JSM Assets Integration with DefectDojo
JSM Assets Integration with DefectDojo
JSM Assets is the asset and configuration management database built into Atlassian's Jira Service Management, formerly sold as Insight. It stores objects such as applications, servers, and services in object schemas that each organization designs for itself, and links those objects to service requests and incidents. Assets is available on Jira Service Management Premium and Enterprise plans and exposes its data through the Assets API, which the DefectDojo Pro connector reads.
JSM Assets Integration with DefectDojo
We already maintain our inventory in JSM Assets, so building a second, slightly different list of applications inside DefectDojo made no sense. The JSM Assets connector for DefectDojo Pro reads the objects in our Assets workspace and creates a DefectDojo Asset for each one, grouped into Organizations by object schema. It imports no findings. What it gives us is a security hierarchy that matches the inventory the service desk already trusts, so when scanners and other connectors start sending findings, they land on Assets with names everyone recognizes.
Why JSM Assets Matters
An inventory is only useful if people keep it current, and the one maintained by IT service management usually gets more attention than any list a security team builds.
- Object schemas reflect how your organization actually groups things, whether by business service, environment, or department.
- Assets objects already connect to service requests and incidents in Jira Service Management, so they carry operational meaning beyond a name.
- Keeping DefectDojo's Asset list in step with JSM Assets avoids two teams arguing over which list is correct.
- Without a connector, new applications have to be added to DefectDojo by hand, and the ones nobody added never get findings attached.
Advantages of This Integration
What an asset connector changes for a DefectDojo Pro instance:
- The hierarchy builds itself. Each Assets object becomes a Record, and with Auto-Mapping enabled DefectDojo creates the matching Asset and places it in an Organization named for the object's schema.
- New inventory shows up automatically. Discover and Sync run on the schedule you set (every 6, 12, or 24 hours) and add Records for objects created since the last run.
- Removals are flagged, never deleted. If an object disappears from JSM Assets, its Record is marked Missing on the next Sync so someone can triage it. DefectDojo does not silently delete the Asset or its findings.
- Findings from other tools have a home. Scan imports, Universal Importer runs, and finding connectors can target the Assets this connector created, so ownership and SLA reporting follow the same inventory as the service desk.
- Names stay stable. With the identity feature enabled, Auto-Mapping remembers each object's identifier, so renaming an object does not create a duplicate Asset.
How This Integration Works
Connectors are part of DefectDojo Pro. Community Edition has no JSM Assets connector, and because this is an asset connector rather than a scanner, there is no file to import instead.
1. Check your plan and account. The Assets API requires a Jira Service Management Premium or Enterprise plan. On Free or Standard plans, the API returns a 403 response stating that access to the Assets API was denied, even though the rest of the site works. The Atlassian account you connect also needs Jira Service Management product access (an agent seat). Site access alone is not enough.
2. Create an API token. Create a classic Atlassian API token from your Atlassian account's security settings at id.atlassian.com. DefectDojo recommends a dedicated service account for the connector.
3. Add the connector in DefectDojo Pro. In the Pro UI, open Connect > Upstream. You can use the Asset filter in the page header to show only asset connectors. On the JSM Assets tile, click Add Configuration and enter:
- Location: your Atlassian site URL, in the form
https://your-site.atlassian.net. - Email: the Atlassian account email that owns the token.
- Secret: the API token.
- Label: a name for this configuration.
Set the Discovery and Synchronization schedules, decide whether to enable Auto-Mapping, and submit. If the account can see nothing, DefectDojo saves the connector and shows a No Data Visible warning.
4. Discover and map. Discover reads your Assets workspace and creates a Record for each object, named after the object's label and grouped by object schema. With Auto-Mapping on, each Record is mapped to an Asset automatically. With it off, review the Unmapped Records list and map, ignore, or leave each one.
Data Granularity: What Gets Imported
This connector imports inventory, not vulnerabilities. The table describes what it maps.
| DefectDojo Object | Source in JSM Assets | Notes |
|---|---|---|
| Record | Assets object | One Record per object in the workspace |
| Record name | Object label | Used as the Asset name when Auto-Mapping creates one |
| Organization | Object schema | Records are grouped by the schema the object belongs to |
| Asset | Mapped Record | Created by Auto-Mapping or assigned manually |
| Record state | Presence in JSM Assets | New, Good, Ignored, Missing, or Error |
| Findings | None | Asset connectors do not import findings |
Because no findings are imported, the Stale record state (which the findings pipeline sets) does not apply to this connector.
Use Cases
Seeding a new DefectDojo Pro instance: A team rolling out DefectDojo Pro connects JSM Assets first. Within one Discover run, the Assets and Organizations match the service catalog, and the scanner connectors configured afterward map onto those existing Assets by name.
Keeping security scope in step with IT: When the service desk registers a new application in JSM Assets, it appears as a new Record on the next Discover. Security sees it without waiting for someone to file a request to add it.
Handling decommissioned systems: An object removed from JSM Assets marks its Record as Missing. The security team can confirm the system is retired and delete the Record, while all findings already recorded against the Asset stay in DefectDojo as history.
Limiting scope: If one schema holds objects that will never be scanned, such as office hardware, those Records can be set to Ignored so they do not clutter the Asset list.
Operational Tips
- Confirm the plan level before troubleshooting anything else. A 403 from the Assets API on a working site almost always means the plan does not include Assets.
- Give the service account an agent seat. A token from an account with only site access fails even if the email and token are correct.
- Decide on Auto-Mapping before the first Discover. Auto-Mapping is convenient for a clean inventory. If your schemas include many objects you never want as Assets, start with it off and map deliberately.
- Use Ignored rather than Delete for objects you never want in DefectDojo. Deleted Records are rediscovered on the next run if the object still exists.
- Watch for name collisions. On first sight, Auto-Mapping matches by name globally, so an Assets object and a finding connector project with the same name share one Asset. That is usually what you want, but check it.
- Turn on the Connector Health Warning notification so an expired token or narrowed permission is reported rather than silently stopping updates.