All integrations

CISA ScubaGear Integration with DefectDojo

CISA ScubaGear Integration with DefectDojo

ScubaGear is an open source PowerShell assessment tool published by the Cybersecurity and Infrastructure Security Agency (CISA) as part of its Secure Cloud Business Applications (SCuBA) project. It checks a Microsoft 365 tenant's configuration against the SCuBA secure configuration baselines for products such as Entra ID, Defender, Exchange Online, SharePoint, and Teams. Each baseline control is marked as a "Shall" (mandatory) or "Should" (recommended) requirement. ScubaGear writes an HTML report, per-product JSON reports, and an ActionPlan.csv listing the controls that did not pass, and DefectDojo can import either the CSV or the JSON.

CISA ScubaGear Integration with DefectDojo

We run CISA ScubaGear against our Microsoft 365 tenant because tenant settings drift. An admin adds an exception, a new feature ships with a permissive default, and the configuration we signed off on last quarter is no longer the one in production. ScubaGear tells us where we stand against the baseline. DefectDojo is where each failing control becomes a Finding with an owner, a due date, and a history, so the next assessment shows what was fixed and what is still open instead of producing another HTML report to compare by eye.

Why ScubaGear Matters

Microsoft 365 is where identity, email, and file sharing live for most organizations, and its security depends heavily on configuration choices that are easy to get wrong.

  • The SCuBA baselines are published by CISA and give a concrete, versioned definition of a secure tenant, which beats an internal checklist nobody maintains.
  • Controls are graded as mandatory or recommended, so teams can separate must-fix items from improvements.
  • ScubaGear checks the tenant directly, covering settings such as phishing-resistant MFA, application registration rights, and external sharing.
  • Federal agencies use the same baselines for Binding Operational Directive 25-01 reporting, and ScubaGear flags which controls are BOD 25-01 requirements.
  • The tool reports a point-in-time result. Tracking remediation across assessments needs a platform behind it.

Advantages of This Integration

What we gained by sending ScubaGear results through DefectDojo:

  • Severity from the baseline itself. DefectDojo derives severity from the result and criticality: a failed Shall control is High, a failed Should control is Medium, and a Warning is Low.
  • Only actionable controls import. Passing controls and controls ScubaGear marks as Not-Implemented (ones the tool cannot evaluate yet) are skipped.
  • Remediation history. Reimporting each assessment into the same Test mitigates controls that now pass, adds new failures, and reactivates any that regressed.
  • Documented exceptions. When a control cannot be met for a business reason, risk acceptance with an expiry records the decision and brings it back for review.
  • SLA tracking and ownership. Tenant configuration findings get the same SLA clock and assignment as any other finding, so identity and messaging teams see their work in one queue.
  • Clean text. The requirement and details columns contain HTML for ScubaGear's report. The parser strips the markup before it reaches the Finding.

How This Integration Works

DefectDojo supports two ScubaGear artifacts, each with its own scan type:

  • ScubaGear Scan reads ActionPlan.csv, which holds only the controls that did not pass. It is written as UTF-8 with a byte order mark.
  • ScubaGear Report Scan reads a per-product JSON report from the IndividualReports folder, which holds every control, passing ones included. These files are UTF-16. The parser detects the encoding from the byte order mark, so no conversion is needed.

Both are graded the same way. The JSON simply carries more source data, and passing controls are dropped on import.

1. Run an assessment. From PowerShell, with ScubaGear installed and an account that can read the tenant configuration:

Invoke-SCuBA -ProductNames aad, defender, exo, sharepoint, teams

2. Import the results. In the UI, open the Engagement, choose Import Scan Results, select ScubaGear Scan (or ScubaGear Report Scan for a JSON file), and upload it. For automation, use the API in Community Edition or DefectDojo Pro:

curl "https://YOUR_INSTANCE/api/v2/import-scan/" 
  -H "Authorization: Token $DD_API_TOKEN" 
  -F "scan_type=ScubaGear Scan" 
  -F "file=@ActionPlan.csv" 
  -F "product_name=m365-tenant" 
  -F "engagement_name=SCuBA Baseline" 
  -F "auto_create_context=true"

DefectDojo Pro users can do the same with Universal Importer:

universal-importer import 
  --defectdojo-url "https://YOUR_INSTANCE.cloud.defectdojo.com/" 
  --scan-type "ScubaGear Scan" 
  --report-path "./ActionPlan.csv" 
  --product-name "m365-tenant" 
  --engagement-name "SCuBA Baseline" 
  --auto-create-context

3. Reimport after each assessment. Send later results to /api/v2/reimport-scan/ against the same Test so the history of each control stays in one place.

Data Granularity: What Gets Imported

DefectDojo Field Source in ScubaGear Output Notes
Title Control ID and Requirement Formatted as MS.AAD.3.1v1: requirement text; badge labels such as "BOD 25-01 Requirement" remain as text
Severity Result and Criticality Fail and Shall is High, Fail and Should is Medium, Warning is Low
Description Requirement, Result, Criticality, Details Adds Non-Compliance Reason and Justification when present
Mitigation Details ScubaGear's evaluation detail, such as how many policies met the requirement
Tool ID (vuln_id_from_tool) Control ID Includes the baseline version suffix, for example v1
Skipped Pass results, Not-Implemented criticality Not imported
Finding type Static As set by the parser
Deduplication Hashcode vuln_id_from_tool, severity

HTML markup in the Requirement and Details fields is removed and whitespace is collapsed before import.

Use Cases

For quarterly tenant reviews: The identity team runs ScubaGear each quarter and reimports the action plan into one Test. Leadership sees how many mandatory controls are still failing and how that number has moved since the last review.

When tracking BOD 25-01 obligations: A federal agency imports ScubaGear results for each tenant into its own Asset. Controls labeled as BOD 25-01 requirements are visible in the Finding title, and their remediation dates and accepted exceptions are recorded in one place.

After a configuration change: Before and after a large change, such as a new conditional access design, the team runs an assessment and reimports it. New failures appear as new Findings, and controls that now pass are mitigated automatically.

Across several tenants: A managed service provider assesses many customer tenants and imports each into the customer's Asset, which gives a per-tenant view of baseline conformance without merging spreadsheets.

Operational Tips

  • Pick one artifact per Test. ScubaGear Scan and ScubaGear Report Scan are separate scan types, so mixing them splits the history of the same controls across two Tests.
  • Severity is part of the deduplication hash. If a control moves from Fail to Warning, reimport mitigates the High or Medium Finding and opens a new Low one, which is the record you want.
  • Baseline updates can change control IDs (the version suffix). Expect new Findings when CISA revises a baseline, and close old ones through reimport.
  • The Mitigation field holds ScubaGear's evaluation detail, not step-by-step guidance. Link the relevant SCuBA baseline section in a note when assigning work.
  • Use risk acceptance with an expiry for controls you have documented exceptions for, and record the justification in the Finding.
  • Set SLAs for High to match how quickly you expect mandatory controls to be fixed, since every failed Shall control lands there.