RiskRecon connector for IBM OpenPages Third Party Risk Management

IBM OpenPages® Third Party Risk Management (TPRM) includes a connector for RiskRecon.

You can use the RiskRecon connector to import cybersecurity ratings and scores for vendors from RiskRecon into OpenPages. You can then view the ratings in OpenPages.

Note: To use the connector, you must meet the following prerequisites:
  • You must have a RiskRecon subscription. Work with RiskRecon to set up access. For more information, contact RiskRecon.
  • You must install the RiskRecon connector. For more information, contact IBM® Support.
When OpenPages imports data from RiskRecon, the import process does the following tasks:
  • Looks for vendors in OpenPages that match the vendors in your RiskRecon portfolio.

    If a vendor in your RiskRecon portfolio does not exist in OpenPages, the job creates a Vendor object.

  • The import process updates the OPSS-RiskRecon-Vendor field group on the Vendor object and creates RiskRecon Ratings objects as children of the Vendor object. TheRiskRecon Ratings objects are created under /BusinessEntity/Library/VRM/VRMLibrary/RiskRecon. The OPSS-RiskRecon-Vendor field group stores the risk ratings and scores at the company level while the RiskRecon Ratings objects store the ratings and scores at the category and subcategory levels.
  • If RiskRecon data exists for the Vendor, the import process updates the OPSS-RiskRecon-Vendor field group and the RiskRecon Ratings objects with the most recent ratings and scores from RiskRecon.

If you remove a vendor from your RiskRecon portfolio, any existing RiskRecon data in OpenPages is not deleted. If you delete a vendor in OpenPages, the vendor is added again when you run the job, unless you also remove the vendor from your RiskRecon portfolio.