Come for the products,
stay for the community

The Atlassian Community can help you and your team get more value out of Atlassian products and practices.

Atlassian Community about banner
4,369,088
Community Members
 
Community Events
168
Community Groups

Letters of Assessment Announcement - October 2021

Tanvir Ahmed Atlassian Team Oct 24, 2021

Atlassian primarily relies on our Atlassian Bug Bounty Program and our own internal testing by our Security Engineers to test and identify security issues or vulnerabilities in our Products and Services. However, on occasion, we do work with expert security testing companies to test targeted portions of our environment based on new development, change in features or functionality, or broad changes in platform or Product architecture.

We have published our thinking regarding the differences in penetration tests versus vulnerability assessments versus a bug bounty program on our Approach to Security Testing page on our Trust Center.

Similar to our previous Letters of Assessments post in June 2021, we are publishing more Letter of Assessments from our recent engagements. We utilized specialist security consultancies for a number of targeted assessment, which we have posted for you to review. You can review each of the Letters of Assessment from our consultancies to review scope, dates performed, and methodology used. We do not, however, post any results or vulnerabilities identified as a result of each assessment. For many customers, these reports can take the place of a penetration test report, and shows that we are actively identifying and managing security issues that may be present in our products or services.

Any security vulnerabilities identified in the tests are tracked in our internal Jira as they come through testing process and are closed according to the SLA timelines noted on our Security Bug Fix Policy.

New Letters of Assessment (LoA) include:

1 comment

M Amine Community Leader Nov 22, 2021

thank you @Tanvir Ahmed for sharing these info

Comment

Log in or Sign up to comment
TAGS

Atlassian Community Events