Use the Jira App in the Marketplace to automate ticket creation in Jira, based on scorecard changes and events. You design rules that these events trigger to create tickets with the following information:
- Event name
- Description
- Link to the SecurityScorecard scorecard associated with the event
Once created, you can update the ticket as you do any other Jira ticket.
SecurityScorecard tracks only the following Jira data from your app integration: the details of the event that triggered the rule, and your username, email, and organization.
Prerequisites
The Jira App integration works with Jira Cloud or Jira Server/Data Center installations. Before you begin, make sure you have the following:
- A SecurityScorecard account with a paid plan
- A Jira account with administrative permissions, or approval to integrate the app from your Jira administrator
Install the app
Install the Jira App from the Marketplace and connect it to your Jira instance before you create any rules.
- Go to Automation > Integrations and search for the Jira app.
- Select Install.
- Review the permissions on the SecurityScorecard authorization screen and select Allow access to continue.
- Select whether you have a Jira Cloud or Jira Server/Data Center installation. If you are unsure, ask your Jira administrator.
-
Enter the requested information and select Confirm. The information you enter depends on your installation type:
Installation type Information to enter Jira Cloud A name for the integration. SecurityScorecard uses this name to identify the connection, and you authorize access directly in Jira in the next step Jira Server/Data Center - Your Atlassian personal access token. Select the link in the form for guidance to obtain the token.
- Your Jira site host. Log in to Jira and copy the URL from your browser navigation bar, or ask your Jira administrator for help. For example: mycompany.atlassian.net
- For a Jira Cloud installation, SecurityScorecard redirects you to your Jira site. Review the permissions Jira requests and select Accept to complete the connection.
- Select your Jira project and task type, then select Finish.
SecurityScorecard then redirects you back to the platform with the integration ready to use.
Create a rule to activate ticket creation
Jira tickets are created automatically whenever the rule is triggered, with details your team uses to take action. You can create up to 25 rules with this app integration.
To create a rule that automates ticket creation with a scorecard event:
- From the Jira App page, select Rules & Actions.
- In the drop-down list, select an option:
- Create your own custom rule.
- Use a predefined rule provided by SecurityScorecard.
- Once in the Rule Builder, add or edit your rule details:
- Enter a name to help you remember the rule.
- Select the event that triggers the rule, such as a grade drop or rise, or a new open issue appears.
- Select a scorecard or portfolio that the rule applies to.
- Select the action that the rule initiates, in this case, creating a Jira ticket.
- Optionally, select a default assignee for the tickets the rule creates. The list of available assignees is pulled directly from the Jira project you selected, so only users who are assignable in that project appear as options.
- If your event is A new Open Issue appears or New Findings for an Open Issue, select how the app groups tickets. See Choose how tickets are created.
- Save the rule.
Note: After you save a rule, it can take up to 24 hours for the corresponding Jira tickets to appear on your Jira board.
Choose how tickets are created
When you set the ticket creation action to be A new Open Issue appears or New Findings for an Open Issue, two options appear for how the app groups findings into tickets.
- Create a Jira ticket per Issue (default): Creates a single Jira ticket for each issue on your scorecard. The ticket includes a summary of all associated findings. Keep this option for summary-level tickets.
- Create a Jira ticket per Issue Finding: In addition to the single per-issue ticket, creates an individual ticket for each finding. This option can create a large number of tickets, depending on the number of findings for the issue. Filter your rule to limit ticket creation volume.
Turn off SecurityScorecard notifications for the Jira app
To disable notifications, turn off each alert individually:
- Select My Settings from your profile avatar in the top-right corner of the platform interface.
- Select the Rules tab on the left to edit, delete, or pause each rule individually.
Uninstall the Jira App integration
First, delete the rules configured for the Jira integration.
Then, on the Jira App page, select Uninstall.