Skip to main content

IriusRisk

Visualize Projects, Threats, Weaknesses, Countermeasures, and Users, and monitor changes through queries and alerts.

Installation

Requirements

  • You need the IriusRisk Host URL and an API Token generated in your IriusRisk account.
  • You must have the necessary permissions in JupiterOne to install new integrations.

Configuring IriusRisk

Creating Global and Project Roles with Required Permissions

  1. Click the Settings icon to open the General Settings dropdown.
  2. Select Permissions from the dropdown.
  3. Under the Global Roles tab:
    • Click Create Role.
    • Provide a Name and Description.
    • Enable the following permissions:
      • ALL_USER_UPDATE (User Service)
      • API_ACCESS (APIs Service)
      • PRODUCTS_LIST_ALL (Project Service)
    • Click Create to finalize the role.
  4. Under the Project Roles tab:
    • Click Create Role.
    • Provide a Name and Description.
    • Enable the following permissions:
      • THREAT_VIEW (Threats Service)
      • COUNTERMEASURE_VIEW (Countermeasures Service)
    • Click Create to finalize the role.

Creating a User

  1. Click the Settings icon to open the General Settings dropdown.
  2. Select Users from the dropdown.
  3. Click + Create User.
  4. Provide the First Name and Last Name.
  5. Enter an Email Address.
  6. Set a Password for the user.
  7. Assign the previously created Global Role and Project Role.
  8. Click Create to finalize the user setup.

Generating an IriusRisk API Token

Refer to the official IriusRisk documentation on creating an API token.

Note: The API token should be generated using the user created above, ensuring the required roles are assigned.

Configuring JupiterOne

  1. From the top navigation bar of the J1 Search homepage, go to Integrations.

  2. Search for IriusRisk and select it.

  3. Click the Add Instance button and configure the following settings:

    • Account Name: Enter a name to identify this IriusRisk instance in JupiterOne. When Tag with Account Name is enabled, ingested entities will store this value in tag.AccountName.
    • Description: Provide a description to help your team identify this integration instance.
    • Polling Interval: Choose a suitable polling interval for monitoring, or leave it as DISABLED for manual execution.
    • IriusRisk Host URL: Enter the host URL of your IriusRisk tenant.
    • IriusRisk API Token: Enter the API token generated for use by JupiterOne.
  4. Click Create Configuration to save your settings.

Next Steps

Now that your integration instance is configured, it will begin running based on the polling interval you provided, populating data within JupiterOne.

Refer to our Instance Management Guide to learn more about managing and editing integration instances.