Has anyone found utility in creating a JIRA issuetype & workflow specifically for security issues or is it easier to use custom fields & the right post functions, etc?
For security-related issues, phrases such as ISO-2700 governance come to mind…
Security issues can be triaged differently... something where having a unique workflow has use. I am also thinking that issue security might be easier to manage.
A security issue may be determined to be a defect or a configuration (just two possibilities). Should the issue type be then changed to defect or configuration if these respective issue types have their own distinct workflows? When it comes to reporting, I do note that JQL does not support CHANGED or WAS operators for the Type field.