All integrations

CISA ScubaGoggles Integration with DefectDojo

CISA ScubaGoggles Integration with DefectDojo

ScubaGoggles is an open source assessment tool published by the Cybersecurity and Infrastructure Security Agency (CISA) as part of its Secure Cloud Business Applications (SCuBA) project. It checks a Google Workspace tenant against the SCuBA secure configuration baselines for services such as Gmail, Calendar, Drive, Chat, and Meet, grading each baseline policy as a "Shall" (mandatory) or "Should" (recommended) requirement. ScubaGoggles is the Google Workspace counterpart to ScubaGear, which covers Microsoft 365. It writes an HTML report, a ScubaResults JSON file with every result, and an ActionPlan.csv of the controls that did not pass, and DefectDojo imports either the JSON or the CSV.

CISA ScubaGoggles Integration with DefectDojo

We run CISA ScubaGoggles because our Google Workspace settings are as security-relevant as anything in our cloud accounts, and nobody was reviewing them on a schedule. The tool gives us a baseline check in a few minutes. DefectDojo turns that check into work: each failing policy becomes a Finding on the Asset that represents our Workspace tenant, tagged with the service it belongs to, assigned to the admin team, and tracked until it passes. The next assessment shows the delta rather than a fresh report to read from the top.

Why ScubaGoggles Matters

Google Workspace holds email, calendars, documents, and chat for many organizations. Sharing defaults, external invitation settings, and authentication policy decide how much of that data leaves the tenant.

  • The SCuBA baselines are written and versioned by CISA, which gives a defensible definition of a secure Workspace configuration.
  • Each policy is labeled mandatory or recommended, so teams can prioritize the controls that matter most.
  • ScubaGoggles covers several Workspace services in one run, and the results are grouped by service and baseline group.
  • It reads the tenant's actual settings rather than relying on documentation or memory.
  • A single assessment is a snapshot. Proving that configuration stays compliant over time needs results stored somewhere with history.

Advantages of This Integration

What we gained by sending ScubaGoggles results through DefectDojo:

  • Severity from the baseline. A failed Shall policy imports as High, a failed Should policy as Medium, and a Warning as Low.
  • No noise from passing or untestable controls. Pass, N/A, and "No events found" results are skipped, as are baselines ScubaGoggles marks Not-Implemented because it cannot evaluate them yet.
  • Service context on each Finding. When importing the JSON results, the Workspace service (for example drive or calendar) becomes the Finding's component, and the baseline group and tenant name are recorded in the description.
  • A link back to the baseline. JSON imports set References to the baseline group's reference URL, so whoever picks up the Finding can read the policy text directly.
  • Remediation history. Reimporting each assessment mitigates policies that now pass, adds new failures, and reactivates regressions.
  • Documented exceptions. Policies you cannot meet for business reasons can be risk-accepted with an expiry and a justification.

How This Integration Works

DefectDojo supports two ScubaGoggles artifacts, each with its own scan type:

  • ScubaGoggles Scan reads the ScubaResults_*.json file, which holds the full set of pass and fail results along with tenant metadata.
  • ScubaGoggles Action Plan reads ActionPlan.csv, which holds only the controls that did not pass.

The JSON carries more context (service, baseline group, tenant, reference URL), so it is the better choice when you have it.

1. Run an assessment. With ScubaGoggles installed and configured with credentials that can read your Workspace settings:

scubagoggles gws -o output

2. Import the results. In the UI, open the Engagement, choose Import Scan Results, select ScubaGoggles Scan (or ScubaGoggles Action Plan for the CSV), and upload the file. For automation, use the API in Community Edition or DefectDojo Pro:

curl "https://YOUR_INSTANCE/api/v2/import-scan/" 
  -H "Authorization: Token $DD_API_TOKEN" 
  -F "scan_type=ScubaGoggles Scan" 
  -F "file=@ScubaResults.json" 
  -F "product_name=google-workspace" 
  -F "engagement_name=SCuBA Baseline" 
  -F "auto_create_context=true"

DefectDojo Pro users can do the same with Universal Importer:

universal-importer import 
  --defectdojo-url "https://YOUR_INSTANCE.cloud.defectdojo.com/" 
  --scan-type "ScubaGoggles Scan" 
  --report-path "./ScubaResults.json" 
  --product-name "google-workspace" 
  --engagement-name "SCuBA Baseline" 
  --auto-create-context

3. Reimport after each assessment. Send later results to /api/v2/reimport-scan/ against the same Test so each policy keeps one history.

Data Granularity: What Gets Imported

DefectDojo Field Source in ScubaGoggles Output Notes
Title Control ID and Requirement Formatted as GWS.CALENDAR.2.1v1: requirement text
Severity Result and Criticality Fail and Shall is High, Fail and Should is Medium, Warning is Low
Description Requirement, Result, Criticality, Details JSON adds baseline group, product, and tenant display name or domain
Mitigation Details ScubaGoggles' evaluation detail for the policy
References GroupReferenceURL JSON only
Component Name Product key JSON only, for example drive or chat
Tool ID (vuln_id_from_tool) Control ID Includes the baseline version suffix
Skipped Pass, N/A, No events found, Not-Implemented Not imported
Finding type Static As set by the parser
Deduplication (JSON) Hashcode vuln_id_from_tool, component_name
Deduplication (CSV) Hashcode vuln_id_from_tool, severity

HTML markup in the Requirement and Details fields is stripped before import.

Use Cases

For scheduled tenant reviews: The Workspace admin team runs ScubaGoggles monthly and reimports the JSON into one Test. Open High Findings show which mandatory policies still fail, and the history shows when each one was fixed.

For agencies following CISA guidance: Organizations adopting the SCuBA baselines import ScubaGoggles results alongside ScubaGear results for Microsoft 365, giving one place to report on SaaS configuration across both suites.

After a policy change: When the team tightens external sharing or invitation settings, a fresh assessment and reimport confirm which Findings closed and whether anything else regressed.

Across business units with separate tenants: Each tenant gets its own Asset, so security leads can compare baseline conformance by tenant without merging HTML reports.

Operational Tips

  • Prefer the JSON results. They carry the service, baseline group, tenant, and reference URL, and the service becomes the component used in deduplication.
  • Do not mix the two scan types in one Test. They deduplicate on different fields, so switching between them splits a policy's history.
  • In the JSON scan type, severity is not part of the hash. In the Action Plan scan type it is, so a Fail that becomes a Warning appears as a new Low Finding there.
  • Baseline revisions can change control ID version suffixes. Expect new Findings after CISA updates a baseline, and let reimport close the old ones.
  • Filter by component to route Findings to service owners, for example Drive policies to the collaboration team and Gmail policies to the messaging team.
  • Use risk acceptance with an expiry and a written justification for policies you deliberately do not meet.