Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

CIS Hardening Standards

Jason Saunders May 16, 2019

Do Jira products, specifically software, confluence, and service desk comply with Center of Internet Security hardening standards?

2 answers

0 votes
Dave Theodore [Coyote Creek Consulting]
Community Champion
May 16, 2019

CIS Benchmarks focus on operating systems and not specifically applications.  Atlassian historically has taken a dim view on stating that their products meet these type of guidelines or compliances.  I believe the major reason is that the tools are very extensible and can be configured to meet the requirements of whatever compliance you need them to. It's also possible to configure them in a manner that would not meet even basic security best practices.

Jason Saunders May 16, 2019

Dave,

Thanks for the information. Our security team requested this confirmation. CIS hardening is not required, it just means I need to fill in the details of each standard manually.

0 votes
Jack Brickey
Community Champion
May 16, 2019

unsure of the precise answer here but will share this link so you can review for yourself. Atlassian Security

Jason Saunders May 16, 2019

Thanks for the link. I'll look through it.

Suggest an answer

Log in or Sign up to answer