Hi everyone,
I'm Asvini, a Product Manager at Atlassian, currently working on our new Backup and Restore experience, which is now in Open Beta. As we continue to shape the product, we're focused on ensuring it meets the security and compliance standards required by teams—especially those in regulated industries.
To help us better support your needs, we’d love your input on the following:
Does your organization require the Backup and Restore product to be ISO 27001, SOC 2,etc or similarly certified in order to adopt it?
And if certification is missing, would that be a hard blocker for adoption?
If the answer is yes—and certification is a requirement—we’d really appreciate the opportunity to learn more about your specific needs. Feel free to comment here and reach out to me at ar@atlassian.com, and I’ll be happy to set up time for a conversation.
Your feedback will directly shape the direction of our product.
Thank you for helping us build a better experience!
— The Backup and Restore Product Team
Same here. The ISO 27001, SOC 2 certifications make it possible to see at a glance that certain security and compliance standards are met. Alternatively, the contents of the certifications would have to be queried separately from the manufacturer of the software. Therefore, these certifications are mandatory and state-of-the-art for software products and should not be put up for discussion.
Hi Asvini,
thanks for involving the community at an early phase of the development work.
For our company, ISO 27001 and SOC 2 certifications are strictly requirements for the implementation of any software product.
The following is the reason why it is so crucial in our scenario:
We operate a very controlled environment with rigorous InfoSec, data privacy, and compliance requirements. Industry-standard certifications like ISO 27001 and SOC 2 Type II are reassurance that vendors have a formal, auditable approach to information security management and:
Reduce by far the amount of internal assessment and risk assessment effort undertaken in procuring as part of the procurement process
Let our internal audit and risk teams chart vendor compliance to our own policy and controls.
Absent these certifications, we would need to conduct comprehensive custom analysis and would be unable to approve the use of such products in production—making lack of certification a difficult blocker to adoption.
I appreciate the opportunity to share this and would be happy to see the relevant certifications (e.g. ISO 27001, SOC 2 Type II) reflected in the Backup and Restore product in the future, as they are a fundamental requirement for production use in our environment.
Best regards,
Bernd
Hi @Asvini R -- I understand you're focused on ISO 27001 and SOC2 right now. However, if you ever want feedback relating to life science companies (pharma, medtech, etc.) that need a Backup and Restore feature that helps them be compliant with regulations such as 21 CFR Part 11 or industry standards such as ISPE GAMP 5, then I'd love the opportunity to discuss.
Yes, ISO 27001 and SOC2 compliance of the Backup and Restore product will contribute to the customer's regulatory compliance, but there's a bit more to the story.
Looking forward to seeing the new Backup and Restore experience!
Recommended Learning For You
Level up your skills with Atlassian learning
Learning Path
Become an effective Jira admin
Manage global settings and shared configurations called schemes to achieve goals more quickly.
Streamline Jira administration with effective governance
Improve how you administer and maintain Jira and minimize clutter for users and administrators.
Learning Path
Become an effective Jira software project admin
Set up software projects and configure tools and agile boards to meet your team's needs.