Receptors & Integrations

Jira Receptor

Jira Receptor Details

The Jira receptor allows you to attach Jira issues as evidence to controls you select. The issues are determined by a Jira filter or label. To get Jira issues evidence onto a control you have two options:

  1. Create a filter in Jira to select the issues that are relevant and then map the filters to the controls. 
  2. Add a label to Jira issues and map that label to the desired control(s). 

Best Practices

  1. Targeted filters:
    1. Relevant: select Jira issues that are relevant to the particular control you want to link it to. Adding unnecessary Jira issues to a control will make interacting with it, evaluating it, etc., slower. 
    2. Time bound: consider limiting the issues to the relevant time of a given audit. E.g., no need to return all Jira issues, when just getting issues since the beginning of an audit will do.
  2. Specific Labels:
    1. Coherent labels: ensure that the tickets are using the same label. Note: labels in Jira are case sensitive.
    2. Formatted labels: have a descriptive label to identify the label. For example, "Sprint-15_Feb-2025."
  3. Use labels, projects, components or other fields to organize Jira issues. This makes it easier to retrieve the relevant Jira issues for controls by limiting the filter to just a given value on the given field.
  4. More info on Jira filters on the Atlassian support site:
    1. Save your search as a filter
    2. Manage filters

Example Scenario (Filters)

For example, take a control for user access requests:

IAM02 User Access Authorized by Management

Access rights are properly assigned and approved by management based on job title and responsibilities.

It needs a list of user access request issues as evidence. These could be tracked as issues in Jira. To provide evidence for the control, simply create a filter that selects the issues in Jira and associate it with the IAM02 control in the Trustero Jira Receptor.

 

Step 1: create the filter - Jira filter to select access request tickets

 

Step 2: map control(s) to filter(s) - Jira receptor config with IAM02 mapped to access request filter

 

Step 3: Jira issue evidence is automatically added to control(s) - Access request tickets evidence on IAM02 from Jira Receptor

Example Scenario (Labels)

For example, take a control for user access requests:

IAM02 User Access Authorized by Management

Access rights are properly assigned and approved by management based on job title and responsibilities.

It needs a list of user access request issues as evidence. These could be tracked as issues in Jira. To provide evidence for the control, simply label the issues in Jira and associate that label with the IAM02 control in the Trustero Jira Receptor.

Step 1: Tag related issues with the designated label (ex. 2025-UAR)

Step 2: map control(s) to label(s) - Jira receptor config with IAM02 mapped to access request label (ex. 2025-UAR)

Step 3: Jira issue evidence is automatically added to control(s) - Access request tickets evidence on IAM02 from Jira Receptor