openapi: 3.2.0 info: title: Tech Risk & Compliance - IT Risk Management Controls API description: The IT Risk Management API provides comprehensive REST endpoints for managing enterprise security controls, threats, vulnerabilities, and their implementations with OAuth2 security and extensive customization capabilities. version: '1.0' contact: name: OneTrust Support url: https://my.onetrust.com/s/contactsupport license: name: Apache 2.0 url: https://www.apache.org/licenses/LICENSE-2.0 servers: - url: https://{hostname} variables: hostname: default: hostname description: The OneTrust hostname such as app.onetrust.com, app-eu.onetrust.com, app-de.onetrust.com, app-uk.onetrust.com, app-apac.onetrust.com, trial.onetrust.com, or uat.onetrust.com. tags: - name: Controls description: APIs to manage the complete control lifecycle including creation, updates, deletion, retrieval, and entity type management with framework integration and custom attributes. externalDocs: description: OpenAPI 3.1.0 - Download Definition url: https://developer.onetrust.com/onetrust/openapi/tech-risk-compliance-it-risk-management.json x-displayName: Controls paths: /api/controls/v1/controls: post: operationId: addControlUsingPOST summary: Create Control description: Use this API to create a new control in the Controls Library. tags: - Controls x-onetrust: spec-label: https://developer.onetrust.com/onetrust/openapi/tech-risk-compliance-it-risk-management.json requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/TechRiskCompliance-ITRiskManagement_ControlCreateRequestDto' responses: '201': description: Created content: application/json: schema: $ref: '#/components/schemas/TechRiskCompliance-ITRiskManagement_IdResponseUUID' '400': description: Bad Request '401': description: Unauthorized '403': description: Forbidden '429': description: "Too Many Requests. \nFor more information, see [API Rate Limits](https://developer.onetrust.com/onetrust/reference/rate-limits-overview)." headers: Retry-After: schema: description: The number of seconds after which requests will be allowed again. format: int32 ot-period: schema: description: The unit of time for which the rate limit applies enum: - HOUR - MINUTE ot-ratelimit-event-id: schema: description: The unique identifier for the rate-limiting event. format: uuid ot-request-made: schema: description: The number of requests made within the specified period. format: int32 ot-requests-allowed: schema: description: The number of requests allowed within the specified period. format: int32 '500': description: Internal Server Error security: - TechRiskCompliance-ITRiskManagement_OAUTH2: - CONTROL /api/controls/v1/controls/pages: post: operationId: findControlsByCriteriaUsingPOST_1 summary: Get List of Controls description: Use this API to retrieve a list of all controls by key terms and filters. The response will include relevant details for each control, including framework and category details and associated attributes. tags: - Controls x-onetrust: spec-label: https://developer.onetrust.com/onetrust/openapi/tech-risk-compliance-it-risk-management.json parameters: - name: page in: query description: Results page to be retrieved (0..N) schema: type: integer format: int32 default: 0 minimum: 0 example: 0 - name: size in: query description: Number of records per page schema: type: integer format: int32 default: 20 maximum: 2000 minimum: 1 example: 20 - name: sort in: query description: 'Sorting criteria in the format: property(,asc|desc). Default sort order is ascending' schema: type: string enum: - identifier,asc - identifier,desc - name,asc - name,desc - frameworkName,asc - frameworkName,desc - status,asc - status,desc - categoryName,asc - categoryName,desc - createdDate,asc - createdDate,desc - lastModifiedDate,asc - lastModifiedDate,desc example: name,asc requestBody: content: application/json: schema: $ref: '#/components/schemas/TechRiskCompliance-ITRiskManagement_SearchCriteriaInformation' responses: '200': description: OK content: application/json: schema: $ref: '#/components/schemas/TechRiskCompliance-ITRiskManagement_PageControlDto' '400': description: Bad Request '401': description: Unauthorized '403': description: Forbidden '429': description: "Too Many Requests. \nFor more information, see [API Rate Limits](https://developer.onetrust.com/onetrust/reference/rate-limits-overview)." headers: Retry-After: schema: description: The number of seconds after which requests will be allowed again. format: int32 ot-period: schema: description: The unit of time for which the rate limit applies enum: - HOUR - MINUTE ot-ratelimit-event-id: schema: description: The unique identifier for the rate-limiting event. format: uuid ot-request-made: schema: description: The number of requests made within the specified period. format: int32 ot-requests-allowed: schema: description: The number of requests allowed within the specified period. format: int32 '500': description: Internal Server Error security: - TechRiskCompliance-ITRiskManagement_OAUTH2: - CONTROL /api/controls/v1/controls/{controlId}: put: operationId: updateControlUsingPUT_1 summary: Update Control description: Use this API to update the attributes of a specific control in the Controls Library. tags: - Controls x-onetrust: spec-label: https://developer.onetrust.com/onetrust/openapi/tech-risk-compliance-it-risk-management.json parameters: - name: controlId in: path description: ID of the control. This value is obtained using [Get List of Controls](/onetrust/reference/findcontrolsbycriteriausingpost_1) API. required: true schema: type: string format: uuid requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/TechRiskCompliance-ITRiskManagement_ControlUpdateRequestDto' responses: '200': description: OK content: application/json: schema: $ref: '#/components/schemas/TechRiskCompliance-ITRiskManagement_ControlDetailInformation' '400': description: Bad Request '401': description: Unauthorized '403': description: Forbidden '429': description: "Too Many Requests. \nFor more information, see [API Rate Limits](https://developer.onetrust.com/onetrust/reference/rate-limits-overview)." headers: Retry-After: schema: description: The number of seconds after which requests will be allowed again. format: int32 ot-period: schema: description: The unit of time for which the rate limit applies enum: - HOUR - MINUTE ot-ratelimit-event-id: schema: description: The unique identifier for the rate-limiting event. format: uuid ot-request-made: schema: description: The number of requests made within the specified period. format: int32 ot-requests-allowed: schema: description: The number of requests allowed within the specified period. format: int32 '500': description: Internal Server Error security: - TechRiskCompliance-ITRiskManagement_OAUTH2: - CONTROL delete: operationId: removeControlUsingDELETE_1 summary: Delete Control description: Use this API to delete an existing control from the Controls Library. tags: - Controls x-onetrust: spec-label: https://developer.onetrust.com/onetrust/openapi/tech-risk-compliance-it-risk-management.json parameters: - name: controlId in: path description: ID of the control. This value is obrtained using [Get List of Controls](/onetrust/reference/findcontrolsbycriteriausingpost_1) API. required: true schema: type: string format: uuid responses: '200': description: OK content: application/json: schema: $ref: '#/components/schemas/TechRiskCompliance-ITRiskManagement_ControlRemovalResponse' '400': description: Bad Request '401': description: Unauthorized '403': description: Forbidden '429': description: "Too Many Requests. \nFor more information, see [API Rate Limits](https://developer.onetrust.com/onetrust/reference/rate-limits-overview)." headers: Retry-After: schema: description: The number of seconds after which requests will be allowed again. format: int32 ot-period: schema: description: The unit of time for which the rate limit applies enum: - HOUR - MINUTE ot-ratelimit-event-id: schema: description: The unique identifier for the rate-limiting event. format: uuid ot-request-made: schema: description: The number of requests made within the specified period. format: int32 ot-requests-allowed: schema: description: The number of requests allowed within the specified period. format: int32 '500': description: Internal Server Error security: - TechRiskCompliance-ITRiskManagement_OAUTH2: - CONTROL /api/controls/v2/control-entity-types: get: operationId: getAllEnabledControlEntityTypesUsingGET summary: Get List of Control Entity Source Types description: Use this API to retrieve a list of all control entity source types. tags: - Controls x-onetrust: spec-label: https://developer.onetrust.com/onetrust/openapi/tech-risk-compliance-it-risk-management.json responses: '200': description: OK content: application/json: schema: type: array items: $ref: '#/components/schemas/TechRiskCompliance-ITRiskManagement_ControlEntityTypeInformation' '400': description: Bad Request '401': description: Unauthorized '403': description: Forbidden '429': description: "Too Many Requests. \nFor more information, see [API Rate Limits](https://developer.onetrust.com/onetrust/reference/rate-limits-overview)." headers: Retry-After: schema: description: The number of seconds after which requests will be allowed again. format: int32 ot-period: schema: description: The unit of time for which the rate limit applies enum: - HOUR - MINUTE ot-ratelimit-event-id: schema: description: The unique identifier for the rate-limiting event. format: uuid ot-request-made: schema: description: The number of requests made within the specified period. format: int32 ot-requests-allowed: schema: description: The number of requests allowed within the specified period. format: int32 '500': description: Internal Server Error security: - TechRiskCompliance-ITRiskManagement_OAUTH2: - CONTROL /api/controls/v2/related/control-entity-types: get: operationId: getAllRelatedControlEntityTypesUsingGET summary: Get Related Control Entity Types description: Use this API to retrieve a list of related control entity types. tags: - Controls x-onetrust: spec-label: https://developer.onetrust.com/onetrust/openapi/tech-risk-compliance-it-risk-management.json responses: '200': description: OK content: application/json: schema: type: array items: $ref: '#/components/schemas/TechRiskCompliance-ITRiskManagement_ControlEntityTypeInformation' '400': description: Bad Request '401': description: Unauthorized '403': description: Forbidden '429': description: "Too Many Requests. \nFor more information, see [API Rate Limits](https://developer.onetrust.com/onetrust/reference/rate-limits-overview)." headers: Retry-After: schema: description: The number of seconds after which requests will be allowed again. format: int32 ot-period: schema: description: The unit of time for which the rate limit applies enum: - HOUR - MINUTE ot-ratelimit-event-id: schema: description: The unique identifier for the rate-limiting event. format: uuid ot-request-made: schema: description: The number of requests made within the specified period. format: int32 ot-requests-allowed: schema: description: The number of requests allowed within the specified period. format: int32 '500': description: Internal Server Error security: - TechRiskCompliance-ITRiskManagement_OAUTH2: - CONTROL components: schemas: TechRiskCompliance-ITRiskManagement_IdResponseUUID: type: object properties: id: description: Primary identifier of the created or updated entity, typically a UUID. type: string format: uuid example: 123e4567-e89b-12d3-a456-426614174000 required: - id TechRiskCompliance-ITRiskManagement_ControlUpdateRequestDto: type: object properties: identifier: description: The identifier of the control. type: string example: A.1.1 maxLength: 50 minLength: 1 name: description: The name of the control. type: string example: Control ABC maxLength: 300 minLength: 1 orgGroupId: description: The identifier of the organization the master control is linked to. In general, this is top organization in the org hierarchy. type: string format: uuid example: 1a2b3c4e-5f6g-7h8i-9j0k-1l2m3n4o5p6q description: description: Description of the control. type: string example: Testing Control maxLength: 4000 minLength: 0 recommendation: description: The recommendation status of this control based on Athena logic. type: string example: Recommended maxLength: 500 minLength: 0 frameworkId: description: Identifier of the framework the control is tied to. type: string format: uuid example: 1a2b3c4e-5f6g-7h8i-9j0k-1l2m3n4o5p6q frameworkName: description: Name of the framework the control is tied to. type: string example: NIST maxLength: 500 minLength: 0 frameworkNameKey: description: Identifier used for translation of Framework Name. type: string example: framework.NIST maxLength: 500 minLength: 0 status: description: The new status of the control. This can be Active, Archived, or Pending. type: string example: Active enum: - Active - Archived - Pending categoryId: description: The identifier of the category tied to the control. Optional if no category is needed or if category name is provided. type: string format: uuid example: 1a2b3c4e-5f6g-7h8i-9j0k-1l2m3n4o5p6q categoryName: description: The name of the category tied to the control. Optional if category Id is provided. type: string example: Access Control maxLength: 500 minLength: 0 categoryNameKey: description: Identifier used for translation of category name. Optional if category Id is provided. type: string example: category.AccessControl maxLength: 500 minLength: 0 attributes: description: Custom Attributes type: object additionalProperties: type: array items: $ref: '#/components/schemas/TechRiskCompliance-ITRiskManagement_AttributeValueInformation' implementationGuidance: description: Implementation guidance of control. type: string example: Testing Control scopeId: description: The identifier of the scope associated with this control. type: string format: uuid example: 123e4567-e89b-12d3-a456-426614174000 justificationIds: description: Set of justification identifiers explaining why this control is included in the framework. type: array items: type: string format: uuid description: Set of justification identifiers explaining why this control is included in the framework. example: - 123e4567-e89b-12d3-a456-426614174001 - 123e4567-e89b-12d3-a456-426614174002 uniqueItems: true required: - identifier - name - orgGroupId TechRiskCompliance-ITRiskManagement_ControlEntityTypeInformation: type: object properties: id: description: ID of the entity type. This can be Assets, Entities, Custom Object GUID in the form of String. type: string example: 1a2b3c4e-5f6g-7h8i-9j0k-1l2m3n4o5p6q label: description: Name of the EntityType. type: string example: Assets translationKey: description: Translation Key of EntityType ID. type: string example: Assets moduleName: description: Module Name of EntityType. type: string example: DataMapping seeded: description: The parameter is true for Base Entity Type and false for Custom Object/Entity Types by default. type: boolean example: true required: - id TechRiskCompliance-ITRiskManagement_ControlDetailInformation: type: object properties: id: description: The identifier of the control. type: string format: uuid example: 1a2b3c4e-5f6g-7h8i-9j0k-1l2m3n4o5p6q identifier: description: The identifier of the control. type: string example: A.5.1.1 name: description: The name of the control. type: string example: Control Name description: description: Description of the control. type: string example: Test Controls for Privacy orgGroupId: description: The identifier of the organization the master control is linked to. In general, this is the top organization in the organization hierarchy. type: string format: uuid example: 1a2b3c4e-5f6g-7h8i-9j0k-1l2m3n4o5p6q orgGroupName: description: Organization Group Name of Control. type: string example: ABC Corp frameworkId: description: Identifier (GUID) of the framework on the control. type: string format: uuid example: 1a2b3c4e-5f6g-7h8i-9j0k-1l2m3n4o5p6q frameworkName: description: Framework Name of Control. type: string example: ISO/IEC 27017 frameworkNameKey: description: Framework Name key for Translation. type: string example: framework.key.iso categoryId: description: Identifier (GUID) of the category on the control. type: string format: uuid example: 1a2b3c4e-5f6g-7h8i-9j0k-1l2m3n4o5p6q categoryName: description: Name of the category on the control. type: string example: Privacy categoryNameKey: description: Identifier used for translation of Category Name. type: string example: ControlName seedControlId: description: The identifier of control that was seeded to the Master Control. type: string format: uuid example: 123e4567-e89b-12d3-a456-426614174000 otControlIdentifier: description: Unique OT identifier of Control. type: string format: uuid example: 123e4567-e89b-12d3-a456-426614174001 status: description: The new status of the control. This can be Active, Archived, or Pending. type: string example: Active enum: - Active - Archived - Pending attributes: description: Custom attributes for the control. These attributes are custom to the tenant. type: object additionalProperties: type: array description: Custom attributes for the control. These attributes are custom to the tenant. items: $ref: '#/components/schemas/TechRiskCompliance-ITRiskManagement_ControlAttributeValueInformation' implementationGuidance: description: Implementation guidance of the control requirement. type: string example: Implementation guidance of the control requirement. licensedContentMissing: description: Flag which identify if any licensed content is missing and should obtain the license validation to view all content. type: boolean example: false contentVersion: description: Indicates the content version of this record. type: string example: '1.0' viewOnly: description: Flag indicating if this control is read-only and cannot be modified. type: boolean example: false required: - id - identifier - name - orgGroupId - orgGroupName TechRiskCompliance-ITRiskManagement_ControlDto: type: object properties: id: description: The identifier of the control. type: string format: uuid example: 1a2b3c4e-5f6g-7h8i-9j0k-1l2m3n4o5p6q identifier: description: The identifier of the control. type: string example: A.5.1.1 name: description: The name of the control. type: string example: Control Name description: description: Description of the control. type: string example: Test Controls for Privacy orgGroupId: description: The identifier of the organization the master control is linked to. In general, this is the top organization in the organization hierarchy. type: string format: uuid example: 1a2b3c4e-5f6g-7h8i-9j0k-1l2m3n4o5p6q frameworkId: description: Identifier (GUID) of the framework on the control. type: string format: uuid example: 1a2b3c4e-5f6g-7h8i-9j0k-1l2m3n4o5p6q categoryId: description: Identifier (GUID) of the category on the control. type: string format: uuid example: 1a2b3c4e-5f6g-7h8i-9j0k-1l2m3n4o5p6q categoryName: description: Name of the category on the control. type: string example: Privacy categoryNameKey: description: Identifier used for translation of Category Name. type: string example: ControlName recommendation: description: Specific recommendations for implementing this control. type: string example: Implement multi-factor authentication for all administrative access to systems containing sensitive data orgGroupName: description: Name of the organization group that this control belongs to. type: string example: Information Security seedControlId: description: Reference to the control that was used as a template or source for creating this control. type: string format: uuid example: 123e4567-e89b-12d3-a456-426614174000 deprecated: true otControlIdentifier: description: OneTrust catalog identifier for this control when imported from the OneTrust control catalog. type: string format: uuid example: 123e4567-e89b-12d3-a456-426614174001 frameworkName: description: Name of the framework associated with this control. type: string example: NIST Cybersecurity Framework frameworkNameKey: description: Localization key for the framework name. type: string example: nist_csf_framework status: description: Current status of the control (e.g., Active, Archived, Pending). type: string example: Active enum: - Active - Archived - Pending viewOnly: description: Flag indicating if this control is read-only and cannot be modified. type: boolean example: false attributes: description: Custom attributes for the control. These attributes are custom to the tenant. type: object additionalProperties: type: array description: Custom attributes for the control. These attributes are custom to the tenant. items: $ref: '#/components/schemas/TechRiskCompliance-ITRiskManagement_ControlAttributeValueInformation' implementationGuidance: description: Implementation guidance of the control requirement. type: string example: Implementation guidance of the control requirement. required: - id - identifier - name - orgGroupId - orgGroupName TechRiskCompliance-ITRiskManagement_ControlRemovalResponse: type: object properties: deletedControl: description: List of controls that were deleted. type: array items: $ref: '#/components/schemas/TechRiskCompliance-ITRiskManagement_ControlDetail' nonDeletedControl: description: List of controls that could not be deleted. type: array items: $ref: '#/components/schemas/TechRiskCompliance-ITRiskManagement_ControlDetail' TechRiskCompliance-ITRiskManagement_AttributeValueInformation: type: object properties: id: description: Unique identifier for the attribute option type: string format: uuid example: a34ccec7-1ec0-4d65-9075-bdd0d923f1d1 value: description: Attribute value type: string example: Text Value valueKey: description: Translation key used for localizing the value type: string example: attribute.option.valueKey colorCode: description: Color code associated with the option. Used for score-based attributes. type: string example: red optionSelectionValue: description: Selection score value linked to the option. Used for score-based or numerical-based attributes. type: string example: '3.5' displayLabel: description: Display name for the option, used for external attributes managed by other systems type: string example: United State | San Francisco associatedAttributeValueInformation: description: Associated attribute option information type: array items: $ref: '#/components/schemas/TechRiskCompliance-ITRiskManagement_AssociatedAttributeValueInformation' disabled: description: Indicates whether this attribute option is currently disabled. type: boolean example: false default: 'false' required: - value TechRiskCompliance-ITRiskManagement_SearchCriteriaInformation: type: object properties: filters: description: Filters used in search. type: array items: $ref: '#/components/schemas/TechRiskCompliance-ITRiskManagement_FilterInformation' uniqueItems: true fullText: description: Full text search terms. type: string example: firewall excludeTotalRecordsCount: type: boolean TechRiskCompliance-ITRiskManagement_AssociatedAttributeValueInformation: type: object properties: id: description: Unique identifier for the attribute option type: string format: uuid example: a34ccec7-1ec0-4d65-9075-bdd0d923f1d1 value: description: Attribute value type: string example: Text Value valueKey: description: Translation key used for localizing the value type: string example: attribute.option.valueKey colorCode: description: Color code associated with the option. Used for score-based attributes. type: string example: red required: - value TechRiskCompliance-ITRiskManagement_PageControlDto: type: object properties: content: description: The list of items for the current page. items: $ref: '#/components/schemas/TechRiskCompliance-ITRiskManagement_ControlDto' type: array empty: description: The flag to check if the entity is empty or not. type: boolean example: false first: description: The flag to check if the entity is first entity or not. type: boolean example: true last: description: The flag to check if the entity is last entity or not. type: boolean example: false number: description: The number associated with the result. type: integer format: int32 example: 0 numberOfElements: description: Total number of elements in the result. type: integer format: int32 example: 20 pageable: $ref: '#/components/schemas/TechRiskCompliance-ITRiskManagement_Pageable' sort: $ref: '#/components/schemas/TechRiskCompliance-ITRiskManagement_Sort' totalPages: description: Total number of pages in the result list. type: integer format: int32 example: 5 totalElements: description: Total number of elements in the result. type: integer format: int64 example: 50 size: description: Size of the result list. type: integer format: int32 example: 20 TechRiskCompliance-ITRiskManagement_Sort: type: object properties: empty: description: The flag to check if the result is empty or not. type: boolean example: false sorted: description: The flag to check if the result is sorted or not. type: boolean example: true unsorted: description: The flag to check if the result is unsorted or not. type: boolean example: false title: Sort TechRiskCompliance-ITRiskManagement_ControlCreateRequestDto: type: object properties: identifier: description: The identifier of the control. type: string example: A.1.1 maxLength: 50 minLength: 1 name: description: The name of the control. type: string example: Control ABC maxLength: 300 minLength: 1 orgGroupId: description: The identifier of the organization the master control is linked to. In general, this is top organization in the org hierarchy. type: string format: uuid example: 1a2b3c4e-5f6g-7h8i-9j0k-1l2m3n4o5p6q description: description: Description of the control. type: string example: Testing Control maxLength: 4000 minLength: 0 recommendation: description: The recommendation status of this control based on Athena logic. type: string example: Recommended maxLength: 500 minLength: 0 frameworkId: description: Identifier of the framework the control is tied to. type: string format: uuid example: 1a2b3c4e-5f6g-7h8i-9j0k-1l2m3n4o5p6q frameworkName: description: Name of the framework the control is tied to. type: string example: NIST maxLength: 500 minLength: 0 frameworkNameKey: description: Identifier used for translation of Framework Name. type: string example: framework.NIST maxLength: 500 minLength: 0 status: description: The new status of the control. This can be Active, Archived, or Pending. type: string example: Active enum: - Active - Archived - Pending categoryId: description: The identifier of the category tied to the control. Optional if no category is needed or if category name is provided. type: string format: uuid example: 1a2b3c4e-5f6g-7h8i-9j0k-1l2m3n4o5p6q categoryName: description: The name of the category tied to the control. Optional if category Id is provided. type: string example: Access Control maxLength: 500 minLength: 0 categoryNameKey: description: Identifier used for translation of category name. Optional if category Id is provided. type: string example: category.AccessControl maxLength: 500 minLength: 0 attributes: description: Custom Attributes type: object additionalProperties: type: array items: $ref: '#/components/schemas/TechRiskCompliance-ITRiskManagement_AttributeValueInformation' implementationGuidance: description: Implementation guidance of control. type: string example: Testing Control seedControlId: description: The identifier of an existing control to use as a template for creating this new control. type: string format: uuid example: 123e4567-e89b-12d3-a456-426614174000 importBatchId: description: The identifier of the import batch this control belongs to when importing multiple controls. type: string format: uuid example: 123e4567-e89b-12d3-a456-426614174001 origin: description: The origin or creation method of this control (Manual, Import, API, etc.). type: string example: Manual enum: - BulkImport - Manual - FrameworkImport - FrameworkContentUpdate otControlIdentifier: description: The OneTrust system identifier for this control when importing from the OneTrust catalog. type: string format: uuid example: 123e4567-e89b-12d3-a456-426614174002 required: - identifier - name - orgGroupId - origin TechRiskCompliance-ITRiskManagement_Pageable: type: object properties: offset: description: The page offset. type: integer format: int64 example: 0 pageNumber: description: Page number of the results list (0….N). type: integer format: int32 example: 0 pageSize: description: Number of records per page (0…N). type: integer format: int32 example: 20 paged: description: The flag to check if the result is paged or not. type: boolean example: true sort: $ref: '#/components/schemas/TechRiskCompliance-ITRiskManagement_Sort' unpaged: description: The flag to check if the result is unpaged or not. type: boolean example: false title: Pageable TechRiskCompliance-ITRiskManagement_ControlDetail: type: object properties: id: description: Control GUID. type: string format: uuid example: 1a2b3c4e-5f6g-7h8i-9j0k-1l2m3n4o5p6q identifier: description: Control Identifier. type: string example: A.1.1 name: description: Control Name. type: string example: Control ABC required: - id - identifier - name TechRiskCompliance-ITRiskManagement_ControlAttributeValueInformation: type: object properties: id: description: Attribute option GUID. type: string format: uuid example: 123e4567-e89b-12d3-a456-426614174000 value: description: Attribute option value. type: string example: Text value valueKey: description: Identifier used for translation of an attribute's option value. type: string example: attribute.option.valueKey optionSelectionValue: description: Selection score value linked to the option. Used for score-based or numerical-based attributes. type: string example: '3.5' TechRiskCompliance-ITRiskManagement_FilterInformation: type: object properties: field: description: Field to search on. type: string example: lastCollected operator: description: Operator for search. type: string example: GREATER_THAN enum: - EQUAL_TO - NOT_EQUAL_TO - BETWEEN - GREATER_THAN - LESS_THAN value: description: "The field value used to filter results. If filtering for a range of values, this would be the start of the range and should be used in conjunction with the `toValue` parameter. \nExamples by type: UUID = 'e68d49c4-f11f-4cd9-8f1b-0be8ef945b8f', LocalDate = '2023-01-01', OffsetDateTime = '2023-01-01T00:00:00Z', String = 'Closed', Number = 7." type: object example: '2020-11-10' oneOf: - type: string format: uuid - type: string format: date - type: string format: date-time - type: string - type: number toValue: description: "The field value for the end of the range. This field should be used in conjunction with the `value` parameter. \nExamples by type: LocalDate = '2023-01-01', OffsetDateTime = '2023-01-01T00:00:00Z', String = 'Closed', Number = 7." type: object oneOf: - type: string format: date - type: string format: date-time - type: string - type: number required: - field - value securitySchemes: TechRiskCompliance-ITRiskManagement_OAUTH2: type: oauth2 flows: clientCredentials: tokenUrl: https://{hostname}/api/access/v1/oauth/token scopes: CONTROL: Access to Control Implementation operations for external systems ITRM: Access to ITRM operations for external systems TechRiskCompliance-RiskTemplate_OAUTH2: type: oauth2 flows: clientCredentials: tokenUrl: https://{hostname}/api/access/v1/oauth/token scopes: INTEGRATION: Integration Scope RISK: Risk Scope RISK_READ: Risk read scope TechRiskCompliance-Risk_OAUTH2: type: oauth2 flows: clientCredentials: tokenUrl: https://{hostname}/api/access/v1/oauth/token scopes: RISK: Risk Scope RISK_READ: Risk read scope INTEGRATION: Integration scope x-readme: explorer-enabled: false proxy-enabled: false metrics-enabled: false x-onetrust: spec-label: OpenAPI 3.1.0