Manage policy versions and lifecycle
Information protection policies give you a rule-based way to detect sensitive data in Jira and Confluence, so you can take action automatically or manually.
Who can do this? |
You can manage and adjust your information protection policies as your organization’s requirements change. Review earlier versions, update the configuration, and choose whether a version is monitored, active, or inactive.
A policy’s version is a record of its configuration. A policy’s state determines whether that configuration is checked and applied.
When you edit and save a configuration change, it creates a new version. Changing a version’s state doesn’t create a new version.
Only one version of a policy can be active at a time. Other versions can be in a different state, including monitored. For example, one version of the policy may be Monitored, another may be Active, and many more may be in Draft.
View policy versions
The first saved configuration is your version 1. Saving later configuration changes automatically creates the next version — you don’t need to manually create versions.
To view a policy’s versions:
Go to Atlassian Administration. Select your organization if you have more than one.
Select Security policies, then Policies.
For the policy, select More actions (), then Manage versions.
Review the version number, state, and last-updated information for each version.
The version history helps you identify the configuration to review, edit, monitor, or activate. Available actions depend on the version’s current state.
Edit a policy
Review and test configuration changes before activating them, especially if the policy automatically redacts content.
To edit a policy:
Go to Atlassian Administration. Select your organization if you have more than one.
Select Security policies, then Policies.
For the policy, select More actions (), then Edit.
Update the scope, exclusions, conditions, or control.
Select Save and Monitor to test the updated configuration without applying its control. Saving the changes creates a new version.
Review its matches and tune the configuration before activating it. Create and test an information protection policy
Check the version history after saving to confirm which version is active and which is monitored. Saving a monitored version doesn’t override an already active version.
Change the state of a version
Update a policy’s state to test, enforce, or stop running a configuration, without editing it.
To change a version’s state:
Go to Atlassian Administration. Select your organization if you have more than one.
Select Security policies, then Policies.
For the policy, select More actions (), then Manage versions.
For the version you want to change, select More actions ().
Select the best state for your goal:
Monitor to evaluate the version and record matches without applying its control.
Activate to enforce the version’s configured control.
Deactivate to stop evaluating and enforcing an active version.
Stop monitoring to stop evaluating a monitored version.
Check the version’s state in the version history. Changing state doesn’t change the version number.
To retire a policy from use, deactivate its active version and stop monitoring any versions you no longer need to evaluate.
Keep in mind: changing the policy’s state won’t restore information that has already been redacted.
More about automatic redaction
Reactivate an earlier version
If an update produces unexpected results, you can reactivate an earlier configuration.
Review its scope, conditions, and control first, and test it in monitoring mode if it hasn’t been validated against your current requirements.
To reactivate an earlier version:
Go to Atlassian Administration. Select your organization if you have more than one.
Select Security policies, then Policies.
For the policy, select More actions (), then Manage versions.
Find the earlier version you want to use.
For that version, select More actions (), then Activate.
Check that the intended version is now Active. Only one version can be active at a time.
Activating an earlier version changes which configuration is enforced; it doesn’t create a new version unless you also edit and save the configuration.
Review ongoing policy activity
Use the policy’s audit events to review monitored matches and investigate policy activity.
To review a policy’s activity:
Go to Atlassian Administration. Select your organization if you have more than one.
Select Security policies, then Policies.
For the policy, select More actions (), then View audit log events.
Review the audit events for the policy.
For policies with Create a violation, use View violations from the policy’s More actions menu to open its filtered violation list.
More on how to review and resolve policy violations
Policies with Redact matching content don’t create violations. Instead their redaction activity is found in the audit log.
More on how to review automatically redacted content
Was this helpful?