---
title: ITSM Data Mapping Guide
description: The following article details the instructions for mapping data fields when creating Destinations in ITSM integrations
---

[Skip to content](https://support.nopsec.com/knowledge/itsm-data-mapping-guide#main-content)

English

Show submenu for translations

![nopsec-full-logo-white.png\]](https://support.nopsec.com/hs-fs/hubfs/Images/Logos/NopSec%20Logos/nopsec-full-logo-white.png?height=40&name=nopsec-full-logo-white.png)

Open main navigation

Close main navigation

- English
  
  Show submenu for translations
- [NopSec.com](https://www.nopsec.com/)

[NopSec.com](https://www.nopsec.com/)

 Welcome to the NopSec Knowledge Base. Start your search below.

- There are no suggestions because the search field is empty.

1. [Knowledge Base](https://support.nopsec.com/knowledge?hsLang=en)
2. [Implementation/Admin Learning Path](https://support.nopsec.com/knowledge/implementation-admin-learning-path?hsLang=en)

# ITSM Data Mapping Guide

## The following article details the instructions for mapping data fields when creating Destinations in ITSM integrations

Data mapping decides what goes into each field of the tickets NopSec creates in Jira or ServiceNow. You set it once per destination, and it applies to every ticket that destination receives from a remediation plan.

This guide is for administrators configuring ITSM destinations. It explains what each type of field needs, which NopSec data fits it, and what the warnings on the mapping screen mean.

### How a mapping rule works

Each rule says: take this **source** (left) and write it into this **destination field** (right). A ticket gets one value per rule, and fields with no rule are left to the destination's own defaults.

The source picker offers up to three groups:

| **Source group** | **What it is** | **When to use it** |
| --- | --- | --- |
| Fixed values | One of the values the destination field itself accepts. Only appears on choice fields. | The same value on every ticket, e.g. Priority = Medium. |
| Fields | A piece of NopSec data, filled in per ticket, e.g. the plan name or owner. | Values that change from ticket to ticket. |
| Templates | A text template that combines several NopSec values into formatted text. | Long text fields such as a description. |

Mapping is set separately for each **Group by** option (Asset, Target, Vulnerability, Vuln Instance, No Grouping), because each option produces a ticket with a different set of data:

- **Asset** grouping creates a ticket for each asset containing all of its vulnerability instances across all of its constituent targets
- **Target** grouping creates a ticket for each target containing all of the vulnerability instances for that target
- **Vulnerability** grouping creates a ticket for each vulnerability containing all of the targets which have that vulnerability
- **Vulnerability Instance** grouping creates a tickets for each vulnerability instance
- **No Grouping** creates a single ticket containing all vulnerability instances

Turn on **Enable Group by option** to make that option available when creating remediation plan tickets.

When you open a destination for the first time, NopSec adds starter rules: one for every field the destination requires, plus suggestions for the title, description, priority and urgency where the destination has them. Starter rules for required fields can't be deleted. Suggested rules can be changed or deleted.

The guide does not cover writing your own templates. Contact your NopSec representative if you need a custom template.

### Types of destination field

NopSec reads the field list straight from your Jira project or ServiceNow table, so the list you see is your own setup, custom fields included. Every field falls into one or more of these types.

| **Type** | **How to recognise it** | **What it needs** |
| --- | --- | --- |
| Required | Listed first in the field picker; its rule has no delete button. | A source. Tickets can't be created without it, so saving is blocked until it has one. |
| Choice | The source picker shows a **Fixed values** group listing the field's options. | A value that exactly matches one of its options. Matching ignores upper and lower case. |
| Needs an internal ID | A warning saying the field needs an internal ID. | An identifier only the destination knows, such as a ServiceNow record ID. A data mapping can't produce it, so expect these values to be rejected. |
| User | A Jira user field, such as Assignee or Reporter. | An email address or display name. NopSec looks the person up in Jira before sending. |
| Plain value | Anything else: text, numbers, dates, labels. | A source of the matching type (see the next section). |

**Why "Fixed values" appears on some rows only:** it lists the options the destination field accepts, and only choice fields have a fixed list of options. Text fields accept any value, so there is nothing to list.

**When a choice value doesn't match:** the ticket is not created. The push fails with an error listing the values the field accepts. A fixed value picked from the list always matches. A NopSec field matches only if every value it can produce is on the list.

### Matching a source to a field

Pick a source that produces the type of value the destination field holds. In the source picker, fields that fit are listed first. Fields that don't fit can still be picked, but the rule shows a warning.

| **NopSec source produces** | **Fits destination fields that hold** |
| --- | --- |
| Text | Text, long text, rich text (HTML) |
| A number | Numbers |
| True/false | True/false |
| A list | Lists, such as Jira labels |
| An object | Structured (JSON) fields |
| Template output | Any field. Templates always produce text. |

Some destination fields are handled by NopSec functions and accept any source. Those never show a type warning.

A type mismatch is a warning, not a block, because the target ITSM platform may convert values on ticket creation. If tickets come out wrong or fail, change the source first.

### Priority, urgency and risk grades

Don't map **Vulnerability Risk Grade** straight into a priority or urgency field unless that field's options use the same words. NopSec grades are Urgent, Critical, High, Medium, Low and None. Most ITSM priority lists use different words, and any grade that doesn't match makes the push fail.

| **Destination field (out-of-the-box options)** | **Risk grades that match** | **Risk grades that fail** |
| --- | --- | --- |
| Jira Priority: Highest, High, Medium, Low, Lowest | High, Medium, Low | Urgent, Critical, None |
| ServiceNow Priority: 1 - Critical, 2 - High, 3 - Moderate, 4 - Low, 5 - Planning | None of them, because the option labels include the number | All six |
| ServiceNow Urgency: 1 - High, 2 - Medium, 3 - Low | None of them, for the same reason | All six |

Your own lists may differ. Open the source picker on the row: the **Fixed values** group shows exactly what your field accepts.

What to do instead, simplest first:

1. Pick one **fixed value** (for example Medium) for every ticket, and let your team re-prioritise in Jira or ServiceNow.
2. Create a destination for each risk grade, and select the appropriate destination when creating the Remediation Action.
3. Ask your Jira or ServiceNow admin to add options that match the NopSec grades.
4. Ask your NopSec contact for a template that translates grades into your field's values.

In ServiceNow, Priority is often calculated from Impact and Urgency. If so, map Urgency (and Impact) rather than Priority.

### Messages on the mapping screen

Red messages block saving, because the push can't succeed as configured. Grey warnings let you save, because only Jira or ServiceNow can say for sure whether the value will be accepted.

| **Message** | **Blocks saving** | **What to do** |
| --- | --- | --- |
| *\[Destination\] requires \[fields\]. Add a rule for each before saving.* | Yes | Add a rule for each field named. |
| *\[Field\] is required by the destination and needs a source* | Yes | Pick a source for that row. |
| *\[Field\] is mapped more than once* | Yes | Keep one rule for that field and delete the others. |
| *\[Field\] needs a source before this can be saved* | Yes | Pick a source, or delete the rule. |
| *Pick a destination field for this source* | Yes | Pick a destination field, or delete the rule. |
| *"\[name\]" is not a field on this destination* | Yes | The field was removed or renamed in Jira or ServiceNow. Pick a field from the list. |
| *"\[value\]" is not one of the values \[field\] accepts* | Yes | The option was removed in the destination. Pick a current one from Fixed values. |
| *\[Field\] has no source and will be skipped* | No | A suggested rule left empty. Pick a source or delete it. |
| *This rule is empty and will be skipped* | No | Fill it in or delete it. |
| *\[Field\] needs an internal ID from the destination, so this value may be rejected* | No | Usually best to delete this rule. See Types of destination field. |
| *\[Field\] expects \[type\], but \[source\] is \[type\]* | No | Pick a source of the matching type. See Matching a source to a field. |

### ITSM Platform-specific notes

#### **Jira**

- The field list comes from the project and issue type the destination points at. A different project can have different fields and options.
- User fields (Assignee, Reporter, custom user pickers) accept an email address or display name. NopSec finds the matching Jira user. If nobody matches, the push fails.
- Group fields accept the group's name.
- Labels is a list field, so map it to a list source or a template.

#### **ServiceNow**

- The field list includes fields inherited from parent tables. An Incident table also shows every Task field, so expect 100+ fields. Type in the picker to search.
- Fields marked mandatory in ServiceNow, or by a data policy, show as required. Fields that the ServiceNow form makes mandatory with a UI policy are not enforced for integrations, so they don't show as required.
- For choice fields you can use either the label ("2 - High") or the stored value ("2"). NopSec converts labels to stored values.
- Reference fields such as Assignment group, Caller or Configuration item need a record ID (sys\_id). They are flagged as needing an internal ID. Leave them out and let ServiceNow assignment rules fill them.
- Fields with a duplicated Column Label also show their underlying Column Name to help identify the correct field to populate.

### Troubleshooting

**Tickets fail with "value '…' is not valid for field …; allowed values: …"** A mapped NopSec field produced a value the choice field doesn't have. This is usually Risk Grade going into Priority. Switch the rule to a fixed value. See Priority, urgency and risk grades.

**A field I added in Jira or ServiceNow isn't in the list** NopSec reads fields from the project or table the destination points at. Check that the field is on that project's create screen (Jira) or on that table (ServiceNow), then reopen the mapping screen.

**I can't delete a rule** The destination requires that field. You can change its source, but the rule must stay.

**The ticket was created but a field is empty** Check the rule isn't showing "will be skipped". Also check the NopSec field has data for that ticket's grouping. For example, target fields can be empty when tickets are grouped by vulnerability. For ServiceNow, check that the field being displayed in a form has the same Column Name as the field being populated in the Mapping.

**I need text that combines several NopSec values** Use a template from the Templates group. If none fits, contact your NopSec representative and ask about custom templates.

- [NopSec Platform 101](https://support.nopsec.com/knowledge/nopsec-platform-101?hsLang=en)
- [Implementation/Admin Learning Path](https://support.nopsec.com/knowledge/implementation-admin-learning-path?hsLang=en)
- [Analyst/Remediator Learning Path](https://support.nopsec.com/knowledge/analyst-remediator-learning-path?hsLang=en#main-content)

    - [Reporting](https://support.nopsec.com/knowledge/analyst-remediator-learning-path?hsLang=en#reporting)
    - [Workflow (Remediation/Exception)](https://support.nopsec.com/knowledge/analyst-remediator-learning-path?hsLang=en#workflow-remediation-exception)
    - [Insights](https://support.nopsec.com/knowledge/analyst-remediator-learning-path?hsLang=en#insights)
    - [Asset Management](https://support.nopsec.com/knowledge/analyst-remediator-learning-path?hsLang=en#asset-management)
- [New Features](https://support.nopsec.com/knowledge/new-features?hsLang=en)
- [Training Videos](https://support.nopsec.com/knowledge/training-videos?hsLang=en)
- [Release Notes](https://support.nopsec.com/knowledge/release-notes?hsLang=en)

[![Chill listening crop-3](https://support.nopsec.com/hs-fs/hubfs/Images/Logos/NopSec-logo-160x160.png?width=24&height=24&name=NopSec-logo-160x160.png "Chill listening crop-3")](https://www.nopsec.com)

NopSec Knowledge Base

Copyright © 2026, NopSec