Atlassian data sharing & exposure security checks
External sharing, public links, guest access, retention and data-protection settings that quietly push company data outside the tenant.
On Atlassian, Black Cat runs 6 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the Atlassian connector needs.
Checks (6)
severity: high Jira Project Public Access fix difficulty: easy #
Restrict Jira project visibility from public to private
- Open the Jira project settings
- Navigate to Access > Permissions
- Change project visibility from public to private
Satisfies: ISO 27001:2022 A.8.12 SOC 2 Type II CC6.7 CIS Controls v8 CIS-03.1 NIST CSF 2.0 PR.DS-01 GDPR (SaaS Security) GDPR-44.1 HIPAA (SaaS Security) HIPAA-308.a4 NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.12
severity: high Confluence Space Anonymous Access fix difficulty: easy #
Disable anonymous access to Confluence spaces
- Open the Confluence space settings
- Navigate to Permissions
- Disable anonymous access
Satisfies: ISO 27001:2022 A.8.12 SOC 2 Type II CC6.7 CIS Controls v8 CIS-03.1 NIST CSF 2.0 PR.DS-01 GDPR (SaaS Security) GDPR-44.1 HIPAA (SaaS Security) HIPAA-308.a4 NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.12
severity: medium Confluence Space Public Links fix difficulty: easy #
Disable public link sharing for Confluence spaces
- Open the Confluence space settings
- Navigate to Permissions > Public links
- Disable public link sharing
Satisfies: ISO 27001:2022 A.8.12 SOC 2 Type II CC6.7 CIS Controls v8 CIS-03.1 NIST CSF 2.0 PR.DS-01 GDPR (SaaS Security) GDPR-44.1 HIPAA (SaaS Security) HIPAA-308.a4 NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.12
severity: medium Jira Project Externally Shared fix difficulty: medium #
Review and disable external sharing on Jira projects that do not require outside access
- Open the Jira project and navigate to Project settings
- Go to Access > Permissions or Sharing settings
- Identify who outside the organization has access
- Remove external access if not explicitly required
- If external access is needed, document the business justification and review regularly
Satisfies: ISO 27001:2022 A.8.12 SOC 2 Type II CC6.7 NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.12
severity: medium Confluence Space Externally Shared fix difficulty: medium #
Review and disable external sharing on Confluence spaces that do not require outside access
- Open the Confluence space and navigate to Space settings > Permissions
- Review which external users or groups have access
- Remove external permissions for users who no longer need access
- If external access is required, restrict it to the minimum necessary pages or sections
- Document the business justification and schedule a quarterly review
Satisfies: ISO 27001:2022 A.8.12 SOC 2 Type II CC6.7 NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.12
severity: medium Archived Confluence Space With Anonymous Access fix difficulty: easy #
Disable anonymous access on archived Confluence spaces to prevent unintended data exposure
- Open the Confluence space and navigate to Space settings > Permissions
- Disable anonymous access for the archived space
- Verify the space content is no longer publicly accessible
Satisfies: NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.12