Skip to content

Atlassian data sharing & exposure security checks

External sharing, public links, guest access, retention and data-protection settings that quietly push company data outside the tenant.

On Atlassian, Black Cat runs 6 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the Atlassian connector needs.

Checks (6)

severity: high Jira Project Public Access fix difficulty: easy #

Restrict Jira project visibility from public to private

  1. Open the Jira project settings
  2. Navigate to Access > Permissions
  3. Change project visibility from public to private

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.12 SOC 2 Type II CC6.7 CIS Controls v8 CIS-03.1 NIST CSF 2.0 PR.DS-01 GDPR (SaaS Security) GDPR-44.1 HIPAA (SaaS Security) HIPAA-308.a4 NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.12

severity: high Confluence Space Anonymous Access fix difficulty: easy #

Disable anonymous access to Confluence spaces

  1. Open the Confluence space settings
  2. Navigate to Permissions
  3. Disable anonymous access

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.12 SOC 2 Type II CC6.7 CIS Controls v8 CIS-03.1 NIST CSF 2.0 PR.DS-01 GDPR (SaaS Security) GDPR-44.1 HIPAA (SaaS Security) HIPAA-308.a4 NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.12

Disable public link sharing for Confluence spaces

  1. Open the Confluence space settings
  2. Navigate to Permissions > Public links
  3. Disable public link sharing

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.12 SOC 2 Type II CC6.7 CIS Controls v8 CIS-03.1 NIST CSF 2.0 PR.DS-01 GDPR (SaaS Security) GDPR-44.1 HIPAA (SaaS Security) HIPAA-308.a4 NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.12

severity: medium Jira Project Externally Shared fix difficulty: medium #

Review and disable external sharing on Jira projects that do not require outside access

  1. Open the Jira project and navigate to Project settings
  2. Go to Access > Permissions or Sharing settings
  3. Identify who outside the organization has access
  4. Remove external access if not explicitly required
  5. If external access is needed, document the business justification and review regularly

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.12 SOC 2 Type II CC6.7 NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.12

severity: medium Confluence Space Externally Shared fix difficulty: medium #

Review and disable external sharing on Confluence spaces that do not require outside access

  1. Open the Confluence space and navigate to Space settings > Permissions
  2. Review which external users or groups have access
  3. Remove external permissions for users who no longer need access
  4. If external access is required, restrict it to the minimum necessary pages or sections
  5. Document the business justification and schedule a quarterly review

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.12 SOC 2 Type II CC6.7 NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.12

severity: medium Archived Confluence Space With Anonymous Access fix difficulty: easy #

Disable anonymous access on archived Confluence spaces to prevent unintended data exposure

  1. Open the Confluence space and navigate to Space settings > Permissions
  2. Disable anonymous access for the archived space
  3. Verify the space content is no longer publicly accessible

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.12

More Atlassian checks

The information on this page is provided for general informational purposes and is believed to be accurate as of its most recent update. Product names, logos, and trademarks are the property of their respective owners and are used for identification purposes only; their use does not imply any affiliation with or endorsement by those owners. Descriptions of third-party applications and of compliance frameworks are based on publicly available documentation and may change over time.

See these checks run on your stack

Start a free 14-day trial — no credit card required.

Start Free Trial