
Summary
This rule monitors changes in the privacy settings of Asana teams to ensure that they are not inadvertently set to public within the organization. When a team's privacy setting is altered to 'public', this can lead to sensitive information being exposed to unintended users within the organization. The rule logs events where a user sets the privacy level of an Asana team to public, specifically focusing on the actor's details and the context in which the change was made. The rule is triggered by the event category 'access_control' with the event type 'team_privacy_settings_changed'. It is configured to run on Asana audit logs with a severity level classified as low due to the typical controls in place at organizational levels to mitigate such risks. The logging captures the user information, their action, and the previous and new privacy settings to ensure accountability and traceability in such critical permission changes.
Categories
- Cloud
- Application
- Identity Management
Data Sources
- Application Log
- User Account
Created: 2023-02-01