---
title: SecurityFrameworkReference type | Wartiva GraphQL API
description: A security framework and the slice of its taxonomy something is filed under — one policy rule. Wartiva GraphQL API reference with arguments, fields, and examples.
url: https://wartiva.com/api-docs/types/security-framework-reference.html
updated: 2026-10-07
---

Policies and findings · GraphQL type

# `SecurityFrameworkReference` type

A security framework and the slice of its taxonomy something is filed under — one policy rule, or the whole rule catalog when returned by the `securityFrameworks` query.

The nesting is the filing: a product listed here is one this framework publishes, and the sections under it are sections of that product. Nothing has to be joined against a separate ownership table to walk it.

## Fields

| Field Name | Description |
|---|---|
| `framework` - [`SecurityFramework`](https://wartiva.com/api-docs/types/security-framework.html) | The framework. See [SecurityFramework](https://wartiva.com/api-docs/types/security-framework.html). Null when this deployment has no definition for the framework; read `frameworkId` for the filing itself. The rest of the taxonomy still resolves. |
| `frameworkId` - [`SecurityFrameworkId!`](https://wartiva.com/api-docs/types/security-framework-id.html) | The framework's id, always present. Read this rather than `framework.id` when reconstructing a [SecurityFrameworkReferenceInput](https://wartiva.com/api-docs/types/security-framework-reference-input.html): the descriptor above is null when the deployment has no definition for the framework, but the filing itself is still this id. |
| `categories` - [`[SecurityCategoryReference!]`](https://wartiva.com/api-docs/types/security-category-reference.html) | The products of this framework that are filed under it. A product with no sections filed under it is still listed, carrying an empty `subCategories`. |

## Used by

- [`Rule`](https://wartiva.com/api-docs/types/rule.html) type: A policy rule evaluated against graph objects.
- [`SecurityFrameworksPayload`](https://wartiva.com/api-docs/types/security-frameworks-payload.html) type: The security taxonomy matching a SecurityFrameworksInput.

## Example

### Example

```json
{
  "framework": SecurityFramework,
  "frameworkId": "CIS",
  "categories": [SecurityCategoryReference]
}

```

---

Wartiva is in early access. Request access: https://wartiva.com/early-access.html  
All pages: https://wartiva.com/llms.txt
