Jira の機密データのリダクションを行う
Attachment scanning functionality is part of an early access program. You may see a difference between the information below and your Guard administration experience.
Guard Detect で機密性の高いデータが検出されると、アラートが送信されます。このアラートには、調査に役立つ機密データの抜粋が含まれています。データが機密扱いで、Jira に保管するべきではないと判断した場合、アラートからデータのリダクションを直接行うことができます。
When you redact, the sensitive data is deleted and replaced by a solid bar. What happens when data is redacted or deleted?
The only way to restore redacted content is to use the Guard Detect API, and this must be actioned within 30 days of the redaction. https://developer.atlassian.com/cloud/guard-detect/developer/api-examples/#restore-redacted-content
Who can do this? |
Redact content or delete an attachment from an alert
Redact content from an alert
リダクションの対象となるデータは、抜粋で赤色でハイライトされます。Jira 作業項目に機密データのインスタンスが複数ある場合は、リダクションを行うインスタンスを選択できます。
アラートから機密データのリダクションを行うには、次の手順に従います。
Guard Detect で、 ヘッダーから [Alerts (アラート )] を選択します。
コンテンツ スキャン アラートに移動します。
ハイライトされた機密データと調査手順を確認して、データのリダクションが必要かどうかを判断します。
[Redact (リダクション)] を選択します。
リダクションを行うインスタンスを選択します。
機密データが削除されます。また、データが表示されていたフィールドと課題履歴では、実線で置き換えられます。この処理には数分かかることがあります。完了したら、お知らせします。
When sensitive data is detected in attachments, you’ll see a Delete attachment option.
機密データの各インスタンスがハイライトされます。このテキストがリダクションの対象となります。アナリストは、いくつかの単語からコンテキストを把握し、データの機密性を判断できます。
[Redact (リダクション)] を選択すると、データのどのインスタンスに対してリダクションを行うかを選択できます。
Delete an attachment from an alert
Guard can’t redact sensitive data in an attachment because attachments are files, not editable page content. When Guard finds an attachment containing sensitive data, you have the option to delete the attachment. This option deletes the attachment and replaces it with a placeholder file on the work item that contained the sensitive attachment.
アラートから機密データのリダクションを行うには、次の手順に従います。
Guard Detect で、 ヘッダーから [Alerts (アラート )] を選択します。
Navigate to a content scanning alert with an attachment.
ハイライトされた機密データと調査手順を確認して、データのリダクションが必要かどうかを判断します。
Select Delete attachment.
Read through the warning message and confirm when you’re ready.
To restore a deleted attachment, use the Guard Detect API within 30 days of its deletion. After that time, it’s permanently deleted.
考慮事項
リダクションが組織にとって適切な修復オプションであるかどうかを判断する際には、いくつかの点を考慮する必要があります。これは、機密データを扱ううえでとり得るいくつかの手段のうちの 1 つにすぎません。
For security reasons, redacted sensitive data and deleted sensitive attachments require extra effort to restore — and is only possible through queries to the Guard Detect API.
アラートの抜粋でハイライトされるテキストは、Jira 作業項目から実際に削除されるものです。
機密データを Jira 作業項目に追加したユーザーには、機密データのリダクションが行われたことが通知されます。通知には、リダクションを行った人の名前が含まれています。
コンテンツのリダクションを行うのに必要な権限
In order to redact sensitive data, the Guard Detect admin must have access to the Jira app instance.
さらに、プロジェクト権限または課題レベルのセキュリティにより、Guard Detect 管理者が Jira 作業項目を見ることができない場合、機密データの抜粋を確認したり、データのリダクションを行ったりすることはできません。
As a workaround, you may want to create an account that can access everything in your Jira apps.
Sensitive attachments can be deleted by a Guard Detect admin regardless of their Jira app access or space permissions.
トラブルシューティング
何らかの理由でリダクション リクエストが失敗した場合は、機密データを手動で削除できます。リダクションが失敗する理由としては次のものがあります。
アイテムに含まれる機密データのインスタンスが多すぎる。
アラートが送信された後に機密データが手動で削除された。
この内容はお役に立ちましたか?