Redact sensitive data from findings
We’re gradually transitioning Guard Detect into Atlassian Administration. We’ll support Guard Detect until the Atlassian Administration experience includes all the same features (and new ones!).
The Findings page in Atlassian Administration is the first step in the transition.
A finding is created when potentially sensitive data is detected. The finding includes an excerpt of the sensitive data to help you investigate. If you determine that the data is sensitive and should not be stored in your Atlassian app, you can choose to redact the data directly from the finding.
When you redact, the sensitive data is deleted and replaced by a solid bar.What happens when data is redacted or deleted from findings?
The only way to restore redacted content or deleted attachments is to use the Guard Detect API, and this must be actioned within 30 days of the redaction. You will need to provide the redaction ID, which is available in your audit log. See API request examples
If you’re spending a lot of time redacting data from findings, consider setting up some information policies to automate redactions.
Who can do this? |
Redact content or delete an attachment from a finding
Redact content from a finding
The data that will be redacted is highlighted in the excerpt.
After redaction, the sensitive data is deleted and replaced with a solid bar.
In Jira, this includes the field where it appeared and in the work item history.
In Confluence, this includes the current version of the Confluence page. You can also choose to delete all the previous versions of the page that contain the finding.
To redact sensitive data from a finding:
アトラシアンの管理に移動します。複数の組織がある場合は、対象の組織を選択します。
Select Security, then Data protection, then Findings.
Select a finding you wish to redact.
Review the highlighted sensitive data and the access logs to see who viewed the content and to determine if the data should be redacted.
[Redact (リダクション)] を選択します。
機密データを含む過去のバージョンも削除するかどうかを確認します。
If sensitive data is detected in an attachment, you'll have the option to Delete attachment.
Delete an attachment from a finding
Findings can't redact sensitive data in an attachment because attachments are files, not editable page content. When an attachment containing sensitive data is detected, you have the option to delete the attachment.
Using a finding to delete an attachment replaces the attachment with a placeholder file. In Confluence, the placeholder file will appear in the current version of the page and any historical versions that contained the sensitive attachment (previous version redaction is currently in beta, so we recommend you check your versions until this is fully available).
To delete an attachment from a finding:
アトラシアンの管理に移動します。複数の組織がある場合は、対象の組織を選択します。
Select Security, then Data protection, then Findings.
Select a finding for a Confluence page with an attachment.
Review the highlighted sensitive data.
Select Delete attachment.
Read through the warning message and confirm when you're ready.
考慮事項
There are a number of things to consider when deciding if redaction is the right remediation option for your organization. It's just one of several ways you could choose to handle sensitive data.
The text highlighted in the finding is the exact text that will be deleted from the current version of the Confluence page. It's not simply masked or sent to the trash.
When you redact sensitive data, it can only be restored through the Guard Detect API for a limited time of 30 days. After 30 days, you cannot restore it. It's not simply masked or sent to the trash.
When you delete an attachment, it can only be restored through the Guard Detect API for a limited time of 30 days. After 30 days, the file is permanently deleted and can't be recovered.
In Confluence, the user who published or updated the Confluence page is notified that sensitive data has been redacted. The notification includes the name of the person who performed the redaction.
In Jira, the user who added the sensitive data to the Jira work item is notified that sensitive data has been redacted. The notification includes the name of the person who performed the redaction.
コンテンツのリダクションを行うのに必要な権限
Redacting in Confluence
An organization admin can redact sensitive data regardless of their app access, space permissions, or page restrictions.
A small amount of context is included in the finding to help you investigate, but you won't be able to view the full content of the item if you don't have permission to do so.
Redacting in Jira
An organization admin must have access to the Jira app that contains the finding. Additionally, if project permissions or issue-level security prevents the admin from seeing the Jira work item, they won't be able to see the sensitive data excerpt or redact the data.
As a workaround, you may want to create an account that can access everything in your Jira apps.
Sensitive attachments can be deleted by an admin regardless of their Jira app access or space permissions.
この内容はお役に立ちましたか?