Do Jira products, specifically software, confluence, and service desk comply with Center of Internet Security hardening standards?
unsure of the precise answer here but will share this link so you can review for yourself. Atlassian Security
CIS Benchmarks focus on operating systems and not specifically applications. Atlassian historically has taken a dim view on stating that their products meet these type of guidelines or compliances. I believe the major reason is that the tools are very extensible and can be configured to meet the requirements of whatever compliance you need them to. It's also possible to configure them in a manner that would not meet even basic security best practices.
Thanks for the link. I'll look through it.
Dave,
Thanks for the information. Our security team requested this confirmation. CIS hardening is not required, it just means I need to fill in the details of each standard manually.
It looks like you're new here. Sign in or register to get started.