Classification Rules
The Logic Behind the Scenes
This application requires you to use groups based on your classification system to control who has access to the issue. The classification needs to appear in the name of the group, and in the format consistent with who the classification will appear in the Banner.
So if you want Top Secret//SCI//REL TO USA to be the classification controlling who gets access to the page, then there needs to be a group created with that in the name, and the user(s) assigned to the group.
If you have already created a security scheme based on those groups, you will be shown in the Setup Up section where to enter that. If one needs to be created for you, this app will do it for you.
Rollup Configuration Rules.
We know you have your own internal rules, but we think our system of determining which level, which compartment(s), and which release(s) go together will fit your rules.- We score the values relative to each other.
- The lower the score, the more restrictive the value.
- Only compartments and releases that can combine together, share the same score.
DISCOVERY
Here is how we do it.
If you already have groups defined in Jira, click the DISCOVER button on the 1.1 configuration page, Data Classification Configuration. We will then do an analysis of your groups based on these steps:
- Require you to enter the classification level into our config section.
- We then search all your existing groups looking for the classification level name and abbreviation
- We group them by level.
- We save off your prefixes and populate the config section with that discovery.
- We then create a list of the unique compartments and releases.
- We look at the combinations those compartments make in the group, as well as the combinations the releases make.
- For those compartments and releases that never combine with any other in their category. They will get a lower score then those compartments and releases that do combine.
- we assign that score to the compartment and release
- We then look to see which compartments only show up for certain levels
- Those that do, get assigned a Level Restriction in our configs.
- Those that don't, that field is left blank.
- Same thing with Releases.
User Selection
We examine what groups a user is in. And then only allow them to select those values they are in a group for. We do that by only displaying the compartments and releases in their groups.Now, you can make combinations from those values that may be different than their groups, so we do a final check before saving that classification. We force them to select a group they belong to so they do not classify the issue to a group they are not read into.