
Summary
The rule `Notion.Workspace.Public.Page.Added` detects when a page within a Notion workspace is set to public. This action is significant for data security as it potentially exposes sensitive information to unintended audiences. The log type employed for this detection is `Notion.AuditLogs`, specifically monitoring events tied to changes in workspace settings. The rule triggers upon detecting a public page addition, with a deduplication period of 60 minutes, ensuring that multiple identical events do not clutter the logs. The severity level for this event is set to 'Info', indicating that while it should be monitored, it does not necessarily indicate a breach or urgent action is required. By consulting the specified runbook, security personnel can follow a defined process for reviewing the public page's context and purpose. The reference link provides guidelines on Notion's policies around public pages, underscoring the importance of verifying such changes.
Categories
- Cloud
- Web
- Application
Data Sources
- User Account
- Application Log
- Network Traffic
Created: 2023-06-15