Policies and findings · GraphQL type

SecurityFrameworkReference type

A security framework and the slice of its taxonomy something is filed under — one policy rule, or the whole rule catalog when returned by the securityFrameworks query.

The nesting is the filing: a product listed here is one this framework publishes, and the sections under it are sections of that product. Nothing has to be joined against a separate ownership table to walk it.

Fields

Field Name Description
framework - SecurityFramework

The framework. See SecurityFramework.

Null when this deployment has no definition for the framework; read frameworkId for the filing itself. The rest of the taxonomy still resolves.

frameworkId - SecurityFrameworkId! The framework's id, always present. Read this rather than framework.id when reconstructing a SecurityFrameworkReferenceInput: the descriptor above is null when the deployment has no definition for the framework, but the filing itself is still this id.
categories - [SecurityCategoryReference!] The products of this framework that are filed under it. A product with no sections filed under it is still listed, carrying an empty subCategories.

Used by

  • Rule type: A policy rule evaluated against graph objects.
  • SecurityFrameworksPayload type: The security taxonomy matching a SecurityFrameworksInput.

Example

Example

{
  "framework": SecurityFramework,
  "frameworkId": "CIS",
  "categories": [SecurityCategoryReference]
}