Created Dec 2, 2020, Last active today
We've been busy as a team working through support efforts for instances affected by recent exploits arising from Confluence vulnerabilities published at: https://confluence.atlassian.com/doc/conflu...
We maintain an always-on bug bounty to identify and triage security issues in our products and services. Many customers ask us for ‘penetration reports’ or similar - basically a report from a third-p...
Hey all, I have a question relating to the side-effects of the mitigation of this Confluence CVE. Specifically, the inability to see thumbnails of attached files after disabling the 'webDAV' pl...
Not too long ago, @Bill Marriott shared some tips for keeping your Atlassian cloud products secure. How do you manage users and maintain security for your Atlassian products? What are som...
Hello! Checking in from the product security team. Most of the time I'll be heads down in our infrastructure or code base, trying to systemically prevent or mitigate security issues. Lately I'...
Hi everyone! I'm Bill Marriott and I run the Trust & Security Program here at Atlassian. I’ve been publishing and answering questions about our overall Trust Program through the Atlassian ...
Hi Atlassian community, I live in Europe and hence my usage of Jira (JSD) needs to be GDPR comliant. According to GDPR you should not send personal information via email (because it is not encrypte...
So, as a FDA regulated company we have to validate off-the-shelf software that we use, with some exceptions. We recently went through an audit and is was brought up that the validation of Jira (writt...
This is the second instalment on how Atlassian manages our risks and compliance obligations using Jira. In Part 1 we created the issue types and the custom fields - now we need to create...
Who am I? My name is Guy Herbert and I am part of the Risk and Compliance team at Atlassian. I have been with Atlassian for about 5 years and have worked in Risk and Compliance for over 25 yea...
This item make little to no sense to me. If it is a public forum/free application then that can make sense but in a corporate environment it makes no sense as there has to be abilities to have r...
With the new single sign on through my.atlassian for all cloud accounts we have run into an issue because we have two separate cloud accounts for two parts of our business. Because the feature set, ...
Chromebleed is telling me our ondemand site is vulnerable to HeartBleed issue. When is this going to get fixed?
The Trust & Security community group is Atlassian's go-to space for all things Security, Compliance, Privacy and more. This group is to share information, tips, and best practices for protecting your data and using Atlassian products in a secure and reliable way.
Copied to clipboard