassian Community Forums are currently in read-only mode. We will be relaunching on a new platform on September 22 (read more here). We apologize for the extended downtime. For concerns or questions, please email communitymanagers@atlassian.com. See you on the other side, on the new Atlassian Community Forums! :)

×

Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

JIRA Server - security best practice

Andrew Henders
October 8, 2018

Hello,

I'm running JIRA Software & Service Desk on the same server and am looking at creating a JIRA Service Desk Project that will allow public sign-up.

JIRA Internal Directory is in use.

I'm wanting to mitigate the risk of a public customer being accidentally assigned to a JIRA Group that would give them access to our internal Software and Business projects.

Any suggestions or experiences appreciated.

Thanks,

Andrew

1 answer

1 accepted

Comments for this post are closed

Community moderators have prevented the ability to post new answers.

0 votes
Answer accepted
Nic Brough -Adaptavist-
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Champions.
October 10, 2018

Putting a person in the wrong group is nothing you can mitigate against in software.  A human chose to put them in the wrong group, the human should not have done that.  The computers can only do what they're told.

The suggestions are all around process - record and audit all requests for user changes.  Lock it down where you can (although there's not a lot you can do with the internal directory - you have to trust your admins to get it right).  Regularly report on permissions and who has them.  And make sure your admins are a small team, well trained, well educated on the risks of getting it wrong (and understanding it IS their fault if it fails), and they collaborate tightly.