Atlassian pipes software flaw reports into Jira, so the boss can see them too
(2023/06/07)
- Reference: 1686159494
- News link: https://www.theregister.co.uk/2023/06/07/atlassian_jira_security/
- Source link:
Atlassian has decided that its Jira issue-tracker needs one more category of issue to track: security flaws.
Suzie Prince, Atlassian's head of product for DevOps, told The Register developers use multiple tools during their days, which makes communicating security issues hard. It can also mean fixing them doesn't make it into workflows that touch all stakeholders in a software project, she added. Wider visibility matters, Prince argues, because when security issues fester in ops or infosec silos, it's hard to know what fixes to prioritize, and why.
Atlassian's answer is to tap info feeds from Snyk, Mend, Lacework, StackHawk, and JFrog, load them into a new "Security" tab in Jira, where security-related issues can be viewed by all stakeholders and automated workflows route work to the right people. Atlassian parses severity scores to help users prioritize.
[1]
Prince said Atlassian saw customers try to build this sort of thing themselves, so the company productized it.
[2]Atlassian says 'Don't #@!% the Planet' so it can keep making money
[3]How does Atlassian hope to actually improve Confluence and Jira? AI, of course!
[4]Atlassian to dump 500 – by email – in the name of 'rebalancing'
[5]Developers: What if someone said you’d never have to meet with marketing again?
The Register asked Prince if there's a downside to wide visibility of flaws. We offered a scenario in which a product manager who works with developers reads news of a colossal flaw – something along the order of importance of the [6]Log4Shell vulnerability in the ubiquitous Apache Log4j logging library – and uses their ability to see that in a Jira queue to order a fix without understanding that other matters could be more important.
"Being knee jerk is what product managers do," she admitted, before going on to argue that having a single place to manage the flaw-fixing workflow means you get a chance to have a conversation about what fixes are at the top of a to-do list, and why, perhaps leading a nervous non-techie to back down gracefully.
[7]
The new security functionality is baked into Jira Software Cloud, accessible to all users today and is covered by existing licenses. Atlassian will add integrations to more security vendors but could not name names or offer a timeline for their inclusion. ®
Get our [8]Tech Resources
[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/devops&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZID@Awd3lpFsKUbE8b0hyAAAAME&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[2] https://www.theregister.com/2023/05/24/atlassian_sustainability_guide/
[3] https://www.theregister.com/2023/04/19/atlassian_ai/
[4] https://www.theregister.com/2023/03/07/atlassian_fires_500/
[5] https://www.theregister.com/2023/01/25/atlassian_extends_automation_to_confluence/
[6] https://www.theregister.com/2022/01/25/sophos_log4shell/
[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/devops&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZID@Awd3lpFsKUbE8b0hyAAAAME&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[8] https://whitepapers.theregister.com/
Suzie Prince, Atlassian's head of product for DevOps, told The Register developers use multiple tools during their days, which makes communicating security issues hard. It can also mean fixing them doesn't make it into workflows that touch all stakeholders in a software project, she added. Wider visibility matters, Prince argues, because when security issues fester in ops or infosec silos, it's hard to know what fixes to prioritize, and why.
Atlassian's answer is to tap info feeds from Snyk, Mend, Lacework, StackHawk, and JFrog, load them into a new "Security" tab in Jira, where security-related issues can be viewed by all stakeholders and automated workflows route work to the right people. Atlassian parses severity scores to help users prioritize.
[1]
Prince said Atlassian saw customers try to build this sort of thing themselves, so the company productized it.
[2]Atlassian says 'Don't #@!% the Planet' so it can keep making money
[3]How does Atlassian hope to actually improve Confluence and Jira? AI, of course!
[4]Atlassian to dump 500 – by email – in the name of 'rebalancing'
[5]Developers: What if someone said you’d never have to meet with marketing again?
The Register asked Prince if there's a downside to wide visibility of flaws. We offered a scenario in which a product manager who works with developers reads news of a colossal flaw – something along the order of importance of the [6]Log4Shell vulnerability in the ubiquitous Apache Log4j logging library – and uses their ability to see that in a Jira queue to order a fix without understanding that other matters could be more important.
"Being knee jerk is what product managers do," she admitted, before going on to argue that having a single place to manage the flaw-fixing workflow means you get a chance to have a conversation about what fixes are at the top of a to-do list, and why, perhaps leading a nervous non-techie to back down gracefully.
[7]
The new security functionality is baked into Jira Software Cloud, accessible to all users today and is covered by existing licenses. Atlassian will add integrations to more security vendors but could not name names or offer a timeline for their inclusion. ®
Get our [8]Tech Resources
[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/devops&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZID@Awd3lpFsKUbE8b0hyAAAAME&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[2] https://www.theregister.com/2023/05/24/atlassian_sustainability_guide/
[3] https://www.theregister.com/2023/04/19/atlassian_ai/
[4] https://www.theregister.com/2023/03/07/atlassian_fires_500/
[5] https://www.theregister.com/2023/01/25/atlassian_extends_automation_to_confluence/
[6] https://www.theregister.com/2022/01/25/sophos_log4shell/
[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/devops&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZID@Awd3lpFsKUbE8b0hyAAAAME&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[8] https://whitepapers.theregister.com/
Re: Is JIRA becoming like helpdesk software?
t245t
The only exposure I've had to "issue-tracker" software was a help desk app, management foisted on us when I worked at a call center. As the call progressed, we typed in stuff in selected boxes by sub-menu. We could not use the app to make technical queries such as error codes. For that we had to google on it. It ran so slow we were reduced to opening multiple windows and typing in any old thing. This left little attention to attend to the caller. As you say, it's primary function was producing shiny graphs and scheduled reports for management.
Is JIRA becoming like helpdesk software?
There is very little good helpdesk software out there. A few options have their advocates, but they're all flawed in one way or another.
I remember when someone explained to me why our new helpdesk software was so lacklustre. "It's the managers. They're the ones that sign the cheques, so look at the features that they get. Shiny graphs, scheduled reports, dashboards that allow them to obsess over SLAs. But actually updating a call? The manager will never see that, so of course it's a bad experience. The development goes where the budget holder's attention is."
JIRA was, for a long time, a common standard for software development precisely because it seemed to pay some attention to what developers wanted as well as what their managers wanted.
It seems that those days may be over...