Hi all, I have several question, and these questions concern both Confluence Server and SaaS solution.
We need to choose a wiki solution and, functionnaly, we would like to choose Confluence. But our CISO ask a lot of questions that we need to answer :
1.1. HOW CONFLUENCE DEALS WITH ACCESS CONTROL ?
Only via a user / pwd connection?
Is there a way to connect to our internal directory?
Is there possibility to control by IP source?
1.2. DATA DIVISION
How is the data partitioned?
Is there a tenant management?
We would like to have a secure access for our whole organization (Digital Branch of the Post Office).
1.3. RIGHTS MANAGEMENT
How are managed data access permissions?
We need three kind of accesses :
• Public pages: accessible to anyone having the URL
This concerns user manuals that can be accessed by the general public.
• Internal Pages La Poste: information that we want to share in our organisation, but not with the whole world, for example, business information: road map, product quality
• Internal project pages: data such as technical specifications, internal procedures, ... only accessible for the project team
1.4. ACCESS TO DATA BY THE HOST (Atlassian or the host in case of on premisce)How can we ensure that the data is not accessible by the host?
1.5 SERVICE AVAILABILITY
What are the SLAs for service availability?
How (for the server solution) can we guarantee high availability (server cluster, etc ...)
1.6. INTEGRITY OF STORED DATA
Does Atlassian guarantee that it does not modify data, either during transport or when the transformation operations are performed on the servers (either on-site or on the SaaS solution)
1.7. ACTIONS LOGGING
Are actions on Confluence logged? If yes, can we access these traces and how ?
Similarly, are system operation logged? If yes, is there an access?
Thank you for your answers