Use hierarchies to help you visualize how organizations you monitor are related within a parent business entity and to show how your own corporate relationships are structured.
Hierarchies can provide useful context for assessing third-party risk, such as how security policies are inherited across related organizations.
Understand how hierarchies are structured
A hierarchy is a tree-structured visualization of a parent entity and its holdings, each represented by its scorecard. A hierarchy can also include published custom scorecards.
A hierarchy is organized around parent/child relationships between scorecards:
- Parent--The holding company at the top of the hierarchy. In a multinational corporate structure, this is the global holding company.
- Child (subsidiary)--An entity directly under a parent. A child can have only one parent at a time.
A hierarchy is not limited to a fixed number of levels--a child can itself be the parent of its own subsidiaries, and that structure can continue for as many levels as your organization's structure requires.
View a hierarchy for a Scorecard
To see how an organization fits into a hierarchy, go to that scorecard and click Hierarchy in the left navigation.
Note: A hierarchy is not an automated Scorecard feature. An organization initiates the creation of their hierarchy by working with our Support team. If you do not see a hierarchy for a given Scorecard, the organization has not posted one.
The hierarchy is displayed as an expandable tree, starting from the top-level parent. Rows with subsidiaries have an arrow next to them--click the arrow to expand or collapse that organization's subsidiaries.
Note: The tree always shows the full corporate family, no matter which scorecard in the family you navigated from. Clicking an organization's name takes you to that organization's own Hierarchy page, but you'll see the same tree, since it always represents the entire family.
Filter and sort a hierarchy
Use the filtering and sorting tools to modify your view of the hierarchy or highlight specific organizations:
- To find a specific organization in the hierarchy, start typing its name in the search box next to the hierarchy tree.
- Click Filter to open the Filters and Sort panel, where you can refine the view further:
- Under What grade to show, select the grades (A-F) you want to see. Parents or children of the filtered organizations that have different grades appear greyed out.
- Under Industry, select one or more industries to show only organizations in those industries.
- Under Sort By, choose how to order the organizations in the tree: alphabetically (A-Z or Z-A), or by grade (highest to lowest, or lowest to highest). Regardless of the selected order, the parent remains on top.
Selections in the Filters and Sort panel apply automatically as you make them.
Display a hierarchy for your own organization
The Support team performs an exhaustive validation process to ensure accuracy, then displays the hierarchy on the platform.
Note: If your organization has Subsidiary Management enabled, admins can also add and update subsidiaries directly in the platform, without going through Support. Learn about using Subsidiary Management.
To submit your hierarchy structure, submit a Support request with a .csv file or spreadsheet attachment formatted as shown in the following examples.
Format for .csv file
For a .csv file, use the following format:
parent,child
,domain.com,
domain.com,child-domain-01.com
domain.com,child-domain-02.com
domain.com,child-domain-03.com
child-domain-01.com,sub-domain-01.com
child-domain-01.com,sub-domain-02.com
child-domain-01.com,sub-domain-03.com
The top row includes the parent and child columns.
The second row includes a blank column, followed by the domain name and suffix columns.
The next set of rows includes all parent-child pairings at any depth in the hierarchy.
Format for spreadsheet
If you are using a spreadsheet, format it like the following screenshot:
Tips for specifying hierarchy structures
- You can ask Support to send you a template file to help you set up the structure.
- For large hierarchies, create multiple CSV files, each containing no more than 1,000 domains.
- If you make a mistake, upload the original .csv file.
- You can ask Support to modify versions of the structure at any time.
- To include a custom scorecard in the hierarchy, enter the Scorecard's UUID, which you can find in the navigation bar of that scorecard's page.
How hierarchies, Scorecards, and Custom Scorecards are related
Keep the following in mind when you work with hierarchies, scorecards, and custom scorecards:
- Scorecards within a hierarchy do not affect each other's scores. Their Digital Footprints are isolated from each other.
- Hierarchies are based on scorecards. An existing scorecard is required for inclusion in a hierarchy. If a scorecard does not exist, you can create a custom scorecard, which represents a subset of its source Scorecard's Digital Footprint.
- You can divide a source Scorecard into multiple custom scorecards, each representing a different department, and then link them to the parent scorecard in a hierarchy.
- A custom scorecard is independent of a hierarchy, even if it is sourced from a scorecard in the hierarchy.
- A hierarchy feature does not provide any insight into the domains on a scorecard's Digital Footprint.
- A scorecard that redirects to another scorecard cannot be linked directly within a hierarchy; instead, use the destination scorecard.
- Access to the scorecard from the hierarchy still depends on that scorecard being followed, as with any other scorecard.