If you are an administrator for a scorecard in a hierarchy, you can use Subsidiary Management to view evidence for issue findings for subsidiary scorecards in your hierarchy and to add or remove subsidiaries directly from the platform.
This enhances your ability to manage risk for organizations with a close corporate relationship to yours, such as those with a shared IT infrastructure.
To use Subsidiary Management, confirm that your scorecard is in a hierarchy. Then submit a Support request to enable this feature.
Understand what "finding evidence" is
When we show findings for issue types on a scorecard, we provide evidence, which depends on the specific issue type. For example, in the case of the Email exposed issue type, the evidence includes the compromised email addresses. Evidence on a given scorecard is only visible to:
- An administrator for that scorecard.
- An administrator for any organization above it in the hierarchy--its parent, grandparent, or any other ancestor further up the tree.
An administrator can only view evidence for the subsidiaries beneath their own organization in the hierarchy. They cannot view evidence for the subsidiaries of a peer branch, an organization that shares an ancestor with theirs but is not itself an ancestor.
For example, as seen in the following screenshot, Example Child Corp. 1 and Example Child Corp. 2 are peer subsidiaries of Example Parent Corp. The scorecard administrator for Example Child Corp. 1 can view finding evidence for their own subsidiaries, but not for the subsidiaries of Example Child Corp. 2.
Verify that you are part of a hierarchy
To see if you are part of a Scorecard hierarchy, go to your scorecard and click Hierarchy in the left navigation bar.
Note: A hierarchy is not an automated scorecard feature. An organization initiates the creation of their hierarchy. If you do not see a hierarchy for your scorecard, submit a request to our Support team.
View evidence for findings for a subsidiary
-
In the Hierarchy tab, select an organization that you want to view evidence for.
Tip: If you already know that you are in a hierarchy that includes a given organization, you can just go to the scorecard for that organization.
- Select the Issues tab for that Scorecard and then select an issue type that you want to investigate.
Or
To investigate issues by specific factor, select the Factors tab. Expand the factor that concerns you, then select an issue type within that factor. - On the issue details page, scroll down to the Findings table.
- Note any findings that concern you and then use the bar above the table to scroll to the right.
- Review the values in the Evidence column.
In the Email exposed issue type example, evidence consists of compromised emails.
Take action on issue findings for subsidiaries
After investigating evidence for findings that concern you, take the following actions to help your subsidiary resolve them:
- Send them an Action Plan targeted at issue resolution.
- Contact them to discuss the issues and how they affect your organization and possibly others in the hierarchy.
- Send them a questionnaire to vet the security controls they have in place to address the issues.
Add a subsidiary to your hierarchy
To add one or more subsidiaries to your hierarchy directly from the platform:
- Go to your Scorecard, click Hierarchy in the left navigation, and click Add Subsidiaries.
- In the Add Subsidiaries panel, confirm the Parent organization. This defaults to your organization, but you can choose a different organization already in your hierarchy.
- Use the Subsidiary search box to find and add the organization or organizations you want to add under that parent. Each one you add appears in a list below the search box, where you can remove it before submitting if you added it by mistake.
- If you have a large number of changes to make, use Get current .csv to download your existing hierarchy, and Upload changes to submit a revised .csv instead of adding subsidiaries one at a time.
- Click Add Subsidiaries to submit your changes. Note that:
- The button stays disabled until you've added at least one subsidiary.
- Adding a subsidiary gives the parent organization limited access to the subsidiary's scorecard. The parent organization must have at least 50% ownership of the subsidiary.
- All changes are reviewed before they take effect.
Manage a subsidiary from the hierarchy tree
With Subsidiary Management enabled, each row in the hierarchy tree has a menu (click the ⋮ icon) with the following options. Which options are available depends on that row's position in the hierarchy:
- Add Company Parent (or Change Company Parent if the row already has one): Set or change which organization this row reports to.
- Add Company Child: Attach a new subsidiary underneath this row.
- Users: Jump to the list of users at that subsidiary. Only available for organizations you've been granted ownership access to.
- Remove From Hierarchy: Detach this row from its parent. Only available for rows that currently have a parent; it's unavailable for a top-level organization, since there's nothing to remove it from.
- Select for removal: Mark this row to remove it in bulk. Selected rows are grouped together for you to review and submit at once.