Hi all,
Our company is considering an Internet facing deployment of Jira. While I have read various articles including the best practices guides on the Atlassian and other web sites, I am wondering whether I should be considering 3rd party products to implement a layered security approach.
I notice from the web site that this software is deployed by quite a few multinationals and I cannot imagine, even for an internal deployment, there are relying 100% on the Jira application to ensure the security of the information in the portal.
Two things that come to mind to implement this approach are:
- Web Application Firewall (WAF)
- Identity Management solution integrated with the WAF and Jira
What have other users done?
Are there any recommendations on these? What works well? Not so well?
Thanks,
Paul