Security Questions and how Azure DevOps for Jira works

  Рет қаралды 25

Move Work Forward

Move Work Forward

Ай бұрын

Check out Azure DevOps for Jira by Move Work Forward security deep dive.
Guide: help.moveworkforward.com/azur...
Azure DevOps for Jira app: marketplace.atlassian.com/app...
Azure DevOps for Jira by Move Work Forward
e-Cyber Security Questions
Q: Is data stored outside of Atlassian products?
A: We store the Personal Access Token and some metadata in our encrypted storage.
Q: Which data can this app read/write?
A: Currently, Azure DevOps for Jira needs the following read-only scopes for the Personal Access Token - Code, Build, Release. The global configuration permissions does not write anything. The only write option available is for the end user from the Jira issue view when a feature branch is created. For this operation, the end-user needs to login with his/her Azure DevOps credentials.
Q: Are there additional compliance certifications?
A: Move Work Forward is SOC 2 Type II Compliance. You can learn more in our Trust Center provided by Vanta - trust.moveworkforward.com/
Additionally, we participate in Cloud Fortified and Bug Bounty programs.
Q: Is DPA available?
A: Yes, www.moveworkforward.com/licen... is the draft and we need to sign it with each company separately. You can find the link in the footer of our website.
Q: What is the classification of data involved?
A: We query or receive via subscriptions/webhooks payloads from Microsoft that pay contain user data. It is the data about pushes, pull requests, branches and pipeline runs. It passes our system, so it can be logged in AWS Cloud Watch (we have 7 days retention).
Q: Who is data owner / data controller / data processor?
A: We are the data processor.
Q: Accesses via which devices: mobile devices, private devices, company devices?
A: As of 14 Jun 2024, only 3 people have production access from company laptops. We adhere to all SOC 2 Type II compliance requirements.
Q: Operational concept regarding IT security check. Where are the servers located, subject of firewalls, virus scanners, patch process. What security certifications or security whitepapers can be provided by the vendor (ISO, ..)?
A: Our backend system is in AWS us-east-1 region. It is fully Serverless (AWS Lambda, API Gateway, SQS, DynamoDB). Every employee or contractor uses Vanta to monitor his/her laptop, we execute reference checks and constant security trainings.
Q: Are there Penetration test results provided by the vendor?
A: We use Bug Crowd Bug Bounty program that employs white-hat hackers to penetrate our apps. We don’t have a public report.
#azuredevops #atlassian #jira #moveworkforward #howto #security

Пікірлер
How to integrate Google Chat for Jira Cloud Demo
5:22
Move Work Forward
Рет қаралды 41
How To Pass ANY Azure Certification in 2024 | Complete Guide
19:00
Travis Media
Рет қаралды 278 М.
I Can't Believe We Did This...
00:38
Stokes Twins
Рет қаралды 104 МЛН
THEY WANTED TO TAKE ALL HIS GOODIES 🍫🥤🍟😂
00:17
OKUNJATA
Рет қаралды 23 МЛН
Can You Draw A PERFECTLY Dotted Line?
00:55
Stokes Twins
Рет қаралды 113 МЛН
Notion Calendar Review | Advanced Calendar for Professionals
7:13
Seamless Integration: Azure DevOps, Jira & Bitbucket
4:12
Move Work Forward
Рет қаралды 151
Cybersecurity Architecture: Application Security
16:36
IBM Technology
Рет қаралды 55 М.
Microsoft Build 2024 Day 1 - Copilot Azure Microsoft 365 GitHub
8:41
Move Work Forward
Рет қаралды 177
How to integrate Azure DevOps and Jira Software to Move Work Forward
3:08
iOS 18 Hands-On: Top 5 Features!
12:47
Marques Brownlee
Рет қаралды 1,4 МЛН
Observability vs. APM vs. Monitoring
9:41
IBM Technology
Рет қаралды 152 М.
Team Hacks: How to work with product feedback
2:15
Move Work Forward
Рет қаралды 187
API vs. SDK: What's the difference?
9:21
IBM Technology
Рет қаралды 1,4 МЛН
Мой инст: denkiselef. Как забрать телефон через экран.
0:54
Красиво, но телефон жаль
0:32
Бесполезные Новости
Рет қаралды 839 М.
АЙФОН 20 С ФУНКЦИЕЙ ВИДЕНИЯ ОГНЯ
0:59
КиноХост
Рет қаралды 428 М.
Samsung Galaxy 🔥 #shorts  #trending #youtubeshorts  #shortvideo ujjawal4u
0:10
Ujjawal4u. 120k Views . 4 hours ago
Рет қаралды 6 МЛН
ОБСЛУЖИЛИ САМЫЙ ГРЯЗНЫЙ ПК
1:00
VA-PC
Рет қаралды 1,9 МЛН