Do Jira products, specifically software, confluence, and service desk comply with Center of Internet Security hardening standards?
CIS Benchmarks focus on operating systems and not specifically applications. Atlassian historically has taken a dim view on stating that their products meet these type of guidelines or compliances. I believe the major reason is that the tools are very extensible and can be configured to meet the requirements of whatever compliance you need them to. It's also possible to configure them in a manner that would not meet even basic security best practices.
Dave,
Thanks for the information. Our security team requested this confirmation. CIS hardening is not required, it just means I need to fill in the details of each standard manually.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
unsure of the precise answer here but will share this link so you can review for yourself. Atlassian Security
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.