Skip to main content

Requirements Sync

Introduction

Requirements Sync connects the Requirements of your Conviso Platform projects with the external backlog tools used by development teams. It lets AppSec teams turn Secure by Design work into actionable items in the engineering workflow, while keeping traceability between Conviso Platform and the external tracker.

While the standard defect tracker integrations (such as the Jira Integration) focus on vulnerability management, Requirements Sync focuses on project requirements and activities: it mirrors your project's action plan into the external tool and keeps statuses aligned in both directions.

This section is organized in two layers:

LayerPurpose
Requirements Sync overview (this page)Explains the behavior shared by every Requirements Sync provider.
Provider guidesExplain provider-specific setup, hierarchy mapping, permissions, and troubleshooting.

Shared Model

Every Requirements Sync provider starts from the same Conviso Platform model:

Conviso Platform entityPurpose
ProjectGroups the Secure by Design work for an application, product, or initiative.
RequirementRepresents a security requirement that should be planned and tracked.
ActivityRepresents the execution tasks or checks linked to a requirement.

To learn how Projects, Requirements, and Activities work in Conviso Platform, see Requirements.

Each external provider maps this model to its own native hierarchy. For example:

ProviderProject →Requirement →Activity →
JiraEpicStorySub-task
note

The external tracker is the execution workspace. Conviso Platform remains the source of truth for security requirements, evidence, and Secure by Design governance regardless of the provider.

Shared Capabilities

Every Requirements Sync integration supports:

  • Outbound sync — Conviso Platform creates and updates records in the external provider (one item for the project, its requirements, and its activities). Depending on the provider and configuration, these can be nested as a parent/child hierarchy or kept at the same level with metadata references — see the provider guide (for Jira, Sync modes).
  • Inbound status sync — Status changes in the external provider are received and applied back to Conviso Platform (via webhooks) when a matching status mapping exists.
  • Manual Sync — Creates or refreshes the external hierarchy on demand, reconciling created, updated, and removed items.
  • Auto Sync — Sends changes automatically when a project, requirement, or activity is created, updated, or removed.
  • Status mappings — Link Conviso Platform statuses to the external workflow statuses, per entity type (project, requirement, activity).
  • Recent deliveries — Integration logs that record successful syncs, skipped updates, unmapped statuses, and external errors.

Provider Guides

Select the guide for your tool:

ProviderStatusGuide
JiraAvailableJira Requirements Integration
Azure BoardsPlanned
ServiceNowPlanned
ClickUpPlanned
BusinessMapPlanned

Support

If you have questions or need help configuring Requirements Sync, contact the Conviso support team.

Contribute to the Docs

Found something outdated or missing? Help us improve the documentation with a quick suggestion or edit.

How to contribute

Resources

By exploring our content, you'll find resources that will enhance your understanding of the importance of a Security Application Program.

Conviso Blog: Explore our blog, which offers a collection of articles and posts covering a wide range of AppSec topics. The content on the blog is primarily in English.

Conviso's YouTube Channel: Access a wealth of informative videos covering various topics related to AppSec. Please note that the content is primarily in Portuguese.