Security In Jira – Andrew Pankevicius, Atlassian
Andrew Pankevicius, Atlassian’s senior product manager, DevOps, discusses Security In Jira. The new security feature within Jira integrates with Snyk, Mend, Lacework, Stackhawk and JFrog, simplifying the workflow of surfacing security vulnerabilities, aggregating vulnerability data, and confirming resolution across application development and deployment.
Transcript
This is techstrong TV By the pleasure of being joined by Andrew. Andrew Pink Avis. Am I saying that it right?
An Andrew Pink Vez. That's right. Yeah.
Vez great. Senior product manager, DevOps with Jira software at Atlassian. Welcome.
Hey, Thanks Mitch. Appreciate it. Glad to, glad to have you join us today.
Um, we're gonna get into a number of things, but love to have you first introduce yourself. Tell us little about you and also what your role is at Atlassian. Yeah, absolutely.
So I work at Atlassian. We've been helping, um, teams adopt agile processes in the software world for over 20 years. Um, my role there is the senior product manager and product lead for security in Jira, which is a new capability that we're releasing, uh, next week.
Fantastic. Exciting. Well, you know, you know, I've been a Jira user myself for, at a number of different companies and, and experienced that and the role Jira has played and, and now Atlassian plays in kinda the open DevOps strategy that you have.
I'd love to hear you talk about, uh, how you approach DevOps and, and kind of bringing, reducing friction and helping flow and keeping people in in that, uh, cognitive mindset to get work done. Yeah, absolutely. So like inside of Atlassian, what we've realized over 20 years of supporting our customers is that, um, there's so many different tools that developers need to access on a daily basis.
Right now, um, in our research we've identified that there's about 25 different tools that the developer might need to navigate in any given week. Um, so that's a lot of context switching and that takes developers far away from focusing on the, on the flow state that's super critical for them to ship great software and what they want to do every day. So what we've realized is that those tools are probably the best breed ones for that, those teams to leverage.
Um, so we wanna take them away from them. The best solution is actually to integrate them and make that diverse kind of tool chain feel like an all-inclusive, all-in-one for a customer. So that's really our approach to DevOps when it comes to Atlassian, is by taking a very open approach to whatever tools customers are, are using on a daily basis.
Bring them into Jira and we'll make sense of that data for you to manage work on a daily basis. Mm-hmm. And those can, you know, anywhere in the development flow and kind of thinking of DevSecOps, right?
Very early in the creating of code in inside the I d e, it can be an infrastructure, it can be in dynamic testing, in in, uh, production or test, you know, running environment. It can be just while we're writing the code. So any, any of those steps is is a place, obviously the earlier the better is where we can engage and hopefully, uh, correct some security issues that we might find as early as Possible.
Absolutely. And like that whole DevSecOps trend slam, it's really emerging and becoming prominent for teams these days to have to manage. Of those 25 tools I just mentioned prior, about nine of them on average inside of an average enterprise is classed as a security tool, which means that there's a lot of different steps.
The developer has to be matching vulnerabilities from lots of different providers, um, as they go from writing a pool request through the deploying code and then managing it at scale. Um, they have to keep on top of it at each step. And that's a lot of cognitive load for developer to take on Analogy that I use is imagine driving a vehicle, in this case you have 24, 25 different tools or dials or buttons you're supposed to be trying to manage while you keep your eyes on the road.
That's what we're trying to do is is eliminate those distractions. That's right. And, and that comes down to that sense of product developer productivity, but more importantly, like developer joy.
You gotta keep them happy whilst they're working on really important features for your customers and keep those distractions away. That's hopefully what we're really trying to do with security and Jira. Excellent.
So let's talk about, uh, security and Jira. I'd love to hear you talk about the announcement. Yeah, absolutely.
So on June 6th we're expanding the scope of, of JIRA's software and cloud, um, to also include a new capability called security in Jira, which is a security tab, um, that's right there accessible for everyone inside the left pane of Jira. What we're doing is enabling our hundred thousand customers to actually, um, manage all of their security vulnerabilities within one place rather than, as we mentioned before, doing all that context switching across nine security tools. You simply plug them into Jira and, and kind of hit play.
Really, it makes it really simple for a team to have a full view of every single security vulnerability and triage it as a team. Interesting. So, um, talk a little bit about then having this security tab.
Is this something people have to go check? Is this something that's gonna show up? Is it your, uh, item that they're following up on?
How, how does that fit into the workflow for a developer and maybe a security team? Yeah, absolutely. So we, we've partnered with five kind of leading vendors in this space to enable this capability, um, that being sneak men, j Frogg, Lacework and Stack Hawk.
So really covering that full software development life cycle and we stream in vulnerabilities from each of these providers directly into Jira and inside of the security in Jira tab, you can really simply view each of those vulnerabilities, rank order them from what provider they've come from and their criticality or severity level and then easily credit Jira issue, um, and assign it to someone in your team to remediate. What's even, what's even more exciting is that we've actually enabled this with our uh, automation for Jira feature set as well. So the teams don't even need to go into the security in Jira tab.
Um, after they've set it up for the first time, they might wish all, all critical vulnerabilities identified are sent straight into their backlog with an issue set a due date and an assignee against it. Mm-hmm. Good.
I'm glad I asked about going into the security tab. Cause you don't want one more thing to check, right? You want that to fall into the flow of, okay, I'm working adding this feature, working this bug, here's the security issue that's come up and just deal with it naturally as part of the flow, whether it comes from one or, or you may have multiple security items that come from the tools cuz some of 'em, you know, a sneak fits into the I D E and a Stack Hawk is do not doing dynamic testing and API testing and you know, and men plugging into, uh, Bitbucket.
So they all kinda have their place in the ecosystem of creating software. Absolutely. And what's more about that is that we're aware that, um, sometimes one vulnerability, oh, sorry, multiple vulnerabilities across different providers might be resolved through one, um, process of remediation.
So you can actually link, um, multiple vulnerabilities to a single issue inside of security in Jira and assign that to a team member, which downstream would resolve a number of vulnerabilities from different providers. Mm-hmm. Very good.
I'd love to hear a little bit more about the integration. Um, with these five, uh, technology security companies, um, are there set of APIs that they use to this or, or to do this? Are they open or others connect access those things?
How does this work? Yeah, it's a great question. So we're open by default really in in line with our idea of having an open, um, DevOps tool chain here.
com for any security vi providers to come in and start integrating into the security and your solution. Very good. J Frogg Artifacty, that and Atlassian were like Futu that and Jenkins were the three first tools that I used for my DevOps implementation.
So I'm having some flashbacks here. All good memories, all good memories too. Better.
Yeah, That's right. There's, there's, that has definitely expanded out in the recent recent years with so many more providers coming in and, um, across our like 2,500 different, uh, marketplace integrations. There's lots of different providers you can connect up to Jerry these days.
That's amazing. That's quite an ecosystem with that many partners and solutions that can be integrated with Atlassian. Absolutely.
Um, talk a little bit about, so, um, you know, it, it isn't all is this just as simple as things show up and just go fix 'em. There there is some, uh, filtering and kind of triage and really looking at security vulnerabilities. Sometimes it's around the, the severity and the priority of the vulnerability may also be, you know, we want to address these things earlier than other issues because we're concentrating on that part of the code.
So there's, there's more than just things popping up in front of a developer to go fix and work on. There's also, um, kind of managing that workload and making sure you're working on the things that matter most for that point in time. Yeah, absolutely.
There's, there's essentially kind of three paths of security that hit, that hit that space you you've mentioned. So number one is actually alignment of security vulnerabilities and their risk against your product for not just developers to know about, but the entire product team. Mm-hmm.
In so many of these cases, um, security tools are class of developer tools, so product managers, business analysts on teams, maybe release managers, don't have insight into the risk, um, that exists inside of their products. So security in Jira brings those vulnerabilities into a security tab where they can all be listed out filtered against severity really easily. And now we're bringing more than just a developer to review an action a a vulnerability kind of in secret.
They're actually, it becomes part of the core kind of sprint planning process as well. We really see teams potentially sitting around security in Jira as part of their sprint planning and selecting which vulnerabilities they wanna start to action today. Well, these vulnerabilities can appear more than just in what developer the code developers are creating, right?
You may be, uh, upgrading to a new version of an open source package Yeah. That you're using and so they can be introduced from multiple sources, not just for your, from your own developers. Absolutely.
Yeah. And this kinda comes into that second point there is like, there's open source risks, there's infrastructure risks, so there's runtime risks and, and this is why we've taken a, an approach of not only being open but having five partners to launch the, the capability with on the 6th of June because we wanna make sure that we cover that full software development life cycle from day one. Well, and, and, and I think that's something important to highlight because, you know, amend with doing kind of SAS testing, um, and I believe it's Stack Hawk that's doing more das dynamic testing in, in, in the, and corporate integrating into the, um, into Bitbucket and into the I D E.
So, so you haven't just picked five people random, it seems pretty logical that, you know, infrastructure application code there, there are multiple places in the life cycle on kind of software stack that these five hit pretty well, I think. Absolutely. And this is where that filtering and then being able to manage like, um, different views of all of the security vulnerabilities that are funneling into Jira is that across five tools, uh, if you are integrated into, let's say even three or four of them, you're gonna have a lot of vulnerabilities streaming through into your system.
Um, and in addition to that, you're gonna wanna rank or the which ones are low that we can take a slower time to resolve versus the high and critical ones that we need an action today. Um, so we kind of really overindex in regards to providing deep filtering there for teams to very easily, um, work out right what actually is top of mind for us across, you know, IAC or sast or S C a, um, for example. And once those issues are linked into security in Jira, um, we also visualize the state of that issue as well.
So now you've got your vulnerabilities and you can also see what Jira issues being linked to it and what the state and who the assignee is to that. So you have basically your dashboard transforms in from a, a set of, uh, vulnerabilities all going red into uh, a bit of a mission control dashboard for you to have clarity over who's resolving it and how quickly it's being done. Mm-hmm.
Great. Um, so is, um, security and Jira, is this a new feature people have to buy and pay for? Is this something that comes, um, with your JIRA's, uh, software cloud account?
How does that work? Yeah, it's a great question. So, um, it is a free capability inside of Jira software, um, and all you need to do is be a, a user of one of those five providers in order for the two to link up and your team to start being able to, to leverage that capability.
Um, if you are new to security, and this is something that seems interesting to your team to explore and you wanna be more aware of your risk posture, um, we've made it really easy to onboard into Secur one of those security tools as well. So inside of the security and Jira tab, you'll start to see that appear within your instance. Um, and you can select one of our five vendors and very easily within two, two clicks, install it into your environment.
Um, and then you can onboard into becoming one of the users of let's say sneak men your stack. Mm-hmm. And it seems like if you're an existing user, maybe two or three or multiple of those tools, it's an easy way to bring those together, even if you aren't using Jira yet, sign up for a free account, right.
Check it out, integrate with those tools. Correct. Yeah, absolutely.
And look, we, we've really tried to work out that sense that integrations are hard for so many cases. Teams, um, pre, pre previous to security in Jira had to write custom code to link up all of their security tools and then create kind of pseudo workflows outside of Jira tweet and get them into their Jira environment. Um, so we've tried to remove all of that clutter for teams to manage and just make it a really simple plug and play operation so you can get onboarded really quickly, um, and start managing your security vulnerabilities and get more of that visibility into, um, into your risk.
You know, it's something I'd love to hear more about too is one of the fundamental thing, fundamental things about DevOps is it's a lot of it is about automation, right? Cuz you're doing so many tasks repetitively you're doing at at them at high velocity too, right? You can't do 'em manually.
Say some more about some of the automation capabilities of Jira Automation's. Our extensive automations engine enables teams to really easily, um, keep tickets up to date on a daily basis without any kind of, um, team members or kind of human intervention there. We know that it's hard for teams to jump into Jira and update, um, issue statuses as they do a deployment, conduct a pool request, um, or any of those kind of actions.
So through automations, once that takes place inside of a developer, the developer tool, we reflect that chain straight away inside of Jira. So you no longer have to take, we take out that busy work of having to keep tickets up to date always. Okay.
Very good. Very good. I would imagine you're probably not stopping at five.
There might be some more down the road, uh, for other security vendors I might be interested in participating. Yeah, absolutely. We're continuing to invest in security in Jira and um, and we, we really welcome additional vendors to, to review our open APIs and get in touch with us if, if this is something that seems right for their team, for, for their company to, to integrate into.
Okay, very good. Notice you have really nice blog posts, videos, some diagrams, uh, and uh, kind of animation that shows, shows what it looks like inside Jira. So we'll put a link to that blog post in the description for folks that are watching the video and you go check it out there.
com will be covering some of the announcement as well, so there'll be lots of good things to read about it. Great. Anything Andrew that we didn't cover you wanted to touch on?
I Think we've covered everything there. I think I would end on is that if you're an active Jira software user, you'll start to see the security, the Jira tab appear inside of your, um, project from the 6th of June onwards. And I really, um, endorse you to give it a shot and, uh, explore.
Okay, very good. Andrew, Andrew pci, thank you very much. Senior product manager, DevOps with Jira software at Atlassian.
We hope you'll come back soon and we'll hear about other great things that are happening there. Really Appreciate it. Thank you Mitch, for the time.
You bet. Thanks Andrew.