openapi: 3.2.0 info: title: Tech Risk & Compliance - IT Risk Management Control Links… description: The IT Risk Management API provides comprehensive REST endpoints for managing enterprise security controls, threats, vulnerabilities, and their implementations with OAuth2 security and extensive customization capabilities. version: '1.0' contact: name: OneTrust Support url: https://my.onetrust.com/s/contactsupport license: name: Apache 2.0 url: https://www.apache.org/licenses/LICENSE-2.0 servers: - url: https://{hostname} variables: hostname: default: hostname description: The OneTrust hostname such as app.onetrust.com, app-eu.onetrust.com, app-de.onetrust.com, app-uk.onetrust.com, app-apac.onetrust.com, trial.onetrust.com, or uat.onetrust.com. tags: - name: Control Links description: APIs to create and manage relationships between controls through bulk linking operations with support for various relationship types and custom parameters. externalDocs: description: OpenAPI 3.1.0 - Download Definition url: https://developer.onetrust.com/onetrust/openapi/tech-risk-compliance-it-risk-management.json x-displayName: Control Links paths: /api/controls/v1/links/bulk: post: operationId: bulkCreateLinksUsingPOST summary: Link Controls description: Use this API to link an existing control to one or multiple related controls in the Controls Library. tags: - Control Links x-onetrust: spec-label: https://developer.onetrust.com/onetrust/openapi/tech-risk-compliance-it-risk-management.json requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/TechRiskCompliance-ITRiskManagement_ControlBulkLinkCreateRequest' responses: '201': description: Created content: application/json: schema: type: array items: $ref: '#/components/schemas/TechRiskCompliance-ITRiskManagement_LinkInformation' '400': description: Bad Request '401': description: Unauthorized '403': description: Forbidden '429': description: "Too Many Requests. \nFor more information, see [API Rate Limits](https://developer.onetrust.com/onetrust/reference/rate-limits-overview)." headers: Retry-After: schema: description: The number of seconds after which requests will be allowed again. format: int32 ot-period: schema: description: The unit of time for which the rate limit applies enum: - HOUR - MINUTE ot-ratelimit-event-id: schema: description: The unique identifier for the rate-limiting event. format: uuid ot-request-made: schema: description: The number of requests made within the specified period. format: int32 ot-requests-allowed: schema: description: The number of requests allowed within the specified period. format: int32 '500': description: Internal Server Error security: - TechRiskCompliance-ITRiskManagement_OAUTH2: - CONTROL components: schemas: TechRiskCompliance-ITRiskManagement_LinkTypeInformation: type: object properties: id: description: Link Type Information Identifier type: string format: uuid name: description: Link Type Information Name type: string nameKey: description: Link Type Information Name Key used for translation type: string TechRiskCompliance-ITRiskManagement_LinkInformation: type: object properties: id: description: Link Information Identifier type: string format: uuid sourceId: description: Link Information Source Identifier type: string format: uuid sourceType: description: Link Information Source Type type: string destinationId: description: Link Information Destination Identifier type: string format: uuid destinationType: description: Link Information Destination Type type: string destinationName: description: Link Information Destination Name type: string destinationOrgGroupId: description: Link Information Destination Organization Group Identifier type: string format: uuid linkType: description: Link Information Link Type Information $ref: '#/components/schemas/TechRiskCompliance-ITRiskManagement_LinkTypeInformation' TechRiskCompliance-ITRiskManagement_LinkableEntity: type: object properties: id: description: Linkable Entity Identifier type: string format: uuid example: 1a2b3c4e-5f6g-7h8i-9j0k-1l2m3n4o5p6q type: description: Linkable Entity Type type: string example: Control minLength: 1 name: description: Linkable Entity Name type: string example: Information security policy orgGroupId: description: Linkable Entity Organization Group Identifier type: string format: uuid example: 1a2b3c4e-5f6g-7h8i-9j0k-1l2m3n4o5pe3 required: - id TechRiskCompliance-ITRiskManagement_ControlBulkLinkCreateRequest: type: object properties: source: description: Source linkable. $ref: '#/components/schemas/TechRiskCompliance-ITRiskManagement_LinkableEntity' destinations: description: Destination linkable(s). At least one destination should be provided type: array items: $ref: '#/components/schemas/TechRiskCompliance-ITRiskManagement_LinkableEntity' maxItems: 2147483647 minItems: 1 minLength: 1 uniqueItems: true linkTypeNameKey: description: Specifies the relationship type key type: string example: RelatedControl minLength: 1 parameters: description: Custom Parameters for domain specific processing additionalProperties: type: object type: object required: - destinations - linkTypeNameKey - source securitySchemes: TechRiskCompliance-ITRiskManagement_OAUTH2: type: oauth2 flows: clientCredentials: tokenUrl: https://{hostname}/api/access/v1/oauth/token scopes: CONTROL: Access to Control Implementation operations for external systems ITRM: Access to ITRM operations for external systems TechRiskCompliance-RiskTemplate_OAUTH2: type: oauth2 flows: clientCredentials: tokenUrl: https://{hostname}/api/access/v1/oauth/token scopes: INTEGRATION: Integration Scope RISK: Risk Scope RISK_READ: Risk read scope TechRiskCompliance-Risk_OAUTH2: type: oauth2 flows: clientCredentials: tokenUrl: https://{hostname}/api/access/v1/oauth/token scopes: RISK: Risk Scope RISK_READ: Risk read scope INTEGRATION: Integration scope x-readme: explorer-enabled: false proxy-enabled: false metrics-enabled: false x-onetrust: spec-label: OpenAPI 3.1.0