openapi: 3.2.0 info: title: Palo Alto Networks Compliance Frameworks API contact: email: support@paloaltonetworks.com name: Palo Alto Networks Technical Support url: https://support.paloaltonetworks.com license: name: MIT url: https://opensource.org/license/mit termsOfService: https://www.paloaltonetworks.com/content/dam/pan/en_US/assets/pdf/legal/palo-alto-networks-end-user-license-agreement-eula.pdf version: '1.0' description: 'Operations tagged Compliance Frameworks across 2 of this provider''s published API definitions: palo-alto-scm-config-posture-management-compliance-framework-compliance-center-recent-v1-openapi.yaml, palo-alto-scm-config-posture-management-posture-openapi.yaml. Each path carries the servers of the definition it was published in.' servers: - url: https://api.strata.paloaltonetworks.com/posture/compliance-frameworks/v1 description: Current - url: https://api.strata.paloaltonetworks.com/posture description: Current security: - BearerAuth: [] tags: - name: Compliance Frameworks description: Operations for managing compliance framework definitions including CRUD, clone, benchmark, and release operations. paths: /definitions: get: tags: - Compliance Frameworks summary: List Compliance Frameworks description: Retrieve all compliance frameworks for the user's TSG operationId: getAllFrameworks security: - BearerAuth: [] parameters: - name: category in: query required: false schema: type: string enum: - PCF - CCF - all description: Filter by framework category PCF (Palo Alto Networks) or CCF (Custom) example: PCF - name: status in: query required: false schema: type: string enum: - draft - released description: Filter by framework status example: released responses: '200': description: Success content: application/json: schema: type: object properties: data: type: array description: Array of compliance frameworks with full definitions items: type: object properties: id: type: string description: Compliance framework ID name: type: string description: Compliance framework name description: type: string description: Framework description source_url: type: string description: Source URL of the framework source: type: string description: Framework source/origin category: type: string description: Framework category enum: - PCF - CCF status: type: string description: Framework status enum: - draft - released releasable: type: boolean description: Whether the framework can be released hierarchy_header: type: object description: Hierarchy header metadata defining levels and groups properties: levels: type: array items: type: object properties: title: type: string name: type: string description: type: string groups: type: array items: type: object properties: group: type: string name: type: string description: type: string color: type: string hierarchy_data: type: object description: Hierarchical control structure properties: children: type: array items: $ref: '#/components/schemas/ControlNode' logo: type: object description: Framework logo image properties: image: type: string description: Base64 encoded image data type: type: string description: Image MIME type name: type: string description: Image filename created_at: type: string format: date-time description: Creation timestamp updated_at: type: string format: date-time description: Last update timestamp example: data: - id: PCF-7f1ae852-f5a4-40ed-911a-88d54ebf8876 name: CSCV8 description: Center for Internet Security Controls Version 8 source_url: https://www.cisecurity.org/controls/cis-controls-list source: CIS category: PCF status: released releasable: true hierarchy_header: levels: - title: Level1 name: Control description: Top level security controls - title: Level2 name: Sub Control description: Detailed implementation guidelines groups: - group: Group1 name: IG1 description: Implementation Group 1 color: '#530909' - group: Group2 name: IG2 description: Implementation Group 2 color: '#064206' hierarchy_data: children: - name: Inventory and Control of Hardware Assets description: Actively manage all hardware devices children: - name: 1.1 Inventory of Hardware Assets description: Maintain an accurate and up-to-date inventory groups_tagged: - IG1 - IG2 - IG3 tags: [] - name: 1.4 Hardware Asset Configuration Management description: Manage hardware configurations groups_tagged: - IG1 - IG2 - IG3 tags: [] created_at: '2024-01-15T10:00:00Z' updated_at: '2024-01-15T10:00:00Z' - id: CCF-8b2cf963-g6b5-51fe-a22b-99e65fcg9987 name: Custom Security Framework description: Organization-specific security controls source_url: https://internal.example.com/security-framework source: Internal category: CCF status: draft releasable: false hierarchy_header: levels: - title: Level1 name: Domain description: Security domains groups: [] hierarchy_data: children: - name: Access Management description: Control user access to systems children: [] created_at: '2024-02-20T14:30:00Z' updated_at: '2024-02-20T14:30:00Z' '400': description: Bad request - invalid query parameter content: application/json: schema: $ref: '#/components/schemas/ErrorResponse' example: _errors: - code: API_CF_E00035 message: Invalid query parameter details: - Invalid value for query parameter 'category' help: https://docs.paloaltonetworks.com/compliance-center/api/errors#API_CF_E00035 _request_id: eb18eb0c-d5b7-43f3-9e38-38464ee11e2f '403': $ref: '#/components/responses/ForbiddenError' '500': $ref: '#/components/responses/InternalServerError' post: tags: - Compliance Frameworks summary: Create Compliance Framework description: Create a new compliance framework definition. The server will assign a unique id. operationId: createFramework security: - BearerAuth: [] requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/ComplianceFrameworkRequest' responses: '201': description: Created successfully headers: Location: description: URI of the created framework schema: type: string example: /definition/PCF-7f1ae852-f5a4-40ed-911a-88d54ebf8876 content: application/json: schema: $ref: '#/components/schemas/ComplianceFrameworkRequest' '400': description: Bad request - invalid request body or missing required fields content: application/json: schema: $ref: '#/components/schemas/ErrorResponse' example: _errors: - code: API_CF_E00001 message: Invalid request body details: - Required field 'name' is missing or invalid in request body help: https://docs.paloaltonetworks.com/compliance-center/api/errors#API_CF_E00001 _request_id: eb18eb0c-d5b7-43f3-9e38-38464ee11e2f '403': $ref: '#/components/responses/ForbiddenError' '500': $ref: '#/components/responses/InternalServerError' servers: - url: https://api.strata.paloaltonetworks.com/posture/compliance-frameworks/v1 description: Current /definitions/{id}: get: tags: - Compliance Frameworks summary: Get Framework Revision description: 'Retrieve details of a compliance framework based on the ''op'' query parameter: - **view_inprogress**: Returns the latest in-progress revision - **view_inrelease**: Returns the currently released revision - **view_aggregated**: Returns aggregated framework data - **view_logo**: Returns the framework''s logo ' operationId: getLatestRevision security: - BearerAuth: [] parameters: - name: id in: path required: true schema: type: string description: Compliance framework ID example: PCF-7f1ae852-f5a4-40ed-911a-88d54ebf8876 - name: op in: query required: true schema: type: string enum: - view_inprogress - view_inrelease - view_aggregated - view_logo description: Operation to perform responses: '200': description: Success content: application/json: schema: type: object properties: image: type: string description: Base64 encoded image data URI (for op=view_logo) name: type: string description: Compliance framework name (for op=view_aggregated) hierarchy_data: type: object description: Hierarchical framework structure (for op=view_aggregated) examples: view_logo: summary: Response when op=view_logo value: image: data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAFAAAABQCAYAAACOEfKtAAAFfklEQVR4Ae2dgVHyTBCGl2/+ArQC/StQK1AqACtQK9AO0AqUCtQK1ArUCqQD6ECtIN89B6v5HITk9nIcTJ6ZHTAhIfeyt3e3uZwd+UFRFEfupees72xXWmA0s6tOpzMp7+joGyfclnsZOLuQlkXcyFTID/7wAs7Ee3a2Ly1VwBu7iPhntgHPa8WrDlqhmXSc9+2617G0hNDFAwfSEkofAduqG06PKlxIRnx8fMj9/b28vLzIaDTy2/b396Xf70uv15OtrS3JiiITnp+fCydS4QTiB51r7Ds9PfWfzYWVCvj29lZcXl4uFO03293d9ceOx+NilSQX8P39vbi5uSmOjo5qi/abca67uzt/7tQkE7BKFbXaKqp4owJaqqjVUlXx6AI2UUVzruLRBExRRXOs4mYB8bacRVtUxfFKKyYBiTHrJNo8owwWggXcBPHUqEWhBAlIy7ZOAi0zQlBoA6P5wFowTt0kdPwdQpCAr6+vsmlo4qIuQQK2fNMKaKQV0Eh0AUl43t7eimvVxLXWMhgMFn6ez9Ab4BjXufXvMddN8vvZ5kYO/ny6z2ox+U8ic319LW645N8jpgpxdXUldVHxeM2V6AKqeLRqCEjhEXEymdTuKpDGV/EeHx99dyPkOkJb2CpEF1B5enryhcaDENKNO+Xz89Nvqwr3QpSzs7MgAbkOrQVN0Ggjwi9/fHz89TdxrixKleMVYuVv5vKOXzE0NY23woxa8B7AE+vENDdG/RJRw8E840fB4xAytYiNVeEyVF8KRousIna7XR8Xl3FwcODFWXZL0yVN/f6LiwtvqUgiIGgcQkRtXRGnCvwA2CLwPjxxb29PUpJMQEBEvOT8/NyLWK5yNDDlRuLk5EQODw8rnZdzamyt4tUxSSogUL0oMAKV4xXxTrMiuq9uPEO8kP6mhegCqgcs6nIQ0/gccY3PUWg9rryvzjQOGqvyeapcRxSKALgxI2uUMK1ilClZQrXlm1ZAI62ARloBZ4TOOwwSMOf0UihJBdzZ2ZFNI9QpggTc3t6WTSPUKYIEjDnepOPMuFjTUgzzFN7rvnIWh9EMf5eNTLiFOmm2MkEjEQpCzLD28jX9PxwOvXFexGFczEiC4R2jC4zPkXEhqUBh+X6OUSzXwrmCJ68XgTCVTQw9f+bsLRrV6OTIefuYVcUUNcv3l42yhBLcjcEbLHC/A6/5LU3F2BaPJNNs/a5lmM5fBML0XTH86lW8CO/UKbq8MqdPj9VtarovxChLKKb5gZaLZkoZM6KqfNbFPF9IFRwB+ZswoBZ6HZTBgmkkQjUMhbtzBO6f55gXzLkvwt218j6qP9VcLRRzeCgMWAO5Tvx2rbH3Iq2yvLrY543tBHm247UicRsRS/UF8xxp62x8123xhdBYpjNfdQ7zz+0yq/4PDw9m8QgNVqJMMo/hCaswPNyKWUCq4LrO0o+BOZ2l92LXjWWzxipTRAAvtHRpUlss74NoTyoRT9ZFwBixT4n6rFxOz8el8D6IKiDdjdwblNhPb0Z/WpNOca7iuYajiE0jzwvnWJUtKatFNCJgbq0y19LUg9eNPbGeSzzkGpp8ar3xR/5XKSLfbU0WLKPxRSdWJSLfScKhaZKs2pFaxBSepyRb9sSadq9qfEcq8SDpwjuISA6uKfHoPqVeyWglSz/RoY0tXhOd5CqsbO2sWFUar0tZZX+y8tXbyIyECMkxMbMqoWSz/F1VIfG4HIRTshFQ4W4bd+XKYtIt4eZTTusGKqxgOZZMF9zWCUPZrVr5zYh7Ik+SKaZZU2kY4YFHMl2Eu6U+///pdDov7s1QWuoyZF39din4MP5dCn62sH5XWk+sAhp1//lnBGWK6dLwl86YCN165JSJTBvbx1nI++IvUfYsCxuwqCUAAAAASUVORK5CYII= view_inprogress: summary: Response when op=view_inprogress value: name: CSCV8 id: PCF-7f1ae852-f5a4-40ed-911a-88d54ebf8876 category: PCF state: released releasable: true hierarchy_data: children: - name: Inventory and Control of Hardware Assets description: '' children: - name: 1.1 Inventory of Hardware Assets description: '' groups_tagged: [] tags: [] - name: 1.4 Hardware Asset Configuration Management description: '' groups_tagged: - IG1 - IG2 - IG3 tags: [] hierarchy_header: levels: - title: Level1 name: Control description: Description of Level1 called Function - title: Level2 name: Sub Control description: '' groups: - group: Group1 name: IG1 description: Description of implementation group color: '#530909' view_inrelease: summary: Response when op=view_inrelease value: name: CSCV8 id: PCF-7f1ae852-f5a4-40ed-911a-88d54ebf8876 category: PCF state: released releasable: true hierarchy_data: children: - name: Inventory and Control of Hardware Assets description: '' children: - name: 1.1 Inventory of Hardware Assets description: '' groups_tagged: [] tags: [] - name: 1.4 Hardware Asset Configuration Management description: '' groups_tagged: - IG1 - IG2 - IG3 tags: [] hierarchy_header: levels: - title: Level1 name: Control description: Description of Level1 called Function - title: Level2 name: Sub Control description: '' groups: - group: Group1 name: IG1 description: Description of implementation group color: '#530909' view_aggregated: summary: Response when op=view_aggregated value: name: CSCV8 id: PCF-7f1ae852-f5a4-40ed-911a-88d54ebf8876 category: PCF state: released releasable: true hierarchy_data: children: - name: Inventory and Control of Hardware Assets description: '' children: - name: 1.1 Inventory of Hardware Assets description: '' groups_tagged: [] tags: [] - name: 1.4 Hardware Asset Configuration Management description: '' groups_tagged: - IG1 - IG2 - IG3 tags: [] hierarchy_header: levels: - title: Level1 name: Control description: Description of Level1 called Function - title: Level2 name: Sub Control description: '' groups: - group: Group1 name: IG1 description: Description of implementation group color: '#530909' '400': description: Bad request - missing or invalid query parameter content: application/json: schema: $ref: '#/components/schemas/ErrorResponse' example: _errors: - code: API_CF_E00035 message: Invalid query parameter details: - 'Query parameter ''op'' is required and must be one of: view_inprogress, view_inrelease, view_aggregated, view_logo' help: https://docs.paloaltonetworks.com/compliance-center/api/errors#API_CF_E00035 _request_id: eb18eb0c-d5b7-43f3-9e38-38464ee11e2f '403': $ref: '#/components/responses/ForbiddenError' '404': $ref: '#/components/responses/NotFoundError' '500': $ref: '#/components/responses/InternalServerError' put: tags: - Compliance Frameworks summary: Update Compliance Framework description: 'Update a compliance framework definition. If an in-progress revision exists, it will be updated. If no in-progress revision exists and ''release=false'', a new in-progress revision is created. If ''release=true'', the framework is both updated and released in a single operation. ' operationId: updateFramework security: - BearerAuth: [] parameters: - name: id in: path required: true schema: type: string description: Compliance framework ID example: PCF-7f1ae852-f5a4-40ed-911a-88d54ebf8876 - name: release in: query required: false schema: type: boolean default: false description: Whether to release the framework after update requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/ComplianceFrameworkRequest' responses: '200': description: Successfully updated content: application/json: schema: $ref: '#/components/schemas/ComplianceFrameworkRequest' '400': description: Bad request - invalid request body or validation error content: application/json: schema: $ref: '#/components/schemas/ErrorResponse' example: _errors: - code: API_CF_E00001 message: Invalid input details: - Invalid value for field 'status' in request body help: https://docs.paloaltonetworks.com/compliance-center/api/errors#API_CF_E00001 _request_id: eb18eb0c-d5b7-43f3-9e38-38464ee11e2f '403': $ref: '#/components/responses/ForbiddenError' '404': $ref: '#/components/responses/NotFoundError' '500': $ref: '#/components/responses/InternalServerError' delete: tags: - Compliance Frameworks summary: Delete Compliance Framework description: Permanently delete a compliance framework and all its revisions operationId: deleteFramework security: - BearerAuth: [] parameters: - name: id in: path required: true schema: type: string description: Compliance framework ID example: PCF-7f1ae852-f5a4-40ed-911a-88d54ebf8876 responses: '204': description: Successfully deleted (no content) '400': $ref: '#/components/responses/BadRequestError' '403': $ref: '#/components/responses/ForbiddenError' '404': $ref: '#/components/responses/NotFoundError' '500': $ref: '#/components/responses/InternalServerError' servers: - url: https://api.strata.paloaltonetworks.com/posture/compliance-frameworks/v1 description: Current /definitions/{id}:clone: post: tags: - Compliance Frameworks summary: Clone Compliance Framework description: Clone the compliance framework to a new one in the user's TSG operationId: cloneFramework security: - BearerAuth: [] parameters: - name: id in: path required: true schema: type: string description: Compliance framework ID to clone example: PCF-7f1ae852-f5a4-40ed-911a-88d54ebf8876 responses: '201': description: Framework cloned successfully headers: Location: description: URI of the cloned framework schema: type: string content: application/json: schema: $ref: '#/components/schemas/ComplianceFramework' '400': description: Bad request - invalid framework ID or framework cannot be cloned content: application/json: schema: $ref: '#/components/schemas/ErrorResponse' example: _errors: - code: API_CF_E00001 message: Invalid input details: - Framework ID format is invalid help: https://docs.paloaltonetworks.com/compliance-center/api/errors#API_CF_E00001 _request_id: eb18eb0c-d5b7-43f3-9e38-38464ee11e2f '403': $ref: '#/components/responses/ForbiddenError' '404': $ref: '#/components/responses/NotFoundError' '500': $ref: '#/components/responses/InternalServerError' servers: - url: https://api.strata.paloaltonetworks.com/posture/compliance-frameworks/v1 description: Current /definitions/{id}:benchmark: post: tags: - Compliance Frameworks summary: Benchmark Compliance Framework description: Mark the compliance framework as a benchmark operationId: benchmarkFramework security: - BearerAuth: [] parameters: - name: id in: path required: true schema: type: string description: Compliance framework ID to benchmark example: PCF-7f1ae852-f5a4-40ed-911a-88d54ebf8876 responses: '200': description: Successfully benchmarked content: application/json: schema: type: object properties: status: type: string example: success example: status: success '400': description: Bad request - framework cannot be benchmarked content: application/json: schema: $ref: '#/components/schemas/ErrorResponse' example: _errors: - code: API_CF_E00001 message: Invalid operation details: - Framework is already benchmarked or cannot be benchmarked help: https://docs.paloaltonetworks.com/compliance-center/api/errors#API_CF_E00001 _request_id: eb18eb0c-d5b7-43f3-9e38-38464ee11e2f '403': $ref: '#/components/responses/ForbiddenError' '404': $ref: '#/components/responses/NotFoundError' '500': $ref: '#/components/responses/InternalServerError' servers: - url: https://api.strata.paloaltonetworks.com/posture/compliance-frameworks/v1 description: Current /definitions/{id}:un-benchmark: post: tags: - Compliance Frameworks summary: Remove Framework Benchmark description: Remove the benchmark designation from the compliance framework operationId: unBenchmarkFramework security: - BearerAuth: [] parameters: - name: id in: path required: true schema: type: string description: Compliance framework ID to un-benchmark example: PCF-7f1ae852-f5a4-40ed-911a-88d54ebf8876 responses: '200': description: Successfully un-benchmarked content: application/json: schema: type: object properties: status: type: string example: success example: status: success '400': description: Bad request - framework cannot be un-benchmarked content: application/json: schema: $ref: '#/components/schemas/ErrorResponse' example: _errors: - code: API_CF_E00001 message: Invalid operation details: - Framework is not currently benchmarked help: https://docs.paloaltonetworks.com/compliance-center/api/errors#API_CF_E00001 _request_id: eb18eb0c-d5b7-43f3-9e38-38464ee11e2f '403': $ref: '#/components/responses/ForbiddenError' '404': $ref: '#/components/responses/NotFoundError' '500': $ref: '#/components/responses/InternalServerError' servers: - url: https://api.strata.paloaltonetworks.com/posture/compliance-frameworks/v1 description: Current /compliance-frameworks/v1/definitions: get: tags: - Compliance Frameworks summary: List Compliance Frameworks description: Retrieve all compliance frameworks for the user's TSG. operationId: ListComplianceFrameworks parameters: - name: category in: query required: false schema: type: string enum: - PCF - CCF - all description: Filter by framework category PCF (Palo Alto Networks) or CCF (Custom). - name: status in: query required: false schema: type: string enum: - draft - released description: Filter by framework status. responses: '200': description: Success. content: application/json: schema: $ref: '#/components/schemas/ComplianceFrameworkListResponse' '400': description: Bad request - invalid query parameter. content: application/json: schema: $ref: '#/components/schemas/Error' '403': description: Forbidden - insufficient permissions. content: application/json: schema: $ref: '#/components/schemas/Error' '500': description: Internal server error. content: application/json: schema: $ref: '#/components/schemas/Error' post: tags: - Compliance Frameworks summary: Create Compliance Framework description: Create a new compliance framework definition. The server will assign a unique id. operationId: CreateComplianceFramework requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/ComplianceFrameworkRequest_2' responses: '201': description: Created successfully. headers: Location: description: URI of the created framework. schema: type: string content: application/json: schema: $ref: '#/components/schemas/ComplianceFramework_2' '400': description: Bad request - invalid request body or missing required fields. content: application/json: schema: $ref: '#/components/schemas/Error' '403': description: Forbidden - insufficient permissions. content: application/json: schema: $ref: '#/components/schemas/Error' '500': description: Internal server error. content: application/json: schema: $ref: '#/components/schemas/Error' servers: - url: https://api.strata.paloaltonetworks.com/posture description: Current /compliance-frameworks/v1/definitions/{id}: get: tags: - Compliance Frameworks summary: Get Framework Revision description: 'Retrieve details of a compliance framework based on the ''op'' query parameter: - **view_inprogress**: Returns the latest in-progress revision - **view_inrelease**: Returns the currently released revision - **view_aggregated**: Returns aggregated framework data - **view_logo**: Returns the framework''s logo ' operationId: GetComplianceFramework parameters: - name: id in: path required: true schema: type: string description: Compliance framework ID. - name: op in: query required: true schema: type: string enum: - view_inprogress - view_inrelease - view_aggregated - view_logo description: Operation to perform. responses: '200': description: Success. content: application/json: schema: $ref: '#/components/schemas/ComplianceFramework_2' '400': description: Bad request - missing or invalid query parameter. content: application/json: schema: $ref: '#/components/schemas/Error' '403': description: Forbidden - insufficient permissions. content: application/json: schema: $ref: '#/components/schemas/Error' '404': description: Compliance framework not found. content: application/json: schema: $ref: '#/components/schemas/Error' '500': description: Internal server error. content: application/json: schema: $ref: '#/components/schemas/Error' put: tags: - Compliance Frameworks summary: Update Compliance Framework description: 'Update a compliance framework definition. If an in-progress revision exists, it will be updated. If no in-progress revision exists and ''release=false'', a new in-progress revision is created. If ''release=true'', the framework is both updated and released in a single operation. ' operationId: UpdateComplianceFramework parameters: - name: id in: path required: true schema: type: string description: Compliance framework ID. - name: release in: query required: false schema: type: boolean default: false description: Whether to release the framework after update. requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/ComplianceFrameworkRequest_2' responses: '200': description: Successfully updated. content: application/json: schema: $ref: '#/components/schemas/ComplianceFramework_2' '400': description: Bad request - invalid request body or validation error. content: application/json: schema: $ref: '#/components/schemas/Error' '403': description: Forbidden - insufficient permissions. content: application/json: schema: $ref: '#/components/schemas/Error' '404': description: Compliance framework not found. content: application/json: schema: $ref: '#/components/schemas/Error' '500': description: Internal server error. content: application/json: schema: $ref: '#/components/schemas/Error' delete: tags: - Compliance Frameworks summary: Delete Compliance Framework description: Permanently delete a compliance framework and all its revisions. operationId: DeleteComplianceFramework parameters: - name: id in: path required: true schema: type: string description: Compliance framework ID. responses: '204': description: Successfully deleted. '400': description: Bad request. content: application/json: schema: $ref: '#/components/schemas/Error' '403': description: Forbidden - insufficient permissions. content: application/json: schema: $ref: '#/components/schemas/Error' '404': description: Compliance framework not found. content: application/json: schema: $ref: '#/components/schemas/Error' '500': description: Internal server error. content: application/json: schema: $ref: '#/components/schemas/Error' servers: - url: https://api.strata.paloaltonetworks.com/posture description: Current /compliance-frameworks/v1/definitions/{id}:clone: post: tags: - Compliance Frameworks summary: Clone Compliance Framework description: Clone the compliance framework to a new one in the user's TSG. operationId: CloneComplianceFramework parameters: - name: id in: path required: true schema: type: string description: Compliance framework ID to clone. responses: '201': description: Framework cloned successfully. headers: Location: description: URI of the cloned framework. schema: type: string content: application/json: schema: $ref: '#/components/schemas/ComplianceFramework_2' '400': description: Bad request - invalid framework ID or framework cannot be cloned. content: application/json: schema: $ref: '#/components/schemas/Error' '403': description: Forbidden - insufficient permissions. content: application/json: schema: $ref: '#/components/schemas/Error' '404': description: Compliance framework not found. content: application/json: schema: $ref: '#/components/schemas/Error' '500': description: Internal server error. content: application/json: schema: $ref: '#/components/schemas/Error' servers: - url: https://api.strata.paloaltonetworks.com/posture description: Current /compliance-frameworks/v1/definitions/{id}:benchmark: post: tags: - Compliance Frameworks summary: Benchmark Compliance Framework description: Mark the compliance framework as a benchmark. operationId: BenchmarkComplianceFramework parameters: - name: id in: path required: true schema: type: string description: Compliance framework ID to benchmark. responses: '200': description: Successfully benchmarked. content: application/json: schema: type: object properties: status: type: string example: success '400': description: Bad request - framework cannot be benchmarked. content: application/json: schema: $ref: '#/components/schemas/Error' '403': description: Forbidden - insufficient permissions. content: application/json: schema: $ref: '#/components/schemas/Error' '404': description: Compliance framework not found. content: application/json: schema: $ref: '#/components/schemas/Error' '500': description: Internal server error. content: application/json: schema: $ref: '#/components/schemas/Error' servers: - url: https://api.strata.paloaltonetworks.com/posture description: Current /compliance-frameworks/v1/definitions/{id}:un-benchmark: post: tags: - Compliance Frameworks summary: Remove Framework Benchmark description: Remove the benchmark designation from the compliance framework. operationId: UnBenchmarkComplianceFramework parameters: - name: id in: path required: true schema: type: string description: Compliance framework ID to un-benchmark. responses: '200': description: Successfully un-benchmarked. content: application/json: schema: type: object properties: status: type: string example: success '400': description: Bad request - framework cannot be un-benchmarked. content: application/json: schema: $ref: '#/components/schemas/Error' '403': description: Forbidden - insufficient permissions. content: application/json: schema: $ref: '#/components/schemas/Error' '404': description: Compliance framework not found. content: application/json: schema: $ref: '#/components/schemas/Error' '500': description: Internal server error. content: application/json: schema: $ref: '#/components/schemas/Error' servers: - url: https://api.strata.paloaltonetworks.com/posture description: Current components: responses: BadRequestError: description: Bad request - invalid parameters or request body content: application/json: schema: $ref: '#/components/schemas/ErrorResponse' example: _errors: - code: API_CF_E00001 message: Invalid input details: - Query parameter 'cf-id' is required help: https://docs.paloaltonetworks.com/compliance-center/api/errors#API_CF_E00001 _request_id: eb18eb0c-d5b7-43f3-9e38-38464ee11e2f NotFoundError: description: Not found - resource does not exist content: application/json: schema: $ref: '#/components/schemas/ErrorResponse' example: _errors: - code: API_CF_E00004 message: Resource not found details: - Compliance framework 'PCF-7f1ae852-f5a4-40ed-911a-88d54ebf8876' not found help: https://docs.paloaltonetworks.com/compliance-center/api/errors#API_CF_E00004 _request_id: eb18eb0c-d5b7-43f3-9e38-38464ee11e2f ForbiddenError: description: Forbidden - insufficient permissions content: application/json: schema: $ref: '#/components/schemas/ErrorResponse' example: _errors: - code: API_CF_E00003 message: Access denied details: - User does not have permission to access this resource help: https://docs.paloaltonetworks.com/compliance-center/api/errors#API_CF_E00003 _request_id: eb18eb0c-d5b7-43f3-9e38-38464ee11e2f InternalServerError: description: Internal server error content: application/json: schema: $ref: '#/components/schemas/ErrorResponse' example: _errors: - code: API_CF_E00500 message: Internal server error details: - An unexpected error occurred while processing the request help: https://docs.paloaltonetworks.com/compliance-center/api/errors#API_CF_E00500 _request_id: eb18eb0c-d5b7-43f3-9e38-38464ee11e2f schemas: ErrorDetail: type: object description: Individual error information properties: code: type: string description: Machine-readable error code following format API_CF_{severity}{number} pattern: ^API_CF_[EWI][0-9]{5} example: API_CF_E00001 message: type: string description: Human-readable error summary minLength: 1 example: Invalid query parameter details: type: array description: Detailed error explanations items: type: string minLength: 1 minItems: 1 example: - Invalid value for parameter 'cf-id' help: type: string description: Documentation URL for error resolution format: uri example: https://docs.paloaltonetworks.com/compliance-center/api/errors#API_CF_E00001 required: - code - message ComplianceFrameworkRequest: type: object description: Compliance framework create/update request properties: name: type: string description: Compliance framework name description: type: string description: Framework description source_url: type: string description: Source URL of the framework source: type: string description: Framework source/origin category: type: string description: Framework category (e.g., 'PCF', 'CCF') enum: - PCF - CCF hierarchy_header: type: object description: Hierarchy header metadata additionalProperties: true hierarchy_data: type: object description: Hierarchical control structure properties: children: type: array description: Array of control nodes items: $ref: '#/components/schemas/ControlNode' logo: type: object description: Framework logo image properties: image: type: string description: Base64 encoded image data (e.g., 'data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAA...') type: type: string description: Image MIME type (e.g., 'image/png', 'image/jpeg') name: type: string description: Image filename (e.g., 'framework-logo.png') example: name: CIS Benchmark v1.4 description: Center for Internet Security Benchmark source_url: https://www.cisecurity.org/benchmark/palo_alto_networks source: CIS category: PCF hierarchy_header: version: '1.4' release_date: '2024-01-15' hierarchy_data: children: - name: Access Control description: Ensure proper access controls bpc_mapped: - 1001 - 1002 children: [] logo: image: data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAA... type: image/png name: framework-logo.png ErrorResponse: type: object description: Standard error response format properties: _errors: type: array description: List of error details items: $ref: '#/components/schemas/ErrorDetail' minItems: 1 _request_id: type: string description: Unique request identifier for troubleshooting format: uuid example: eb18eb0c-d5b7-43f3-9e38-38464ee11e2f required: - _errors - _request_id ComplianceFramework: type: object description: Compliance framework resource properties: id: type: string description: Compliance framework ID example: PCF-7f1ae852-f5a4-40ed-911a-88d54ebf8876 name: type: string description: Compliance framework name description: type: string description: Framework description source_url: type: string description: Source URL of the framework source: type: string description: Framework source/origin category: type: string description: Framework category enum: - PCF - CCF hierarchy_header: type: object description: Hierarchy header metadata additionalProperties: true hierarchy_data: type: object description: Hierarchical control structure logo: type: object description: Framework logo image properties: image: type: string description: Base64 encoded image data type: type: string description: Image MIME type name: type: string description: Image filename created_at: type: string format: date-time description: Creation timestamp updated_at: type: string format: date-time description: Last update timestamp status: type: string description: Framework status enum: - draft - released example: id: PCF-7f1ae852-f5a4-40ed-911a-88d54ebf8876 name: CIS Benchmark v1.4 description: Center for Internet Security Benchmark source_url: https://www.cisecurity.org/benchmark/palo_alto_networks source: CIS category: PCF status: released created_at: '2024-01-15T10:00:00Z' updated_at: '2024-01-15T10:00:00Z' ControlNode: type: object description: Control node in the compliance framework hierarchy properties: name: type: string description: Control name description: type: string description: Control description bpc_mapped: type: array description: Array of BPC (Best Practice Check) IDs mapped to this control items: type: integer children: type: array description: Nested child controls items: $ref: '#/components/schemas/ControlNode' ComplianceFrameworkRequest_2: type: object properties: name: type: string description: Compliance framework name. description: type: string description: Framework description. source_url: type: string description: Source URL of the framework. source: type: string description: Framework source/origin. category: type: string description: Framework category. enum: - PCF - CCF hierarchy_header: type: object description: Hierarchy header metadata. additionalProperties: true hierarchy_data: type: object description: Hierarchical control structure. properties: children: type: array items: $ref: '#/components/schemas/ControlNode_2' logo: type: object description: Framework logo image. properties: image: type: string description: Base64 encoded image data. type: type: string description: Image MIME type. name: type: string description: Image filename. ComplianceFrameworkListResponse: type: object properties: data: type: array items: $ref: '#/components/schemas/ComplianceFramework_2' ComplianceFramework_2: type: object properties: id: type: string description: Compliance framework ID. name: type: string description: Compliance framework name. description: type: string description: Framework description. source_url: type: string description: Source URL of the framework. source: type: string description: Framework source/origin. category: type: string description: Framework category. enum: - PCF - CCF status: type: string description: Framework status. enum: - draft - released releasable: type: boolean description: Whether the framework can be released. hierarchy_header: type: object description: Hierarchy header metadata. additionalProperties: true hierarchy_data: type: object description: Hierarchical control structure. properties: children: type: array items: $ref: '#/components/schemas/ControlNode_2' logo: type: object description: Framework logo image. properties: image: type: string description: Base64 encoded image data. type: type: string description: Image MIME type. name: type: string description: Image filename. created_at: type: string format: date-time description: Creation timestamp. updated_at: type: string format: date-time description: Last update timestamp. ControlNode_2: type: object description: Control node in the compliance framework hierarchy. properties: name: type: string description: Control name. description: type: string description: Control description. bpc_mapped: type: array description: Array of BPC IDs mapped to this control. items: type: integer children: type: array description: Nested child controls. items: $ref: '#/components/schemas/ControlNode_2' Error: type: object properties: _errors: type: array items: type: object properties: code: type: string description: The error code representing a specific error condition. message: type: string description: A brief description of the error condition. details: type: array items: type: string description: An explanation of the error condition. help: type: string format: uri description: A URL link to documentation describing the error condition. _request_id: type: string format: uuid description: The request ID for troubleshooting purposes. securitySchemes: BearerAuth: type: http scheme: bearer bearerFormat: JWT description: Bearer token authentication using JWT x-refined-from: - palo-alto-scm-config-posture-management-compliance-framework-compliance-center-recent-v1-openapi.yaml - palo-alto-scm-config-posture-management-posture-openapi.yaml