Regarding ISO compliance (ISO 27002, 9.4.5.f), there is a question if all access to program source libraries is logged. Is there a log, or way to enable a log, that tracks user access to source code repositories within Bitbucket Server (v 6.1)?
Hello Jon,
Atlassian takes compliance very seriously. With this said, we’re always reviewing and adding to our compliance portfolio. Further information about Atlassian compliance may be found at Atlassian Compliance.
Within that page there is a subsection which mentioned ISO 27002, it reports the following:
ISO/IEC 27018 is a code of practice that focuses on protection of personal data in the cloud. It is based on the information security standard ISO/IEC 27002 and provides additional implementation guidance for ISO/IEC 27002 controls applicable to public cloud Personally Identifiable Information (PII). It also provides a set of additional controls and associated guidance intended to address public cloud PII protection requirements not addressed by the existing ISO/IEC 27002 control set.
The scope is Atlassian Cloud offerings Jira Cloud, Confluence Cloud and Bitbucket Cloud including the micro services used to deliver these applications. Also Corporate functions including Legal, Talent, Policy, Privacy, Procurement, Risk & Compliance, Security, Workplace Experience and Workplace Technology teams.
View the Atlassian ISO/IEC 27018 Certificate
I hope this information proves helpful and you’re able to locate what you need to satisfy compliance.
Regards,
Stephen Sifers
Online forums and learning are now in one easy-to-use experience.
By continuing, you accept the updated Community Terms of Use and acknowledge the Privacy Policy. Your public name, photo, and achievements may be publicly visible and available in search engines.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.