Security Incident Response
Suspected security issues should be reported to Mederak Apps Service Desk. Include "Security report" in the request summary when possible.
What to include
- Summary of the issue.
- Steps to reproduce.
- Potential impact.
- Affected Jira site or app version, if known.
- Any screenshots or proof-of-concept material that can be shared safely.
Internal handling process
- Acknowledge the report.
- Open an internal security ticket and assign an owner.
- Triage severity based on exploitability, data impact, customer impact and availability impact.
- Contain the issue if active exploitation or data exposure is suspected.
- Develop and test a fix or mitigation.
- Release the fix through the Atlassian Marketplace and Forge deployment process.
- Notify affected customers and Atlassian when required.
- Complete a post-incident review for material incidents.
Customer notification
If a confirmed security incident affects customer data, we will notify affected customers without undue delay and provide information that is reasonably available, including the nature of the incident, affected data categories, mitigation steps and customer actions where needed.