scf_update_compensating_control
Update a vendor compensating control by modifying its gap description, control text, effectiveness rating, or risk-reduction notes to reflect current mitigation status.
Instructions
Update a vendor compensating control (write — editor role). Only passed fields change: gap description, control text, effectiveness rating, risk-reduction notes.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| cc_id | Yes | Compensating control UUID — obtain from scf_list_compensating_controls | |
| org_id | Yes | Organization UUID — obtain from scf_list_organizations | |
| vendor_id | Yes | Vendor UUID — obtain from scf_list_vendors | |
| gap_description | No | The gap the control offsets | |
| compensating_control | No | The control that offsets the gap | |
| effectiveness_rating | No | Effectiveness (default partial) | |
| risk_reduction_notes | No | How much residual risk this removes |