What is an information protection policy?

Who can do this?
Role: Organization admin, Guard Detect admin
Atlassian Cloud: Atlassian Guard Premium
Atlassian Government Cloud: Available

Information protection policies give you a rules-based way to detect sensitive data in Jira and Confluence, so you can take action automatically or manually.

This empowers you to delegate certain policies to run from detection to redaction autonomously, once you’re confident the matches found meet your requirements.

Every policy is configured to suit a specific criteria with a certain focus. This means many policies can run in parallel without the risk of diluting audit logs or confusing the chosen action.

How information protection policies work

Information protection policies are triggered by specific actions in your organization, site, or app. For example, when a Jira work item or Confluence page is created or updated, Atlassian Guard will evaluate every Active policy, in almost real-time.

If a policy finds matching data, your chosen action will run. The policy finding and action is then written to the audit log. If there are multiple policies seeking the same sensitive data, a policy that automatically redacts content will take precedence over one that creates a violation. If the actions match, the violation will be added to the audit log for each policy, or redacted.

States of a policy

You can transition a policy through different states as you get clearer on its requirements. Move back and forth between these states as you like. These are the available states:

State

What happens

When to use

Draft

The policy configuration is saved but isn’t checked or enforced.

Perfect for exploration. Stick to this state while you work out your configuration.

Monitored

The policy is evaluated when content changes. Matches are recorded in the audit log, but the policy doesn’t create violations or redact content.

Great when you want to understand how your policy functions and tune the details.

Active

The policy is checked and applies its control when conditions are met.

Ideal when your policy is working as you’d planned.

Whenever you edit and save a draft, a new version of that policy is generated so you can always return to a previous iteration.

Any version of a policy can become the active policy, but you can only have one active version at a time. For example, you might have 11 versions of one policy. Version 11 is active, which means all other 10 versions are not-active, and either in the draft or monitored state.


Understand how to build a policy

When you set up a policy, you’ll make a few key decisions:

  • Where the policy applies. You can set up a policy to scan your entire organization, specific sites within your organization, or your selection of apps. You can also choose if there are certain locations where the policy does not apply.

  • What information to detect. You’ll decide how the condition operates, then what information is being detected. This is a predefined list to include common, sensitive information like credit card numbers, IP addresses, passwords, and more.

  • How to respond when a policy finds a match. You can either create a violation for an admin to review, or automatically redact the matching information.

How to build an information protection policy

 

Still need help?

The Atlassian Community is here for you.