Controls
Add control to test mapping
Add a control to test mapping.
POST
/
controls
/
{controlId}
/
add-test-to-control
Add control to test mapping
curl --request POST \
--url https://api.vanta.com/v1/controls/{controlId}/add-test-to-control \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"testId": "<string>"
}
'import requests
url = "https://api.vanta.com/v1/controls/{controlId}/add-test-to-control"
payload = { "testId": "<string>" }
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({testId: '<string>'})
};
fetch('https://api.vanta.com/v1/controls/{controlId}/add-test-to-control', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.vanta.com/v1/controls/{controlId}/add-test-to-control",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'testId' => '<string>'
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.vanta.com/v1/controls/{controlId}/add-test-to-control"
payload := strings.NewReader("{\n \"testId\": \"<string>\"\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.vanta.com/v1/controls/{controlId}/add-test-to-control")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"testId\": \"<string>\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.vanta.com/v1/controls/{controlId}/add-test-to-control")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"testId\": \"<string>\"\n}"
response = http.request(request)
puts response.read_body{
"control": {
"id": "a2f7e1b9d0c3f4e5a6c7b8d9",
"externalId": "CRY-104",
"name": "Data encryption utilized",
"description": "Access reviews are performed to ensure that access is appropriate for the user's role and responsibilities.",
"source": "Vanta",
"domains": [
"CRYPTOGRAPHIC_PROTECTIONS"
],
"owner": {
"id": "65e1efde08e8478f143a8ff9",
"emailAddress": "example-person@email.com",
"displayName": "Example Owner"
},
"role": "CONTROLLER",
"customFields": [
{
"label": "Additional context",
"value": "This control is critical for GDPR compliance"
}
],
"creationDate": null,
"modificationDate": null
},
"test": {
"id": "aws-account-access-removed-on-termination",
"name": "AWS accounts deprovisioned when personnel leave",
"lastTestRunDate": "2024-06-18T20:17:38.463Z",
"latestFlipDate": null,
"description": "Verifies that AWS accounts linked to removed users are removed.\n",
"failureDescription": "Some AWS accounts associated with terminated personnel have not been deactivated.",
"remediationDescription": "Remove all accounts listed from AWS.\n",
"version": {
"major": 0,
"minor": 0
},
"category": "Account security",
"integrations": [
"aws"
],
"status": "OK",
"deactivatedStatusInfo": {
"isDeactivated": false,
"deactivatedReason": null,
"lastUpdatedDate": null
},
"remediationStatusInfo": {
"status": "PASS",
"soonestRemediateByDate": null,
"itemCount": 0
},
"owner": null
}
}Authorizations
Bearer authentication header of the form Bearer <token>, where <token> is your auth token.
Path Parameters
Body
application/json
The ID of the test to add to the control.
Related topics
Add control to document mappingRemove control from test mappingRemove control from document mappingTests in VantaAdd owners to resourcesWas this page helpful?
⌘I
Add control to test mapping
curl --request POST \
--url https://api.vanta.com/v1/controls/{controlId}/add-test-to-control \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"testId": "<string>"
}
'import requests
url = "https://api.vanta.com/v1/controls/{controlId}/add-test-to-control"
payload = { "testId": "<string>" }
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({testId: '<string>'})
};
fetch('https://api.vanta.com/v1/controls/{controlId}/add-test-to-control', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.vanta.com/v1/controls/{controlId}/add-test-to-control",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'testId' => '<string>'
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.vanta.com/v1/controls/{controlId}/add-test-to-control"
payload := strings.NewReader("{\n \"testId\": \"<string>\"\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.vanta.com/v1/controls/{controlId}/add-test-to-control")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"testId\": \"<string>\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.vanta.com/v1/controls/{controlId}/add-test-to-control")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"testId\": \"<string>\"\n}"
response = http.request(request)
puts response.read_body{
"control": {
"id": "a2f7e1b9d0c3f4e5a6c7b8d9",
"externalId": "CRY-104",
"name": "Data encryption utilized",
"description": "Access reviews are performed to ensure that access is appropriate for the user's role and responsibilities.",
"source": "Vanta",
"domains": [
"CRYPTOGRAPHIC_PROTECTIONS"
],
"owner": {
"id": "65e1efde08e8478f143a8ff9",
"emailAddress": "example-person@email.com",
"displayName": "Example Owner"
},
"role": "CONTROLLER",
"customFields": [
{
"label": "Additional context",
"value": "This control is critical for GDPR compliance"
}
],
"creationDate": null,
"modificationDate": null
},
"test": {
"id": "aws-account-access-removed-on-termination",
"name": "AWS accounts deprovisioned when personnel leave",
"lastTestRunDate": "2024-06-18T20:17:38.463Z",
"latestFlipDate": null,
"description": "Verifies that AWS accounts linked to removed users are removed.\n",
"failureDescription": "Some AWS accounts associated with terminated personnel have not been deactivated.",
"remediationDescription": "Remove all accounts listed from AWS.\n",
"version": {
"major": 0,
"minor": 0
},
"category": "Account security",
"integrations": [
"aws"
],
"status": "OK",
"deactivatedStatusInfo": {
"isDeactivated": false,
"deactivatedReason": null,
"lastUpdatedDate": null
},
"remediationStatusInfo": {
"status": "PASS",
"soonestRemediateByDate": null,
"itemCount": 0
},
"owner": null
}
}