Cybersecurity Management › Threat Detection & Response Management
Threat Detection & Response Management
SOC, SIEM, incident response.
Threat Detection & Response Management (BC-620.30) is a level-2 business capability under Cybersecurity Management in the Cross-Industry model. The catalog holds 411 API surface(s) from 96 provider(s) that can perform some part of it, 34 of them rated strong or better. Reach is the vendor surface that lands on this capability — it is not a claim about what any particular organisation has deployed.
Sub-capabilities
Security Monitoring and SIEM Operations BC-620.30.10
SIEM, SOAR, and security telemetry monitoring.
Threat Hunting BC-620.30.20
Proactive hypothesis-driven threat hunting.
Cyber Threat Intelligence BC-620.30.30
Collection, analysis, and dissemination of cyber threat intelligence.
Cyber Incident Response BC-620.30.40
Detection, containment, eradication, and recovery from cyber incidents.
Digital Forensics BC-620.30.50
Forensic acquisition and analysis in support of incidents and litigation.
Providers that reach this capability
Ordered by rating band. Reach means a provider publishes an API surface that can perform some part of this capability — it is not a claim that any particular organisation has deployed it.