Cybersecurity Management

BC-620 Level 1 Cross-Industry 344 providers 2726 API surfaces 120 rated strong or better

Security strategy, controls, identity, and threat response.

Cybersecurity Management (BC-620) is a level-1 business capability in the Cross-Industry model. The catalog holds 2726 API surface(s) from 344 provider(s) that can perform some part of it, 120 of them rated strong or better. Reach is the vendor surface that lands on this capability — it is not a claim about what any particular organisation has deployed.

Where this capability definition comes from. This capability is part of a published business-architecture model that API Evangelist did not author. It is redistributed here under CC-BY-4.0. Turbo EA Capabilities by Vincent Verdet — Turbo EA, https://github.com/vincentmakes/turbo-ea-capabilities, CC BY 4.0 Changes: Consolidated from 333 per-L1 YAML files into one JSON; English only (upstream i18n/ omitted); descriptions whitespace-normalised. No capability was added, removed, renamed or re-parented. Source repository · NOTICE and third-party framework attributions

Sub-capabilities

Security Strategy & Governance Management BC-620.10

Security strategy, policies, frameworks, GRC.

3 providers, 12 API surfaces

Identity & Access Management BC-620.20

IAM, PAM, federation, joiners-movers-leavers.

331 providers, 2071 API surfaces

Threat Detection & Response Management BC-620.30

SOC, SIEM, incident response.

38 providers, 247 API surfaces

Vulnerability Management BC-620.40

Vulnerability scanning, patching, remediation.

29 providers, 130 API surfaces

Security Architecture Management BC-620.50

Secure design, security patterns, zero trust.

5 providers, 15 API surfaces

Security Awareness Management BC-620.60

Awareness training, phishing simulations, culture.

1 provider, 2 API surfaces

Providers that reach this capability

Ordered by rating band. Reach means a provider publishes an API surface that can perform some part of this capability — it is not a claim that any particular organisation has deployed it.

Workflows that realise this capability

Arazzo workflows whose own sourceDescriptions call APIs that carry this capability. The link is derived, not asserted: each workflow declares x-realizes-capability-ids with the spec and confidence behind it.

This page carries no rating. Capabilities are not rated. A capability is a description of what a business does, not a thing a company publishes, so a Kin Score would have nothing to measure.
The edge table is a Pro feature. This page shows which providers and tags reach Cybersecurity Management. The underlying tag → capability edges — each with the quoted fragment of the provider's own OpenAPI that evidences it, a calibrated confidence score, and the contract-provenance gate it passed — are available through the API, along with company-level capability maps. Only edges at confidence ≥ 0.7 with evidence found verbatim in the source contract are published at all.

See plans →  ·  How the edges are graded →