Policies and findings · GraphQL type

SecurityFramework type

A security framework: the published control set an organization is assessed against.

This is the framework itself. What is filed under it — the products and sections a rule, or the whole rule catalog, is assessed against — is carried by SecurityFrameworkReference.

Fields

Field Name Description
id - SecurityFrameworkId! The unique identifier for the security framework.
label - String! The display name of the framework, such as "Center for Internet Security".
description - String! What the framework covers and how its controls are structured.

Used by

Example

Example

{
  "id": "CIS",
  "label": "xyz789",
  "description": "xyz789"
}