Automatic removal of sensitive information added to Jira

Gabriel Ben-harosh Hasson May 20, 2021

We are implementing Jira data center and I have a question about managing sensitive information.

Our security team raised a concern regarding internal users adding sensitive customers information to Jira issues, mainly via attachments. For example attaching a MS Excel file with multiple customers information to a Jira issue.

Is there a way to scan (internally or externally to Jira) attachments for sensitive information and automatically remove these attachments?

Thanks,
Gabriel

1 answer

1 accepted

3 votes
Answer accepted
Mirek
Community Leader
Community Leader
Community Leaders are connectors, ambassadors, and mentors. On the online community, they serve as thought leaders, product experts, and moderators.
May 20, 2021

Well nothing really can help on Jira side.. Not even think that there would be a plugin for that..

Many security tools scan attachments before those can be uploaded into the system and block them, so if those can scan and search for threats then probably similar method can be used for finding specific data. However this overall might be hard.. What would happen when someone would upload a scan or something that is is not easy to read? Without OCR or things like that it would be not possible..

I think definitively users should be educated that it for sure about managing data and privacy.

Suggest an answer

Log in or Sign up to answer