-
Notifications
You must be signed in to change notification settings - Fork 281
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Is opendistro GDPR compliant? #4
Comments
Hi @pavolloffay Open Distro for Elasticsearch Security provides a variety of security tools like encryption in transit, role based access control at the index, document, and field-level. It also provides an audit logging feature to track access to your cluster and log security and compliance related events. It is up to the user to configure their cluster correctly for GDPR, but the security plugin provides tools to help meet compliance. |
thanks @elfisher. To be honest I do not know what exactly is required for GDPR compliance. As GDPR probably requires more "checkboxes" it would be helpful to provide more documentation how each requirements can be met with opendistro. At the moment I found only this https://opendistro.github.io/for-elasticsearch/features/security.html |
It's important to note that even SearchGuard does not make you GDPR compliant, but it helps with some of the requirements. There's a lot more than just RBAC, Auditing, and Encryption that are required to be compliant. At a high level, many of the core functions of RBAC, Auditing, and Encryption appear to be in Open Distro for Elasticsearch that help with being compliant for GDPR. |
@pavolloffay Thanks for opening this issue. As there isn't a direct issue or feature request for the project, I'm going to go ahead and close the issue. Thanks. |
Moved test: - SecurityConfigApiActionTest into ConfigRestApiIntegrationTest Test with the Legacy prefix removed since new tests use randomization for paths Signed-off-by: Andrey Pleskach <[email protected]>
Moved test: - SecurityConfigApiActionTest into ConfigRestApiIntegrationTest Test with the Legacy prefix removed since new tests use randomization for paths Signed-off-by: Andrey Pleskach <[email protected]>
Moved test: - SecurityConfigApiActionTest into ConfigRestApiIntegrationTest Test with the Legacy prefix removed since new tests use randomization for paths Signed-off-by: Andrey Pleskach <[email protected]>
Moved test: - SecurityConfigApiActionTest into ConfigRestApiIntegrationTest Test with the Legacy prefix removed since new tests use randomization for paths Signed-off-by: Andrey Pleskach <[email protected]>
Hi,
is Opendistro fully GDPR compliant like SearchGuard https://search-guard.com/gdpr-compliance-elasticsearch?
The text was updated successfully, but these errors were encountered: