BigID Integration with DefectDojo
BigID Integration with DefectDojo
BigID is a data security, privacy, and compliance platform that discovers and classifies sensitive data across an organization's data sources. Its data security posture management (DSPM) capabilities raise cases for problems such as exposed sensitive data, over-permissive access, and unprotected stores of personal information. DefectDojo imports BigID cases from a JSON export, or pulls them with the DefectDojo Pro BigID connector.
BigID Integration with DefectDojo
We use BigID to find where regulated data lives and when it is exposed. Those cases are security work, but they were tracked in a separate console from the rest of our findings, so nobody reported on them together. Importing BigID cases into DefectDojo makes each case a Finding tied to its data source, with the policy, sensitivity, and affected-object count in the description. What made the security team comfortable was that the integration reads only the count of affected objects, never samples of the data, so DefectDojo doesn't become another copy of the sensitive data.
Why BigID Matters
Data exposure is a different kind of risk from a vulnerable package or a misconfigured server, and it often goes unmeasured by traditional scanners.
- BigID looks at the data itself, so it can tell you that a store holds personal or regulated information, not just that the store is reachable.
- Its cases are tied to policies, which link each exposure to a specific rule your privacy or compliance team defined.
- Cases name the data source and the sensitivity classification, which is what you need to route them to the right owner.
- DSPM results are most useful when they sit next to infrastructure and application findings for the same systems, which BigID alone doesn't provide.
Advantages of This Integration
- No sensitive data copied. Only the case identity, its policy and data-source context, and the count of affected objects are read. Samples, previews, or values in the export are never written into a finding.
- Per-data-source findings. The data source is the component, so the same policy failing on two data sources stays two findings with separate owners.
- Status carried over. Cases BigID marks
resolved,remediated, orclosedimport as inactive and mitigated. Any other status stays active, so an unfamiliar state never hides a live exposure. - Filtering by classification. The data-source type and sensitivity group become tags.
- File and API agree. The parser mirrors the connector under the scan type
BigID Scan, so file imports and connector Syncs deduplicate against each other.
How This Integration Works
Option 1: File import. Use this path when you can't grant DefectDojo BigID API credentials. Export the cases response as JSON. BigID's own samples disagree on the envelope, so the parser accepts a bare array of cases, {"data": {"cases": [...]}}, or {"cases": [...]}. Each case becomes one finding. Cases without a caseId are dropped, because the ID is the finding's identity.
In the UI, open an Engagement, choose Import Scan Results, select BigID Scan, and upload the file. For automation, use the API in Community Edition or DefectDojo Pro:
curl "https://YOUR_INSTANCE/api/v2/import-scan/"
-H "Authorization: Token $DD_API_TOKEN"
-F "scan_type=BigID Scan"
-F "file=@bigid-cases.json"
-F "product_name=data-platform"
-F "engagement_name=BigID DSPM"
-F "auto_create_context=true"
With DefectDojo Pro, Universal Importer runs the same import from a scheduled job:
universal-importer import
--defectdojo-url "https://YOUR_INSTANCE.cloud.defectdojo.com/"
--scan-type "BigID Scan"
--report-path "./bigid-cases.json"
--product-name "data-platform"
--engagement-name "BigID DSPM"
--auto-create-context
Option 2: BigID connector (DefectDojo Pro). Create a BigID user token under Administration, Access Management. In the DefectDojo Pro UI, add the BigID connector, enter your BigID instance URL as the Location, paste the user token, and optionally set a Minimum Severity. DefectDojo exchanges the user token for a short-lived system token on each Sync. The connector imports DSPM findings from BigID's actionable insights and creates a Record for each BigID data source, carrying the cases raised against it. As with the file parser, findings carry identifiers, classifications, and affected-object counts only.
Data Granularity: What Gets Imported
| DefectDojo Field | Source in BigID Case | Notes |
|---|---|---|
| Title | caseLabel |
Falls back to policyName, then BigID case <id> |
| Severity | severityLevel |
critical, high, medium, low map directly; unrecognized or absent is Info |
| Description | Policy, policy description, data source, type, sensitivity, affected-object count, status, assignee | Count only; no data samples |
| Mitigation | remediationSteps |
BigID's own remediation steps, when present |
| Component Name | dataSourceName |
The data source the case is about |
| Date | updated_at, else created_at |
Invalid dates keep the import date |
| Unique ID from Tool | caseId |
Formatted as bigid-<case id> |
| Vuln ID from Tool | caseId |
|
| Tags | dataSourceType, sensitivityGroup |
For filtering by store type and classification |
| Active / Mitigated | caseStatus |
resolved, remediated, closed are mitigated; anything else active |
| Finding type | Static | Data at rest, nothing exercised |
| Deduplication | Unique ID or hashcode | Unique ID from tool, falling back to title, severity, component_name |
Use Cases
Data exposure SLAs: A security team sets SLAs on Critical and High BigID cases. Data owners see their cases in DefectDojo with deadlines, and each Sync or reimport closes the ones BigID reports as remediated.
Routing by data source: Because each finding names its data source and is tagged with its type, cases on a cloud warehouse go to the data platform team while cases on file shares go to IT, without manual sorting.
Combined risk reporting: A security lead reports exposure for a system by looking at its Asset in DefectDojo: BigID cases for the data, scanner findings for the hosts, and application findings for the code that touches it.
Privacy-sensitive environments: A team bound by strict data handling rules imports BigID exports through the file parser, knowing that sample values in the file are never read into findings.
Operational Tips
- The parser never reads data samples, but the export file itself may contain them. Treat the JSON as sensitive and delete it after import.
- Only
resolved,remediated, andclosedclose a case. If your BigID workflow uses other closing states, those cases stay active until they reach one of the three. - The affected-object count appears in the description, which helps sort cases by size even though BigID's severity drives SLAs.
- Use
minimum_severity, or the connector's Minimum Severity, to start with Critical and High cases. - Reimport into the same Test, or let the connector Sync on schedule, so cases resolved in BigID are mitigated in DefectDojo.
- Use the sensitivity-group tags to build reports for privacy or compliance stakeholders who only care about specific data classes.