TrustCloud launches Application Assurance: AI-native continuous control monitoring for enterprises. Read more →

Jira Cloud

Estimated reading: 6 minutes 3665 views

Purpose

Once you set up your compliance program, TrustOps works to ensure that your systems remain compliant with your adopted controls. To do so, TrustCloud retrieves lists of resources against systems in your product and business stack to use for compliance evidence.

This document outlines the steps you can take to grant TrustCloud access to retrieve Jira ticket details and use them as evidence.

Set up Jira Cloud for automated tests with TrustCloud

TrustCloud’s API-based integrations map seamlessly to your frameworks and controls to power automated evidence collection, continuous monitoring, and predictive risk analysis. Let’s explore how you can set up Jira Cloud for automated tests.

By granting TrustCloud limited access to metadata through a service principal account, you can ensure that your systems remain compliant with your adopted controls. TrustCloud’s focus on trust, security, and simplifying compliance makes it a valuable asset in the GRC landscape.

Read our GRC Launchpad article: Integrations to learn more.

Explore 100+ evidence collection integrations to power evidence collection and real-time risk analysis.

Instructions to grant TrustCloud limited access to Jira Cloud

  1. Create Jira integration credentials
    1. If you’re using Jira Cloud, please refer steps 2–9 to create connection credentials for your organization
    2. If you’re using Jira Data Center, please refer steps 10–15 to create connection credentials for your organization
  2. Log in to your Jira Cloud instance as a user who has read permission for all the projects and also has access to create an API token in your organization.
  3. Click the gear icon in the upper-right corner of any page.Jira Cloud
  4. Click on ‘Atlassian account settings’.Jira Cloud
  5. In the left sidebar, click on ‘Security’.jira 3 2
  6. On the security page, check the ‘API tokens’ section. Click on ‘Create and Manage API tokens’.API
  7. On the ‘API Tokens’ page, click on the “Create API Token” button.jira 5
  8. On the ‘Create API Token’ dialog, provide a label. Click on the “Create button”.API
  9. Click on the “Copy” button in the ‘Your new API token’ dialogue to copy the generated token to the clipboard. This will be used to set up the Jira Cloud integration.API
  10. Login to your Jira Data Center instance as a user who has read permission for all the projects and also has access to create a personal access token (PAT).
  11. In the upper-right corner of any page, click on the profile icon, then select the Profile tab from within the drop-down menu.
    Jira Cloud
  12. In the Profile page, click on the left sidebar & then select Personal Access Tokens.
    jira 9
  13. In the Personal Access Tokens page, click on the Create token button.
    Jira Cloud
  14. Within the Create a personal access token page:
    1. Provide a Token Name for your token
    2. Uncheck the Automatic expiry checkbox, so the token you create does not expire
    3. Create the token by clicking the Create button.
      Create personal access token
  15. In the New personal access token created dialogue, click the Copy button to copy the generated token to the clipboard. This will be used to set up the Jira Data Center integration.
    Personal access token
  16. Provide your Jira Cloud organization URL or Jira Data Center instance custom domain URL to TrustCloud.
    A Jira Cloud Organization URL can be https://your-organization-name.atlassian.net & a Jira Data Center organization URL will be your custom Jira application domain.
  17. Provide your API Token / PAT to TrustCloud.

Data feeds

TrustCloud’s Hybrid Data Fabric can pull data from various JIRA workflows to help automate conmon of controls. The outcome will be dependent on your business processes, documentation and technical controls that rely on Jira workflows for implementation. To meet such objectives, we can create deeper integrations to pull an inventory and map it to necessary workflows. Below is a sample of control testing that TrustCloud enables with Jira:

  1. Vulnerability Scanning & Remediation

To automate the continuous monitoring of the above control, TrustCloud pulls the following types of data feeds from Jira:

  1. Remediation
  2. AssetRecon

A sample of read-only data elements we pulled from these data feeds.

Read only: Remediation
   - ticket_id
   - vuln_id
   - asset_uuid
   - status
   - created_date
   - resolved_date
   - reviewer
   - reviewer_status
   - review_date
   - qa_check_performed
   - qa_notes

Read only: Asset Recon
   - ticket_id
   - tag_owner
   - status
   - created_date
   - resolved_date

Creating a ticket in Jira

TrustOps tasks can be linked to Jira in two ways. The first is automatic ticket creation, and the other is manual ticket creation.

Creating a Ticket in Jira

TrustOps tasks can be linked to Jira in two ways. The first is automatic ticket creation, and the other is manual ticket creation.

Automatic Ticket Creation

Ticket creation with Jira can be fully automated with TrustOps. Any user can choose to create all their tasks automatically in Jira. To create a ticket in Jira automatically, you need to change a few settings. Once this setting is enabled, any task that is assigned to a particular user will be created in Jira.

To enable automatic ticket creation

    1. Go to your TrustCloud program.
    2. Go to “Integrations” from the left-hand side menu.
    3. Select “Connected Apps.”
    4. Navigate to the “Task Management” section to configure automatically creating tickets in Jira for selected projects.
      The following screenshot shows the task management Jira configuration.
      TC task management Jira
    5. Click on the “Configure” button.
    6. Select Project, Issue Type, Epic, Reporter and Assignee.
      The following screenshot shows how to set up automated ticket creation.
      TC Automatic Ticket Jira
    7. Click on “Complete” button. Now, if any task is assigned to you, it will be automatically created in Jira.

Manual Ticket Creation

If automated ticket creation is not required, tickets can be created manually in Jira via the standard task flow.

To create a ticket manually

  1. Navigate to any of the tasks in TrustOps.
  2. Click on the “Create Issue with Jira” button from the three-dot menu.
    The following screenshot shows how to create an issue with Jira.
    TC Issue with Jira
  3. Enter key details such as project, issue type, reporter, assignee, summary, and description.
    The following screenshot shows capturing accurate Jira status via TrustOps tasks.
    TC Issue with Jira 01
  4. Click on the “Create Issue” button.
  5. You can check the “Tickets” tab of the task to see the tickets linked to that particular task. It shows the current status, assignee, and priority level. As TrustOps-Jira integration is bi-directional, changes made to the ticket in Jira will be reflected in the corresponding TrustOps task.

NOTE:

    1. TrustOps does not support pushing tickets into private Jira projects or into projects that are hidden by the Jira administrator.
    2. TrustOps does not support the customization of fields or requirements that change by project type.
    3. If you face any issues or have a specific Jira use case, kindly contact TrustOps support for further assistance.

Have a question?

Join our TrustCommunity to learn about security, privacy, governance, risk and compliance, collaborate with your peers, and share and review the trust posture of companies that value trust and transparency!

Join the conversation

You might also be interested in

Duo

This document outlines the steps you can take to grant TrustCloud access to only...

Google Cloud Platform

This document outlines the steps you can take to grant TrustCloud access to only...

Bitbucket

Instructions to grant TrustCloud read-only access to your Bitbucket organization...

Hybrid Data Fabric

The Hybrid Data Fabric is a built-in connector between your TrustCloud and an external...

Okta

Set up Okta for automated tests with TrustCloud! This document outlines the steps you...

ServiceNow

Set up ServiceNow for Ticket as Evidence with TrustCloud! This document outlines the steps...

Tenable.io

This document outlines the steps you can take to grant TrustCloud access to only...

AWS

This document outlines the steps you can take to grant TrustCloud access to only...
OR

TrustCommunity

Instant support with our AI chatbot

Please login with your TrustCloud credentials to continue