Skip to main content

Unicis Apps

CSC — Cybersecurity Controls for Jira - Unicis.Tech OÜ Docs

Multi-framework cybersecurity control tracking and GAP analysis app for Atlassian Jira Cloud.

The Cybersecurity Controls (CSC) for Jira is an enterprise-ready solution that provides a comprehensive set of baseline security controls embedded directly in Jira Cloud. It enables organizations to assess, track, and improve their cybersecurity posture using industry-recognized frameworks, while using existing Jira issues as evidence for control implementation.

Demo

Watch the demo video on Vimeo: https://vimeo.com/792355047 (1

minute)

Supported Frameworks

FrameworkDescription
MVSP v1.0Minimum Viable Secure Product — baseline B2B security checklist
ISO/IEC 27001
& 2022
Information Security Management System
NIST CSF 2.0NIST Cybersecurity Framework
EU NIS2 DirectiveEU Critical Infrastructure Cybersecurity
GDPRGeneral Data Protection Regulation
CIS Controls v8.1CIS Critical Security Controls
SOC 2Service Organization Control 2
C5
Cloud Computing Compliance Controls Catalogue
OWASP ASVSApplication Security Verification Standard

Features

  • Assign the CSC app to one or more Jira projects
  • Link multiple Jira issues as evidence for each control requirement
  • Interactive dashboard with pie chart and radar (maturity) charts
  • Filter controls by section, control name, and status
  • Multi-project support with a unified dashboard across all assigned projects

Requirements

  • Atlassian Jira Cloud (not available for Server or Data Center)
  • Requires read, write, manage, and storage access to your Jira account
  • All data is stored in your Atlassian Cloud instance — not shared with Unicis

Installation

Install from the Atlassian Marketplace.

Configuration

  1. Click AppsManage your apps
  2. Under APPS on the side panel, click Cybersecurity Control Settings
  3. Select your Framework control from the dropdown
  1. Click Add Project to assign Jira projects

Available action per project:

  • Delete — removes the project from CSC

Dashboard

Access the dashboard:

  • Jira Software project: Select Cybersecurity Controls Dashboard on the left sidebar
  • Jira Business project: Select from AppsCybersecurity Control Dashboard in the top menu

Charts

  1. Pie chart — distribution of control statuses as a proportion of all controls
  2. Radar chart — security maturity levels per domain, based on ISO/IEC 21827

Controls Table

ColumnDescription
CodeFramework code, e.g. MVSP-1.1
SectionDomain or section, e.g. Business Controls, Application Design Controls
ControlControl name, e.g. Training, Self-assessment
RequirementsWhat must be set up and put into practice
StatusCurrent maturity level (dropdown)
TicketsLinked Jira issues as evidence (dropdown selection from project issues)

Maturity Levels (ISO/IEC 21827
)

Maturity level is based on ISO/IEC 21827

— Systems Security Engineering — Capability Maturity Model:

StatusMeaning
UnknownHas not been checked yet
Not ApplicableManagement has determined this can be ignored
Not PerformedComplete lack of recognizable policy, procedure, or control
Performed InformallyDevelopment barely started; requires significant work
PlannedProgressing but not yet complete
Well DefinedMostly complete; detail lacking or not yet actively enforced by management
Quantitatively ControlledComplete; implemented and recently started operating
Continuously ImprovingFully satisfied; actively monitored with substantial auditor evidence

Add a Control from a Jira Issue

  1. Open a Jira issue
  2. Click the CSC logo icon in the issue panel menu
  3. Select a control from the dropdown in the format: CODE: Section, Control name
    • Example: MVSP-1.5: Business controls, Training
  4. Click + Add Control to add more controls to the same issue
  5. Click the trash icon next to a specific control to remove it individually

Activity / Audit Log

Access logs by opening the Jira ticket → ActivityActivity logs of CSC.

Log format examples:

[Author] created the Cybersecurity Controls 1/5/2023 3:29:09 PM
[Author] changed the control M/DD/YYYY H:MM AM/PM
  MVSP-1.1, Business controls, Vulnerability reports → MVSP-1.3, Business controls, Self-assessment

Logged events: Initial, Created, Added, Removed, Changed

Pricing

See the Atlassian Apps pricing page.

Permissions

CSC performs the following actions on behalf of the user:

  • Read and write to app storage (App Storage scope)
  • Create and manage Jira issues
  • Create and edit issues in Jira, post comments, create worklogs, and delete issues
  • Manage project settings and create project-level objects (versions, components)
  • View active user profile
  • View Jira project and issue data

Technical Details

Built on Atlassian Forge UI Kit components using:

  • ProjectPage
  • IssuePanel
  • IssueActivity
  • AdminPage

Required OAuth scopes:

read:jira-work
write:jira-work
manage:jira-project
storage:app