Data Controls for reporting/integration purposes

This is probably a pet peeve of mine - how do we control what data people can get out of BigFix without giving them “too much” (i.e. sensitive data they shouldn’t have). Years ago I pushed and got the Web Reports Blacklisting released (Yea, you probably haven’t even heard what that is because it was always released a bit on the side without much visibility to it) but it has been something that at least offered some functionality around it (we’ve been using it for quite a few years now) but now a lot more interfaces/integrations are coming and I went back to submit the idea officially again, as similar type of control needs to be implemented across all of them in my opinion. If you agree, please share.

4 Likes

Nice idea, I voted for it!

I completely agree this is something BigFix should support across all reporting interfaces, REST API, and future integrations.

We often assume that anything behind the corporate firewall is already secure, but sometimes issues come from inside the organization, whether it's a compromised account, someone having more access than they really need, or simply accidental data exposure. That's why giving people access to only the data they actually need is always a good practice.

Of course, no security control is perfect, and Master Operators or administrators will always need broader access. But being able to control which properties, analyses, or data sets different roles can see would go a long way in reducing unnecessary exposure of sensitive information.

It won't solve every security concern, but it's definitely another layer of protection, and I fully support it.

1 Like