A security framework: the published control set an organization is assessed against.
This is the framework itself. What is filed under it — the products and sections a rule, or the whole rule catalog, is assessed against — is carried by SecurityFrameworkReference.
Fields
| Field Name | Description |
|---|---|
id - SecurityFrameworkId!
|
The unique identifier for the security framework. |
label - String!
|
The display name of the framework, such as "Center for Internet Security". |
description - String!
|
What the framework covers and how its controls are structured. |
Used by
SecurityCategoryReferencetype: One product of a security framework and the sections within it something is filed under.SecurityFrameworkReferencetype: A security framework and the slice of its taxonomy something is filed under — one policy rule, or the whole rule catalog when returned by the…SecuritySubCategoryReferencetype: One section of a product something is filed under.
Example
Example
{
"id": "CIS",
"label": "xyz789",
"description": "xyz789"
}