---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Common Security Advisory Framework (CSAF)

# Common
Security Advisory Framework (CSAF) {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

When used with Vulnerability Solution Management, the Common Security Advisory Framework (CSAF) enables automation security notifications through a machine-readable JSON format.
The CSAF lets you integrate with any solution intelligence vendor using the solution management framework to import the intelligence data. The CSAF security notifications can be one of the following types.

* Security Advisories
* Vulnerability Exploitability Exchange (VEX)
* Security Incident Response
* Informational Advisory
{#csaf-overview__ul_gg4_k1d_r1c}The CSAF only supports the file imports, URL imports, and API imports of security advisories from vendors.

