---
title: SecurityFramework type | Wartiva GraphQL API
description: A security framework: the published control set an organization is assessed against. This is the framework itself.
url: https://wartiva.com/api-docs/types/security-framework.html
updated: 2026-10-07
---

Policies and findings · GraphQL type

# `SecurityFramework` type

A security framework: the published control set an organization is assessed against.

This is the framework itself. What is filed under it — the products and sections a rule, or the whole rule catalog, is assessed against — is carried by [SecurityFrameworkReference](https://wartiva.com/api-docs/types/security-framework-reference.html).

## Fields

| Field Name | Description |
|---|---|
| `id` - [`SecurityFrameworkId!`](https://wartiva.com/api-docs/types/security-framework-id.html) | The unique identifier for the security framework. |
| `label` - [`String!`](https://wartiva.com/api-docs/types/string.html) | The display name of the framework, such as "Center for Internet Security". |
| `description` - [`String!`](https://wartiva.com/api-docs/types/string.html) | What the framework covers and how its controls are structured. |

## Used by

- [`SecurityCategoryReference`](https://wartiva.com/api-docs/types/security-category-reference.html) type: One product of a security framework and the sections within it something is filed under.
- [`SecurityFrameworkReference`](https://wartiva.com/api-docs/types/security-framework-reference.html) type: A security framework and the slice of its taxonomy something is filed under — one policy rule, or the whole rule catalog when returned by the…
- [`SecuritySubCategoryReference`](https://wartiva.com/api-docs/types/security-sub-category-reference.html) type: One section of a product something is filed under.

## Example

### Example

```json
{
  "id": "CIS",
  "label": "xyz789",
  "description": "xyz789"
}

```

---

Wartiva is in early access. Request access: https://wartiva.com/early-access.html  
All pages: https://wartiva.com/llms.txt
