02 — Capability · BC-760
Cybersecurity
Protect the enterprise's information, systems and people from digital threats — set the security posture, control who gets in, detect and respond to attacks, and reduce the weaknesses attackers would use.
- Information Security
- Cyber Defense
- InfoSec
- Security Operations
In scope
- Security policy, risk assessment and the assurance that controls work
- Identity, authentication and access across workforce, customers and machines
- Threat detection, incident response and recovery from security events
- Vulnerability reduction across infrastructure, applications, data and suppliers
Out of scope
- Physical site security, guarding and badge systems (see BC-840)
- The enterprise risk framework security risk reports into (see BC-130)
- Regulatory compliance programs beyond security controls (see BC-140)
Realized by · 16
- ServiceNow · Security Operationspartial via BC-760.30
- SAP S/4HANA · Governance, Risk and Compliancepartial via BC-760.20.30
- Microsoft 365 · Microsoft Entra IDstrong via BC-760.20.10
- Microsoft 365 · Microsoft Intunestrong via BC-760.40
- Microsoft 365 · Microsoft Purviewpartial via BC-760.50
- Microsoft 365 · Microsoft Defenderpartial via BC-760.30
- Oracle Fusion Cloud Applications · Risk Management and Compliancepartial via BC-760.20.30
- GitHub · Advanced Securitystrong via BC-760.50
- Snowflake · Governancestrong via BC-760.50
- Okta · Universal Directorycore via BC-760.20.10
- Okta · Single Sign-Oncore via BC-760.20.20
- Okta · Adaptive Multi-Factor Authenticationcore via BC-760.20.20
- Okta · Lifecycle Managementstrong via BC-760.20.10
- Okta · Identity Governancepartial via BC-760.20.30
- Okta · Privileged Accessemerging via BC-760.20.40
- Okta · Customer Identitystrong via BC-760.20.20
Used in · 4
- Commit-to-Production · 02 Test & Secure via BC-760.50
- Hire-to-Retire · 03 Offer & Onboard via BC-760.20
- Hire-to-Retire · 06 Separate & Offboard via BC-760.20
- Demand-to-Change · 03 Design & Review via BC-760.50
Build it · 9
- pattern Zero Trust via BC-760.20
- pattern Secrets Management via BC-760.50.30
- pattern Federated Identity via BC-760.20.20
- pattern Service Mesh via BC-760.40.30
- stack Workforce identity stack via BC-760.20
- book Threat Modeling via BC-760.50
- book Security Engineering via BC-760.10
- book Building Secure and Reliable Systems via BC-760.20
- book Zero Trust Networks via BC-760.20
Decomposes into · 6
- BC-760.10Security Governance & RiskSet the security policies and control framework, assess where the real risks are and prove to leadership and auditors that the controls that matter are in place and working.
- BC-760.20Identity & Access ManagementKnow who and what is accessing enterprise systems, grant only the access each needs for as long as they need it, and make privileged access rare, recorded and reviewed.
- BC-760.30Threat Detection & ResponseWatch for attacks across the estate, respond to confirmed incidents fast enough to limit the damage, and learn enough from each one to see the next one sooner.
- BC-760.40Infrastructure & Endpoint ProtectionReduce the attack surface of servers, networks, cloud environments and devices by finding weaknesses, closing them on a schedule and hardening what remains.
- BC-760.50Application & Data SecurityBuild security into the software the enterprise writes and buys, and protect the data it holds through encryption, key control and controls on where data may go.
- BC-760.60Third-Party & Supply Chain SecurityHold suppliers, partners and the software components the enterprise consumes to a security standard, because an attacker rarely needs to come through the front door.