Table of Contents
Summary
The main RiskRecon vendor scores are already in Whistic automatically through version 2 of our integration! Additionally, you can configure version 1 separately, which links to your RiskRecon vendor profile.
📋 Supported Versions
Version 1 - Overview vendor scoring on the vendor details page only, plus a link to the RiskRecon vendor profile overview page.
Version 2 - Fully automated overview vendor scoring updated daily.
✅ Requirements
If you are interested in version 1, please confirm with your Whistic contact that your account is qualified and prepared for setup, etc.
🔧 Steps
Only version 1 requires configuration
Overview
- RiskRecon Setup
- Whistic Setup
🔑 RiskRecon Setup & API Key Renewal
- Log in to your RiskRecon account.
- Go to My-Account System Administration.
- Navigate to the API Keys tab and click New API Key.
- Create a description. Select key expiration. Click Create API Key.
- Under the API Keys tab, the newly created API Key will appear. Select New.
- Copy the link. Please note that these keys do expire and need to be replaced if you get the following message: Error: Risk Recon is unavailable. Check your API Key and try again.
- Add any vendors to your account that you would like to be pulled into Whistic.
⚙️ Whistic Setup
- From the Resources or Settings dropdown, select Integrations.
- Click on RiskRecon Configure
- Copy your API Key and Save Configuration
- You will now see the Rating tab on every vendor details page.
- If you would like to pull in scores for a vendor, select the Rating tab and then select RiskRecon.
- A pop-up will appear with a search box.
- Type in your vendor, select, and Submit. Your scores will now show perpetually for this vendor.
If you would like to remove the score for this vendor at any point, click the Remove button.
📊 Basic Usage
Overview
- Automated Scores
- Configurable Links
🤖 Automated Scores
(Version 2) There are 3 places this data can be viewed: Vendor Catalog, Vendor Details, and the Reporting page. The rating and score columns can be applied in the Vendor Catalog. On your Reporting page you can also filter by the scores.
If you would like to see the category scores, please click on the vendor and view them in the vendor details under the Rating section.
🔗 Configurable Links
(Version 1) We also have an additional configuration that may be applied, which allows you to do 2 things:
- Links to the vendor overview page in RiskRecon.
- And allows you to sync with any company added to your RiskRecon account portfolio.
Example link:
https://portal.riskrecon.com/portal/vendor/{$1448294}/overview
⚠️ Mismatch Scores
If a score appears to be different in Whistic compared to what you are seeing in RiskRecon, it could be due to a setting that is applied on the RiskRecon side.
We recommend to check and see if the record in RiskRecon is listed as a snapshot. If it is a snapshot, the score will likely be different than what is placed in Whistic as it is a score for a specific time (snapshot) and is not continuously updated.
❓ FAQ
Why are there two RiskRecon sections on my vendor page?
The one at the top is the automated scoring. The one at the bottom is the manually configured section. These cannot be consolidated currently.
Why can't I find Whistic's score in RiskRecon?
In rare instances, it may be difficult to find a corresponding vendor RiskRecon score that Whistic has in your RiskRecon account. This is likely because our integration uses RiskRecon's API instead of their UI, which may not always align. If you have additional questions, feel free to contact RiskRecon or Whistic Support.
Does Whistic adjust the scores in any way?
No, we simply pass them along to you in Whistic!
📈 RiskRecon Rating Methodology
For more information on RiskRecon scoring and methodology, you can download the latest report from this link:
https://www.riskrecon.com/cybersecurity-risk-rating-model
Should you have any questions regarding the information in this file, please reach out to RiskRecon directly at support@riskrecon.com
📄 RiskRecon RatingMethodology.pdf
1 MB Download