Work with security vulnerabilities in Jira
Connecting a security tool lets you view security containers and vulnerabilities in Jira, triage them, and quickly link them to work items.
Your team can assess each vulnerability (based on factors like severity or how complex the fix is), link it to a work item, add the work item to your sprint or backlog, and track it until it’s resolved.
By turning unplanned security vulnerabilities into manageable work, you can improve your team’s focus on security while still maintaining your regular workload balance and rituals.
Once you’ve connected a security tool to your Jira site, you can add security containers to your space and view vulnerabilities. on the Development page.
Each container shows the name of the security tool it belongs to, and how recently it was updated. Select a container to view more details, or go to your security tool to manage it.
You must have the following to do the things described on this page:
Role: Space admin
Before you begin
Make sure that:
your site administrator has connected a security tool to your Jira site
the development feature is enabled for your space
Connect security containers to a space
You can connect as many security containers to a space as you like, and a container can also be connected to more than one space at a time. However, to help prevent multiple teams from seeing the same vulnerability and duplicating work, we recommend connecting each container to just one space whenever possible.
To connect security containers from the Development page:
Select Development from your space’s navigation.
Select Vulnerabilities under the Related work section.
If there aren’t any containers connected to your space yet, select Finish setup to connect the first one.
If there’s already at least one container connected to your space, select the manage connection icon to add more.
In the Tools sidebar, look for your security tool, then select Connect containers.
Select the containers you’d like to connect, then select Connect.
Remove security containers from a space
To remove security containers from the Development page:
From your space's navigation, select Development.
Select the connection icon [Connect icon] under the Related work section.
Select the relevant security tool for the container you want to remove.
Select the more actions icon (•••) next to the container you want to remove, then select Remove connection.
Link a security vulnerability to a Jira work item
You can create a new work item for a vulnerability, or link it to an existing work item.
From your space navigation, select Development, then select Vulnerabilities in the Related work section.
In the vulnerabilities section, find the vulnerability you want to link a work item to, then:
To create a new work item, select Create.
To link to a work item that already exists, select More actions (), then Link work item.
Link a vulnerability to multiple work items
You can link a vulnerability to more than one work item. If the vulnerability already has a work item linked to it, here’s how to link another one:
In the vulnerabilities section, find the vulnerability you want to link a work item to.
Select More actions (), then:
Select Edit linked work item to link to another existing work item.
Select Create another to create and link another new work item.
Unlink a work item from a vulnerability
When you unlink a work item, it will be removed from the work items column in the vulnerabilities section of the Development page.
To unlink a work item from a vulnerability:
From your space navigation, select Development, then select Vulnerabilities in the Related work section.
In the vulnerabilities section, find the vulnerability you want to unlink a work item from.
In the work items column, hover over the work item you want to unlink and select the unlink work item icon, then select Unlink work item , then select Unlink.
Or, select More actions (), then Edit linked work item.
Confirm which work items are currently linked to the vulnerability.
To unlink a work item, select ( x ) next to the work item, then Save.
Was this helpful?