Exclude Code/Credentials in e-mails

Valentin Peralta May 19, 2021

Hello,

What is the best way to hide/exclude sensitive information from JIRA emails (ticket updates, etc)? It's a security liability to include stuff like keys, code, passwords, etc. on emails; but I don't know what can be done to avoid this issue without disabling email notifications.

1 answer

1 vote
Nic Brough -Adaptavist-
Community Leader
Community Leader
Community Leaders are connectors, ambassadors, and mentors. On the online community, they serve as thought leaders, product experts, and moderators.
May 19, 2021

There's no code for doing that in Jira, because there's no way to tell it information is sensitive (other than to use simple security to protect the entire issue)

You're looking at the wrong part of the problem though.  There is no real technical solution, and if your people are putting sensitive information into Jira, you have to assume it's compromised already.

The real solution is to get your people to stop publishing it in Jira.  You actually have a security issue here, and it needs to be fixed by prevention, not "closing the door after the horse has bolted"

Payne
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Leaders.
May 19, 2021

Our organization had a small problem with help desk staff putting passwords in issues, and we resolved it exactly as you state, simply by user education. Not only should information like that not go out in emails, the topic of the original poster's question, but further, it should not be in Jira, period, where many more eyes than are necessary have access to that information.

Suggest an answer

Log in or Sign up to answer
DEPLOYMENT TYPE
CLOUD
PRODUCT PLAN
PREMIUM
PERMISSIONS LEVEL
Site Admin
TAGS
AUG Leaders

Atlassian Community Events