New Idea
Custom Rules rules engine: need checkbox to suppress emailed Excel data - significant security issue
Posting here for comments from the security team & other SA's at a minimum -
Currently, there's no way to suppress the emailed spreadsheet of an unencrypted data set to the person running the rule - I'm surprised we got this far without InfoSec review issues from one or more of our Jupiter/Venus customers.
I know that a product risk is being opened by Erik Grand for the new customer Carbon Black (and I'm pretty sure it's a blocker for them moving forward with implementation), but I think the priority may be even higher, given that it's just been luck so far that we haven't had to address it already.
We may need a short-term fix to this, at a minimum, where there's a checkbox for the rules engine to disable sending the spreadsheets - and if we add it to the UI for the individual rule, the admin should either be able to set a default, or the default should be "no spreadsheet" and then the user can use a checkbox to receive one for a test run.
Longer term, being able to download test results, or otherwise view on screen, would be the way to go, I'd assume.
I'll let others chime in, but wanted to get this started for wider discussion and prioritization beyond the product risk being opened. Thank you!
Currently, there's no way to suppress the emailed spreadsheet of an unencrypted data set to the person running the rule - I'm surprised we got this far without InfoSec review issues from one or more of our Jupiter/Venus customers.
I know that a product risk is being opened by Erik Grand for the new customer Carbon Black (and I'm pretty sure it's a blocker for them moving forward with implementation), but I think the priority may be even higher, given that it's just been luck so far that we haven't had to address it already.
We may need a short-term fix to this, at a minimum, where there's a checkbox for the rules engine to disable sending the spreadsheets - and if we add it to the UI for the individual rule, the admin should either be able to set a default, or the default should be "no spreadsheet" and then the user can use a checkbox to receive one for a test run.
Longer term, being able to download test results, or otherwise view on screen, would be the way to go, I'd assume.
I'll let others chime in, but wanted to get this started for wider discussion and prioritization beyond the product risk being opened. Thank you!
Reply
Rich Text Editor, editor1
Editor toolbars
Press ALT 0 for help
Sign up
If you ever had a profile with us, there's no need to create another one.
Don't worry if your email address has since changed, or you can't remember your login, just let us know at community@gainsight.com and we'll help you get started from where you left.
Else, please continue with the registration below.
Welcome to the Gainsight Community
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.