openapi: 3.2.0 info: title: Tech Risk & Compliance - IT Risk Management Evidence Task… description: The IT Risk Management API provides comprehensive REST endpoints for managing enterprise security controls, threats, vulnerabilities, and their implementations with OAuth2 security and extensive customization capabilities. version: '1.0' contact: name: OneTrust Support url: https://my.onetrust.com/s/contactsupport license: name: Apache 2.0 url: https://www.apache.org/licenses/LICENSE-2.0 servers: - url: https://{hostname} variables: hostname: default: hostname description: The OneTrust hostname such as app.onetrust.com, app-eu.onetrust.com, app-de.onetrust.com, app-uk.onetrust.com, app-apac.onetrust.com, trial.onetrust.com, or uat.onetrust.com. tags: - name: Evidence Task Implementations description: APIs to manage evidence collection tasks including implementation retrieval, attachment handling (files, links, notes), and comprehensive search with interval-based collection tracking. externalDocs: description: OpenAPI 3.1.0 - Download Definition url: https://developer.onetrust.com/onetrust/openapi/tech-risk-compliance-it-risk-management.json x-displayName: Evidence Task Implementations paths: /api/controls/v1/evidence-task-implementations/pages: post: operationId: findAllEvidencesBySearchCriteria_1 summary: Get List of Evidence Task Implementations description: Use this API to retrieve a list of all evidence task implementations by entity, such as by assignee, control, and current interval status. The response will include relevant details for each evidence implementation. tags: - Evidence Task Implementations x-onetrust: spec-label: https://developer.onetrust.com/onetrust/openapi/tech-risk-compliance-it-risk-management.json parameters: - name: page in: query description: Results page to be retrieved (0..N) schema: type: integer format: int32 default: 0 minimum: 0 example: 0 - name: size in: query description: Number of records per page schema: type: integer format: int32 default: 20 maximum: 2000 minimum: 1 example: 20 - name: sort in: query description: 'Sorting criteria in the format: property(,asc|desc). Default sort order is ascending' schema: type: string enum: - number,asc - number,desc - name,asc - name,desc - primaryEntityName,asc - primaryEntityName,desc - primaryEntityType,asc - primaryEntityType,desc - collectionInterval,asc - collectionInterval,desc - collectionStartDate,asc - collectionStartDate,desc - lastCollected,asc - lastCollected,desc - currentIntervalStatus,asc - currentIntervalStatus,desc - currentIntervalStartDate,asc - currentIntervalStartDate,desc - currentIntervalEndDate,asc - currentIntervalEndDate,desc - relatedControls,asc - relatedControls,desc - evidenceTaskType,asc - evidenceTaskType,desc - createdDate,asc - createdDate,desc - lastModifiedDate,asc - lastModifiedDate,desc example: name,asc requestBody: content: application/json: schema: $ref: '#/components/schemas/TechRiskCompliance-ITRiskManagement_SearchCriteriaInformation' responses: '200': description: OK content: application/json: schema: $ref: '#/components/schemas/TechRiskCompliance-ITRiskManagement_PageEvidenceImplementationDto' '400': description: Bad Request '401': description: Unauthorized '403': description: Forbidden '429': description: "Too Many Requests. \nFor more information, see [API Rate Limits](https://developer.onetrust.com/onetrust/reference/rate-limits-overview)." headers: Retry-After: schema: description: The number of seconds after which requests will be allowed again. format: int32 ot-period: schema: description: The unit of time for which the rate limit applies enum: - HOUR - MINUTE ot-ratelimit-event-id: schema: description: The unique identifier for the rate-limiting event. format: uuid ot-request-made: schema: description: The number of requests made within the specified period. format: int32 ot-requests-allowed: schema: description: The number of requests allowed within the specified period. format: int32 '500': description: Internal Server Error security: - TechRiskCompliance-ITRiskManagement_OAUTH2: - CONTROL /api/controls/v1/evidence-task-implementations/{evidenceTaskImplementationId}: get: operationId: findEvidenceImplementationsById_1 summary: Get Evidence Task Implementation description: Use this API to retrieve a single evidence implementation by its unique identifier. tags: - Evidence Task Implementations x-onetrust: spec-label: https://developer.onetrust.com/onetrust/openapi/tech-risk-compliance-it-risk-management.json parameters: - name: evidenceTaskImplementationId in: path description: The unique identifier (UUID) of the evidence task implementation. required: true schema: type: string format: uuid example: 123e4567-e89b-12d3-a456-426614174000 responses: '200': description: OK content: application/json: schema: $ref: '#/components/schemas/TechRiskCompliance-ITRiskManagement_EvidenceImplementationDto' '400': description: Bad Request '401': description: Unauthorized '403': description: Forbidden '429': description: "Too Many Requests. \nFor more information, see [API Rate Limits](https://developer.onetrust.com/onetrust/reference/rate-limits-overview)." headers: Retry-After: schema: description: The number of seconds after which requests will be allowed again. format: int32 ot-period: schema: description: The unit of time for which the rate limit applies enum: - HOUR - MINUTE ot-ratelimit-event-id: schema: description: The unique identifier for the rate-limiting event. format: uuid ot-request-made: schema: description: The number of requests made within the specified period. format: int32 ot-requests-allowed: schema: description: The number of requests allowed within the specified period. format: int32 '500': description: Internal Server Error security: - TechRiskCompliance-ITRiskManagement_OAUTH2: - CONTROL /api/controls/v1/evidence-task-implementations/{evidenceTaskImplementationId}/attachments: post: operationId: addEvidenceImplementationAttachment summary: Add Attachments to Evidence Task Implementation description: 'Use this API to attach files, a note or a link to a specific Evidence Task Implementation. > 🗒 Things to Know > > - The files must first be uploaded to the OneTrust application using the Upload File API. The `Id` and `Name` parameter values returned in the Upload File API response are required in the request body for this API.' tags: - Evidence Task Implementations x-onetrust: spec-label: https://developer.onetrust.com/onetrust/openapi/tech-risk-compliance-it-risk-management.json parameters: - name: evidenceTaskImplementationId in: path description: The unique identifier (UUID) of the evidence task implementation. required: true schema: type: string format: uuid example: 123e4567-e89b-12d3-a456-426614174000 requestBody: required: true content: application/json: schema: description: Request containing attachment details to be added to the evidence task implementation. type: string oneOf: - $ref: '#/components/schemas/TechRiskCompliance-ITRiskManagement_EvidenceTaskImplementationAttachmentFileRequest' - $ref: '#/components/schemas/TechRiskCompliance-ITRiskManagement_EvidenceTaskImplementationAttachmentLinkRequest' - $ref: '#/components/schemas/TechRiskCompliance-ITRiskManagement_EvidenceTaskImplementationAttachmentNoteRequest' responses: '200': description: OK '400': description: Bad Request '401': description: Unauthorized '403': description: Forbidden '429': description: "Too Many Requests. \nFor more information, see [API Rate Limits](https://developer.onetrust.com/onetrust/reference/rate-limits-overview)." headers: Retry-After: schema: description: The number of seconds after which requests will be allowed again. format: int32 ot-period: schema: description: The unit of time for which the rate limit applies enum: - HOUR - MINUTE ot-ratelimit-event-id: schema: description: The unique identifier for the rate-limiting event. format: uuid ot-request-made: schema: description: The number of requests made within the specified period. format: int32 ot-requests-allowed: schema: description: The number of requests allowed within the specified period. format: int32 '500': description: Internal Server Error security: - TechRiskCompliance-ITRiskManagement_OAUTH2: - CONTROL components: schemas: TechRiskCompliance-ITRiskManagement_PageEvidenceImplementationDto: type: object properties: content: description: The list of items for the current page. items: $ref: '#/components/schemas/TechRiskCompliance-ITRiskManagement_EvidenceImplementationDto' type: array empty: description: The flag to check if the entity is empty or not. type: boolean example: false first: description: The flag to check if the entity is first entity or not. type: boolean example: true last: description: The flag to check if the entity is last entity or not. type: boolean example: false number: description: The number associated with the result. type: integer format: int32 example: 0 numberOfElements: description: Total number of elements in the result. type: integer format: int32 example: 20 pageable: $ref: '#/components/schemas/TechRiskCompliance-ITRiskManagement_Pageable' sort: $ref: '#/components/schemas/TechRiskCompliance-ITRiskManagement_Sort' totalPages: description: Total number of pages in the result list. type: integer format: int32 example: 5 totalElements: description: Total number of elements in the result. type: integer format: int64 example: 50 size: description: Size of the result list. type: integer format: int32 example: 20 TechRiskCompliance-ITRiskManagement_BasicDetail: type: object properties: id: description: Identifier (GUID) type: string format: uuid example: 1a2b3c4e-5f6g-7h8i-9j0k-1l2m3n4o5p6q name: description: Name type: string example: Entity Name TechRiskCompliance-ITRiskManagement_ControlEntityTypeInformation: type: object properties: id: description: ID of the entity type. This can be Assets, Entities, Custom Object GUID in the form of String. type: string example: 1a2b3c4e-5f6g-7h8i-9j0k-1l2m3n4o5p6q label: description: Name of the EntityType. type: string example: Assets translationKey: description: Translation Key of EntityType ID. type: string example: Assets moduleName: description: Module Name of EntityType. type: string example: DataMapping seeded: description: The parameter is true for Base Entity Type and false for Custom Object/Entity Types by default. type: boolean example: true required: - id TechRiskCompliance-ITRiskManagement_EvidenceTaskImplementationAttachmentNoteRequest: type: object properties: collectionDate: description: The date that the attachment was collected. type: string format: date example: '2021-01-01' documentType: description: The type of attachment. type: string example: FILE enum: - FILE - NOTE - LINK note: description: The note to attach. type: string example: Note name: description: The name of the attachment. type: string example: Attachment Name required: - collectionDate - documentType - name - note TechRiskCompliance-ITRiskManagement_EvidenceTaskImplementationAttachmentFileRequest: type: object properties: collectionDate: description: The date that the attachment was collected. type: string format: date example: '2021-01-01' documentType: description: The type of attachment. type: string example: FILE enum: - FILE - NOTE - LINK evidenceTaskImplementationDocumentRequests: description: The list of files to attach. type: array items: $ref: '#/components/schemas/TechRiskCompliance-ITRiskManagement_EvidenceTaskImplementationDocumentRequest' minItems: 1 required: - collectionDate - documentType - evidenceTaskImplementationDocumentRequests TechRiskCompliance-ITRiskManagement_SearchCriteriaInformation: type: object properties: filters: description: Filters used in search. type: array items: $ref: '#/components/schemas/TechRiskCompliance-ITRiskManagement_FilterInformation' uniqueItems: true fullText: description: Full text search terms. type: string example: firewall excludeTotalRecordsCount: type: boolean TechRiskCompliance-ITRiskManagement_BasicEntityReference: type: object properties: id: description: Identifier of the entity (UUID). type: string format: uuid example: 123e4567-e89b-12d3-a456-426614174000 name: description: The name of the entity. type: string example: Entity Name nameKey: description: Name of the entity used for translation. type: string example: EntityName required: - id - name TechRiskCompliance-ITRiskManagement_AiEvidenceAnalysisResult: type: object properties: overallScore: type: string indicator: type: string enum: - Success - Warning - Error - Empty TechRiskCompliance-ITRiskManagement_EvidenceTaskImplementationAttachmentLinkRequest: type: object properties: collectionDate: description: The date that the attachment was collected. type: string format: date example: '2021-01-01' documentType: description: The type of attachment. type: string example: FILE enum: - FILE - NOTE - LINK url: description: The URL to attach. type: string format: url example: https://example.com/link description: description: The description of the URL. type: string example: Link Description name: description: The name of the attachment. type: string example: Attachment Name required: - collectionDate - description - documentType - name - url TechRiskCompliance-ITRiskManagement_Sort: type: object properties: empty: description: The flag to check if the result is empty or not. type: boolean example: false sorted: description: The flag to check if the result is sorted or not. type: boolean example: true unsorted: description: The flag to check if the result is unsorted or not. type: boolean example: false title: Sort TechRiskCompliance-ITRiskManagement_EvidenceImplementationDto: type: object properties: id: description: GUID of Evidence Implementation. type: string format: uuid example: 1a2b3c4e-5f6g-7h8i-9j0k-1l2m3n4o5p6q number: description: Numeric identifier for Evidence Implementation. type: integer format: int64 example: 123 orgGroup: description: The identifier (GUID) of the organization evidence implementation. $ref: '#/components/schemas/TechRiskCompliance-ITRiskManagement_BasicDetail' primaryEntity: description: Entity Details of the primary implementor. $ref: '#/components/schemas/TechRiskCompliance-ITRiskManagement_EvidenceEntityInformation' primaryEntityName: description: Entity Details of the primary implementor. type: string example: Asset124 evidenceTaskId: description: Master evidence task id. type: string format: uuid example: 123e4567-e89b-12d3-a456-426614174123 name: description: Name of the evidence task. type: string example: Security Updates description: description: Description of the evidence task. type: string example: i) Provide evidence to confirm that periodic security updates are published and communicated to employees and contractors. guidance: description: Guidance of the evidence task. type: string example: For internal users, the security updates communication can be demonstrated by making these policies available to them through the corporate intranet. collectionInterval: description: Entity Details of the primary implementor. type: string example: MONTHLY enum: - ONE_TIME - WEEKLY - BIWEEKLY - MONTHLY - QUARTERLY - BIANNUALY - YEARLY collectionStartDate: description: Start of the collection. type: string format: date example: '2020-11-05' lastCollected: description: Last evidence collected date. type: string format: date example: '2020-11-10' currentIntervalStatus: description: Current interval status. type: string example: InProgress enum: - NotCollected - Collected - OverDue - InProgress currentIntervalEndDate: description: Current interval end date. type: string format: date example: '2020-11-30' assignee: description: List of evidence Assignee. type: array items: $ref: '#/components/schemas/TechRiskCompliance-ITRiskManagement_BasicEntityReference' approver: description: List of evidence approver. type: array items: $ref: '#/components/schemas/TechRiskCompliance-ITRiskManagement_BasicEntityReference' relatedControls: description: Number of related controls. type: integer format: int32 example: 2 related: description: Number of related entities. type: integer format: int32 example: 2 canSplit: description: Flag to indicate if evidence can be split. type: boolean example: true evidenceTaskType: description: Evidence task type. type: string example: SYSTEM enum: - SYSTEM - CUSTOM createdBy: description: The user or operation the control was created by. type: string format: uuid example: 1a2b3c4e-5f6g-7h8i-9j0k-1l2m3n4o5p6q createdDate: description: The date the control implementation was created. type: string format: date-time example: '2020-11-05T22:01:21.200+00:00' lastModifiedBy: description: The user or process the control was last modified by (GUID). type: string format: uuid example: 123e4567-e89b-12d3-a456-426614174001 lastModifiedDate: description: The date the control was last modified. type: string format: date-time example: 2020-11-05T22:01:21.200+00:0 collectedEvidenceCount: description: The count for collected evidences. type: integer format: int32 example: 1 automaticCollection: description: Status of the automatic collection configuration. type: string example: AVAILABLE enum: - CONFIGURED - AVAILABLE - NOT_AVAILABLE deleteType: description: Evidence task implementation delete type. type: string example: SOFT duplicate: description: If similar implementation is present from same master evidence for given control implementation. type: boolean example: false dueDateOffset: description: Offset for the due date in days. type: integer format: int32 example: 5 collectionStartMonth: description: Start month of the collection. type: string example: January aiEvidenceAnalysisResult: description: AI Evidence Analysis Result. $ref: '#/components/schemas/TechRiskCompliance-ITRiskManagement_AiEvidenceAnalysisResult' suggestedSystemAvailable: type: boolean required: - number TechRiskCompliance-ITRiskManagement_Pageable: type: object properties: offset: description: The page offset. type: integer format: int64 example: 0 pageNumber: description: Page number of the results list (0….N). type: integer format: int32 example: 0 pageSize: description: Number of records per page (0…N). type: integer format: int32 example: 20 paged: description: The flag to check if the result is paged or not. type: boolean example: true sort: $ref: '#/components/schemas/TechRiskCompliance-ITRiskManagement_Sort' unpaged: description: The flag to check if the result is unpaged or not. type: boolean example: false title: Pageable TechRiskCompliance-ITRiskManagement_EvidenceTaskImplementationDocumentRequest: type: object properties: attachmentId: description: The unique identifier of the attachment. type: string format: uuid example: 1a2b3c4e-5f6g-7h8i-9j0k-1l2m3n4o5p6q name: description: The name of the attachment. type: string example: Attachment Name required: - attachmentId - name TechRiskCompliance-ITRiskManagement_EvidenceEntityInformation: type: object properties: id: description: The identifier (GUID) of the related entity. type: string format: uuid example: 1ab2fff0-cb80-b560-99a1-4a3b527f61f5 name: description: The name of the entity. type: string example: Asset 305 type: description: The type of the related entity. type: string example: Risks enum: - ControlImplementations - Risks - Assets - ProcessingActivities - Vendors - Entities - Initiatives evidenceEntityType: description: The type of the related entity. $ref: '#/components/schemas/TechRiskCompliance-ITRiskManagement_ControlEntityTypeInformation' orgGroupId: description: The identifier (GUID) of the organization which contains the entity. type: string format: uuid example: 1ab2fff0-cb80-b560-99a1-4a3b527f61f5 controlEntityType: $ref: '#/components/schemas/TechRiskCompliance-ITRiskManagement_ControlEntityTypeInformation' required: - evidenceEntityType - id - name TechRiskCompliance-ITRiskManagement_FilterInformation: type: object properties: field: description: Field to search on. type: string example: lastCollected operator: description: Operator for search. type: string example: GREATER_THAN enum: - EQUAL_TO - NOT_EQUAL_TO - BETWEEN - GREATER_THAN - LESS_THAN value: description: "The field value used to filter results. If filtering for a range of values, this would be the start of the range and should be used in conjunction with the `toValue` parameter. \nExamples by type: UUID = 'e68d49c4-f11f-4cd9-8f1b-0be8ef945b8f', LocalDate = '2023-01-01', OffsetDateTime = '2023-01-01T00:00:00Z', String = 'Closed', Number = 7." type: object example: '2020-11-10' oneOf: - type: string format: uuid - type: string format: date - type: string format: date-time - type: string - type: number toValue: description: "The field value for the end of the range. This field should be used in conjunction with the `value` parameter. \nExamples by type: LocalDate = '2023-01-01', OffsetDateTime = '2023-01-01T00:00:00Z', String = 'Closed', Number = 7." type: object oneOf: - type: string format: date - type: string format: date-time - type: string - type: number required: - field - value securitySchemes: TechRiskCompliance-ITRiskManagement_OAUTH2: type: oauth2 flows: clientCredentials: tokenUrl: https://{hostname}/api/access/v1/oauth/token scopes: CONTROL: Access to Control Implementation operations for external systems ITRM: Access to ITRM operations for external systems TechRiskCompliance-RiskTemplate_OAUTH2: type: oauth2 flows: clientCredentials: tokenUrl: https://{hostname}/api/access/v1/oauth/token scopes: INTEGRATION: Integration Scope RISK: Risk Scope RISK_READ: Risk read scope TechRiskCompliance-Risk_OAUTH2: type: oauth2 flows: clientCredentials: tokenUrl: https://{hostname}/api/access/v1/oauth/token scopes: RISK: Risk Scope RISK_READ: Risk read scope INTEGRATION: Integration scope x-readme: explorer-enabled: false proxy-enabled: false metrics-enabled: false x-onetrust: spec-label: OpenAPI 3.1.0