Work with security vulnerabilities in Jira

Connecting a security tool lets you view security containers and vulnerabilities in Jira, triage them, and quickly link them to work items.

Your team can assess each vulnerability (based on factors like severity or how complex the fix is), link it to a work item, add the work item to your sprint or backlog, and track it until it’s resolved.

By turning unplanned security vulnerabilities into manageable work, you can improve your team’s focus on security while still maintaining your regular workload balance and rituals.

Once you’ve connected a security tool to your Jira site, you can add security containers to your space and view vulnerabilities. on the Development page.

Each container shows the name of the security tool it belongs to, and how recently it was updated. Select a container to view more details, or go to your security tool to manage it.

You must have the following to do the things described on this page:

Role: Space admin

Before you begin

Make sure that:

Connect security containers to a space

You can connect as many security containers to a space as you like, and a container can also be connected to more than one space at a time. However, to help prevent multiple teams from seeing the same vulnerability and duplicating work, we recommend connecting each container to just one space whenever possible.

To connect security containers from the Development page:

  1. Select Development from your space’s navigation.

  2. Select Vulnerabilities under the Related work section.

    1. If there aren’t any containers connected to your space yet, select Finish setup to connect the first one.

    2. If there’s already at least one container connected to your space, select the manage connection icon to add more.

  3. In the Tools sidebar, look for your security tool, then select Connect containers.

  4. Select the containers you’d like to connect, then select Connect.

Remove security containers from a space

To remove security containers from the Development page:

  1. From your space's navigation, select Development.

  2. Select the connection icon [Connect icon] under the Related work section.

  3. Select the relevant security tool for the container you want to remove.

  4. Select the more actions icon (•••) next to the container you want to remove, then select Remove connection.

You can create a new work item for a vulnerability, or link it to an existing work item.

  1. From your space navigation, select Development, then select Vulnerabilities in the Related work section.

  2. In the vulnerabilities section, find the vulnerability you want to link a work item to, then:

    1. To create a new work item, select Create.

    2. To link to a work item that already exists, select More actions (), then Link work item.

You can link a vulnerability to more than one work item. If the vulnerability already has a work item linked to it, here’s how to link another one:

  1. In the vulnerabilities section, find the vulnerability you want to link a work item to.

  2. Select More actions (), then:

    1. Select Edit linked work item to link to another existing work item.

    2. Select Create another to create and link another new work item.

When you unlink a work item, it will be removed from the work items column in the vulnerabilities section of the Development page.

To unlink a work item from a vulnerability:

  1. From your space navigation, select Development, then select Vulnerabilities in the Related work section.

  2. In the vulnerabilities section, find the vulnerability you want to unlink a work item from.

  3. In the work items column, hover over the work item you want to unlink and select the unlink work item icon, then select Unlink work item , then select Unlink.

  4. Or, select More actions (), then Edit linked work item.

    1. Confirm which work items are currently linked to the vulnerability.

    2. To unlink a work item, select ( x ) next to the work item, then Save.

 

Still need help?

The Atlassian Community is here for you.