Hi,
we are planning to use a number of the Marketplace applications and I found that most of the applications require full View & Edit & Delete & Admin access to the whole subscription data.
There are several issues with this and I'm asking to understand how Atlassian customers deal with the following:
1. Data preservation.
Jira Software does not have a concept of a recycle bin. Delete operation destroys the data immediately and for good. Everybody seem to have a workaround by denying users 'delete' operation and replacing it with the new 'recycle bin' state. That is bearable. Until we connect a marketplace application that demands 'delete' permission. Now we are at a mercy of the 3rd-party developers, hoping they do not introduce a bug that would accidentally wipe out the data from our subscription.
2. Access limits.
We take care to carefully set up the access per user group so that people see what they need to and nothing more. And then we need to give the full access to all the data to some external application, with which we are supposed to conduct a separate business, validate their EULA is ok with our business requirements etc.
3. Admin audit.
There are limits on what is written in the audit log of the Jira Software. Namely, not all administrative operations on user access are marked with the specific administrator name. There is even Jira issue on this, exists for several years.
How do we monitor the admin activity by these marketplace applications on our subscription?
4. Applications security.
The most popular test management marketplace application does not have its security self-assessment complete. What do you do in this case? Are we supposed to trust the vendor that does not do even self-assessment? They have tens of thousands of downloads. Is this ok with everyone or people just do not care or what?
5. Marketplace applications vulnerability mitigation and remediation.
This is described in Security Bug Fix Policy For Marketplace Apps.
"Cloud apps are expected to fix critical vulnerabilities within 4 weeks of being reported or triaged."
This does not comply with the BINDING OPERATIONAL DIRECTIVE 19-02 - VULNERABILITY REMEDIATION REQUIREMENTS FOR INTERNET-ACCESSIBLE SYSTEMS https://www.cisa.gov/binding-operational-directive-19-02 which allows 15 days for remediation of the critical severity vulnerabilities
How does this work for compliance sensitive customers?
6. Data residency.
Data stored and operated by the Marketplace Applications is not pined to specific location.
https://support.atlassian.com/security-and-access-policies/docs/understand-data-residency/
Given we the Marketplace Applications require full access to the all the data in our subscription, it follows that the none of the data is guaranteed not to leave the customer designated location.
What am I missing here?
The above issues are of a concern for me and I welcome thoughts and clarifications from the customers and the Atlassian producers.
Thank you!