openapi: 3.2.0 info: title: Tech Risk & Compliance - IT Risk Management Riskโ€ฆ description: The IT Risk Management API provides comprehensive REST endpoints for managing enterprise security controls, threats, vulnerabilities, and their implementations with OAuth2 security and extensive customization capabilities. version: '1.0' contact: name: OneTrust Support url: https://my.onetrust.com/s/contactsupport license: name: Apache 2.0 url: https://www.apache.org/licenses/LICENSE-2.0 servers: - url: https://{hostname} variables: hostname: default: hostname description: The OneTrust hostname such as app.onetrust.com, app-eu.onetrust.com, app-de.onetrust.com, app-uk.onetrust.com, app-apac.onetrust.com, trial.onetrust.com, or uat.onetrust.com. tags: - name: Risk Relationships description: APIs to manage relationships between risks and other entities including threats, vulnerabilities, controls, and inventory items. externalDocs: description: OpenAPI 3.1.0 - Download Definition url: https://developer.onetrust.com/onetrust/openapi/tech-risk-compliance-it-risk-management.json x-displayName: Risk Relationships paths: /api/risk/v2/risks/{riskId}/control-implementations: post: operationId: addControlsToRiskUsingPOST summary: Add Controls to Risk description: Adds control implementations to a risk tags: - Risk Relationships x-onetrust: spec-label: https://developer.onetrust.com/onetrust/openapi/tech-risk-compliance-it-risk-management.json parameters: - name: riskId in: path description: Unique identifier of the risk required: true schema: type: string format: uuid example: 123e4567-e89b-12d3-a456-426614174000 requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/TechRiskCompliance-Risk_RiskControlImplementationsRequest' responses: '201': description: Controls added successfully '400': description: Bad Request '401': description: Unauthorized '403': description: Forbidden '429': description: "Too Many Requests. \nFor more information, see [API Rate Limits](https://developer.onetrust.com/onetrust/reference/rate-limits-overview)." headers: Retry-After: schema: description: The number of seconds after which requests will be allowed again. format: int32 ot-period: schema: description: The unit of time for which the rate limit applies enum: - HOUR - MINUTE ot-ratelimit-event-id: schema: description: The unique identifier for the rate-limiting event. format: uuid ot-request-made: schema: description: The number of requests made within the specified period. format: int32 ot-requests-allowed: schema: description: The number of requests allowed within the specified period. format: int32 '500': description: Internal Server Error security: - TechRiskCompliance-Risk_OAUTH2: - INTEGRATION - RISK /api/risk/v2/risks/{riskId}/threats: post: operationId: addThreatToRisk summary: Add Threat to Risk description: 'Use this API to add or replace a threat on a risk. > ๐Ÿ—’ Things to Know > > - If a threat was previously assigned to the risk, that threat will be replaced with the new specified threat after calling this API.' tags: - Risk Relationships x-onetrust: spec-label: https://developer.onetrust.com/onetrust/openapi/tech-risk-compliance-it-risk-management.json parameters: - name: riskId in: path description: Unique identifier of the risk required: true schema: type: string format: uuid example: 123e4567-e89b-12d3-a456-426614174000 requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/TechRiskCompliance-Risk_RiskThreatAddRequest' responses: '201': description: Threat added or replaced successfully '400': description: Bad Request '401': description: Unauthorized '403': description: Forbidden '429': description: "Too Many Requests. \nFor more information, see [API Rate Limits](https://developer.onetrust.com/onetrust/reference/rate-limits-overview)." headers: Retry-After: schema: description: The number of seconds after which requests will be allowed again. format: int32 ot-period: schema: description: The unit of time for which the rate limit applies enum: - HOUR - MINUTE ot-ratelimit-event-id: schema: description: The unique identifier for the rate-limiting event. format: uuid ot-request-made: schema: description: The number of requests made within the specified period. format: int32 ot-requests-allowed: schema: description: The number of requests allowed within the specified period. format: int32 '500': description: Internal Server Error security: - TechRiskCompliance-Risk_OAUTH2: - INTEGRATION - ITRM /api/risk/v2/risks/{riskId}/vulnerabilities: post: operationId: addVulnerabilitiesToRisk summary: Add Vulnerabilities to Risk description: 'Use this API to add or replace vulnerabilities on a risk. > ๐Ÿ—’ Things to Know > > - If vulnerabilities were previously assigned to the risk, those vulnerabilities will be replaced with the new specified vulnerabilities after calling this API.' tags: - Risk Relationships x-onetrust: spec-label: https://developer.onetrust.com/onetrust/openapi/tech-risk-compliance-it-risk-management.json parameters: - name: riskId in: path description: Unique identifier of the risk required: true schema: type: string format: uuid example: 123e4567-e89b-12d3-a456-426614174000 requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/TechRiskCompliance-Risk_RiskVulnerabilityAddRequest' responses: '201': description: Vulnerabilities added or replaced successfully '400': description: Bad Request '401': description: Unauthorized '403': description: Forbidden '429': description: "Too Many Requests. \nFor more information, see [API Rate Limits](https://developer.onetrust.com/onetrust/reference/rate-limits-overview)." headers: Retry-After: schema: description: The number of seconds after which requests will be allowed again. format: int32 ot-period: schema: description: The unit of time for which the rate limit applies enum: - HOUR - MINUTE ot-ratelimit-event-id: schema: description: The unique identifier for the rate-limiting event. format: uuid ot-request-made: schema: description: The number of requests made within the specified period. format: int32 ot-requests-allowed: schema: description: The number of requests allowed within the specified period. format: int32 '500': description: Internal Server Error security: - TechRiskCompliance-Risk_OAUTH2: - INTEGRATION - ITRM components: schemas: TechRiskCompliance-Risk_RiskControlImplementationsRequest: type: object properties: controlIds: type: array items: format: uuid uniqueItems: true status: description: Status of the control implementation. Can be Pending, Implemented, or NotDoing. Defaults to Pending if not specified type: string example: Pending default: Pending enum: - Pending - Implemented - NotDoing example: controlIds: - a8d2f0c6-63e5-476b-b600-79a447251a2a - b9e3f1d7-74f6-587c-c711-8ab558362b3b status: Pending required: - controlIds TechRiskCompliance-Risk_RiskVulnerabilityAddRequest: type: object properties: vulnerabilityIdList: description: List of unique identifiers of vulnerabilities to be added. If empty, all existing vulnerabilities will be removed from the risk. type: array items: type: string format: uuid description: List of unique identifiers of vulnerabilities to be added. If empty, all existing vulnerabilities will be removed from the risk. example: - 123e4567-e89b-12d3-a456-426614174000 - 987fcdeb-51a2-43d7-9abc-123456789012 required: - vulnerabilityIdList TechRiskCompliance-Risk_RiskThreatAddRequest: type: object properties: threatId: description: Unique identifier of the threat to be added. If null, any existing threat will be removed from the risk. type: string format: uuid example: 123e4567-e89b-12d3-a456-426614174000 securitySchemes: TechRiskCompliance-ITRiskManagement_OAUTH2: type: oauth2 flows: clientCredentials: tokenUrl: https://{hostname}/api/access/v1/oauth/token scopes: CONTROL: Access to Control Implementation operations for external systems ITRM: Access to ITRM operations for external systems TechRiskCompliance-RiskTemplate_OAUTH2: type: oauth2 flows: clientCredentials: tokenUrl: https://{hostname}/api/access/v1/oauth/token scopes: INTEGRATION: Integration Scope RISK: Risk Scope RISK_READ: Risk read scope TechRiskCompliance-Risk_OAUTH2: type: oauth2 flows: clientCredentials: tokenUrl: https://{hostname}/api/access/v1/oauth/token scopes: RISK: Risk Scope RISK_READ: Risk read scope INTEGRATION: Integration scope x-readme: explorer-enabled: false proxy-enabled: false metrics-enabled: false x-onetrust: spec-label: OpenAPI 3.1.0