slug: palo-alto-networks provider: Palo Alto Networks generated_by: planning/capability-mapping/scripts/classify_capabilities.py model: claude-opus-5 frame: - Banking & Capital Markets - Software & Technology min_confidence: 0.7 capability_model: source: https://github.com/vincentmakes/turbo-ea-capabilities license: CC-BY-4.0 attribution: Turbo EA Capabilities by Vincent Verdet — Turbo EA, https://github.com/vincentmakes/turbo-ea-capabilities, CC BY 4.0 notice: NOTICE edge_count: 186 edges: - tag: Vulnerabilities Dashboard spec_file: palo-alto-networks-vulnerabilities-dashboard-api-openapi.yml capability_id: BC-620.40 capability_id_l1: BC-620 capability_name: Vulnerability Management confidence: 0.9 evidence: '"Get Prioritized Vulnerabilities V4", "Get Vulnerabilities Burndown", "Get Vulnerable Assets by CVE"; schema "RemediationItem"' reason: CVE prioritisation, vulnerable-asset identification and remediation burndown are squarely vulnerability management. - tag: SSO spec_file: palo-alto-networks-sso-api-openapi.yml capability_id: BC-620.20 capability_id_l1: BC-620 capability_name: Identity & Access Management confidence: 0.87 evidence: '"enable single sign-on (SSO) using an Identity Provider (IdP) that supports Security Assertion Markup Language (SAML) or OpenID Connect (OIDC)"; operations "Create SAML Configuration", "Get OIDC Login URL"' reason: Operations configure SAML/OIDC federation for tenant administrators — squarely Identity & Access Management (federation). - tag: AccessPolicies spec_file: palo-alto-networks-access-policies-api-openapi.yml reanchored_from: palo-alto-networks-accesspolicies-api-openapi.yml capability_id: BC-620.20 capability_id_l1: BC-620 capability_name: Identity & Access Management confidence: 0.85 evidence: '"GET /iam/v1/access_policies List all access policies", "Assign an access policy", schema "access_policy_create"' reason: IAM access policy assignment and revocation for platform principals — squarely identity and access management, evidenced by the /iam/v1/ path and access_policy schemas. - tag: Advanced Threat Prevention spec_file: palo-alto-networks-advanced-threat-prevention-api-openapi.yml capability_id: BC-620.30 capability_id_l1: BC-620 capability_name: Threat Detection & Response Management confidence: 0.85 evidence: '"Request Advanced Threat Prevention Report in Batch Mode", "Request Advanced Threat Prevention Report PCAP"; "require an active subscription to the Advanced Threat Prevention security service"' reason: Retrieval of threat analysis reports and packet captures from the threat prevention cloud is threat detection and response tooling. - tag: CustomRoles spec_file: palo-alto-networks-custom-roles-api-openapi.yml reanchored_from: palo-alto-networks-customroles-api-openapi.yml capability_id: BC-620.20 capability_id_l1: BC-620 capability_name: Identity & Access Management confidence: 0.85 evidence: GET /iam/v1/custom_roles "List custom roles", "Create a custom role"; schemas custom_role, permission_set_access reason: IAM endpoints managing custom roles and permission set access for the platform — squarely identity and access management. - tag: IDP spec_file: palo-alto-networks-idp-api-openapi.yml capability_id: BC-620.20 capability_id_l1: BC-620 capability_name: Identity & Access Management confidence: 0.85 evidence: GET /sspm/identity/v1/idps Get all Identity Providers; POST .../accounts/logout Trigger account logout; GET .../mfa_activity Get Multi-factor authentication activity logs reason: Manages identity providers, IdP accounts, forced logout and MFA activity for identity security posture — squarely identity & access management (federation, authentication controls). - tag: Images spec_file: palo-alto-networks-images-api-openapi.yml capability_id: BC-620.40 capability_id_l1: BC-620 capability_name: Vulnerability Management confidence: 0.85 evidence: '"Get Image Scan Results", "Start Image Scan", schemas vuln.Secret, vulnerability.Exploits, vulnerability.RiskFactors' reason: 'Prisma Cloud CWPP container image scanning: the operations start scans and return vulnerability/compliance findings for images, which is straightforwardly Vulnerability Management. Not product image/media handling.' - tag: IoT Public API spec_file: palo-alto-networks-iot-public-api-api-openapi.yml capability_id: BC-620 capability_id_l1: BC-620 capability_name: Cybersecurity Management confidence: 0.85 evidence: GET /iot/pub/v1/device/list device-inventory Get the Device Inventory; GET /iot/pub/v1/alert/list Get Security Alerts; GET /iot/pub/v1/vulnerability/list Get Vulnerabilities reason: 'IoT security visibility API: device inventory, security alert triage/resolution and vulnerability listing. Clearly Cybersecurity Management; spans threat detection/response and vulnerability management so no single L2 is named exclusively.' - tag: Local User Groups spec_file: palo-alto-networks-local-user-groups-api-openapi.yml capability_id: BC-620.20 capability_id_l1: BC-620 capability_name: Identity & Access Management confidence: 0.85 evidence: '"These APIs are used for defining and managing identity services configurations within Strata Cloud Manager"; POST /local-user-groups Create a local user group' reason: Lifecycle management of local user groups within an identity services configuration surface is Identity & Access Management. - tag: Local Users spec_file: palo-alto-networks-local-users-api-openapi.yml capability_id: BC-620.20 capability_id_l1: BC-620 capability_name: Identity & Access Management confidence: 0.85 evidence: POST /local-users Create a local user; "defining and managing identity services configurations" reason: CRUD over local user accounts used for authentication in the security platform's identity services — Identity & Access Management, not HR employee records. - tag: LocalUserGroups spec_file: palo-alto-networks-local-user-groups-api-openapi.yml reanchored_from: palo-alto-networks-localusergroups-api-openapi.yml capability_id: BC-620.20 capability_id_l1: BC-620 capability_name: Identity & Access Management confidence: 0.85 evidence: '"Manages local user groups."; POST /sse/config/v1/local-user-groups Create local user groups' reason: SSE configuration of local user groups for access control is Identity & Access Management. - tag: MSSP Managed Tenant Lifecycle Endpoints spec_file: palo-alto-networks-mssp-managed-tenant-lifecycle-endpoints-api-openapi.yml capability_id: BC-4230.10 capability_id_l1: BC-4230 capability_name: Tenant Provisioning & Lifecycle confidence: 0.85 evidence: POST /api/v1/mssp/{mssp-id}/managed-tenant createManagedTenant Create a new managed tenant; DELETE ... softDeleteManagedTenant Delete a managed tenant reason: Operations create, read, update and soft-delete managed tenants within an MSSP hierarchy of the multi-tenant Prisma Cloud service — squarely tenant provisioning and lifecycle. Not a security-domain capability; the objects managed are tenants, not security controls. - tag: ManageSecurityRules spec_file: palo-alto-networks-managesecurityrules-api-openapi.yml capability_id: BC-620 capability_id_l1: BC-620 capability_name: Cybersecurity Management confidence: 0.85 evidence: '"Security rules determine whether to block or allow a session based on traffic attributes"; "Create a Security Rule"' reason: CRUD over network security rules enforcing allow/deny on traffic — core cybersecurity control management. L2 not specified since it spans policy and secure architecture. - tag: Permission Groups spec_file: palo-alto-networks-permission-groups-api-openapi.yml capability_id: BC-620.20 capability_id_l1: BC-620 capability_name: Identity & Access Management confidence: 0.85 evidence: GET /authz/v1/permission_group — "Get all existing Permission Groups", POST "Add new Custom Permission Group" reason: Authorisation/permission group CRUD under an authz endpoint is identity and access management. - tag: PermissionSets spec_file: palo-alto-networks-permission-sets-api-openapi.yml reanchored_from: palo-alto-networks-permissionsets-api-openapi.yml capability_id: BC-620.20 capability_id_l1: BC-620 capability_name: Identity & Access Management confidence: 0.85 evidence: GET /iam/v1/permission_sets — "List permission sets"; schema custom_role_id reason: IAM permission sets and custom roles are access management primitives. - tag: Permissions spec_file: palo-alto-networks-permissions-api-openapi.yml capability_id: BC-620.20 capability_id_l1: BC-620 capability_name: Identity & Access Management confidence: 0.85 evidence: GET /iam/v1/permissions — "List all access permissions" reason: Enumeration of access permissions under the IAM API is identity & access management. - tag: Roles spec_file: palo-alto-networks-roles-api-openapi.yml capability_id: BC-620.20 capability_id_l1: BC-620 capability_name: Identity & Access Management confidence: 0.85 evidence: GET /iam/v1/roles "List all roles"; schemas role, permission_set_access reason: IAM roles and permission-set access for the platform — identity and access management. Read-only role catalogue keeps confidence just short of certainty. - tag: Security Rules spec_file: palo-alto-networks-security-rules-api-openapi.yml capability_id: BC-620 capability_id_l1: BC-620 capability_name: Cybersecurity Management confidence: 0.85 evidence: '"Create a security rule", "Move a security rule", schemas security-rule-type, internet-rule-type' reason: CRUD and ordering of firewall security policy rules in Strata Cloud Manager — security control configuration under Cybersecurity Management; evidence does not clearly name one L2. - tag: SecurityRules spec_file: palo-alto-networks-securityrules-api-openapi.yml capability_id: BC-620 capability_id_l1: BC-620 capability_name: Cybersecurity Management confidence: 0.85 evidence: '"Create security rule" on /v1/config/rulestacks/{rulestackname}/rulelists/{rulelistname}, schema CreateSecurityRuleRequest.UrlCategory' reason: Manages firewall rulestack security rules (sources, destinations, URL categories) for Prisma Access and Cloud NGFW — security control configuration. - tag: User Profile spec_file: palo-alto-networks-user-profile-api-openapi.yml capability_id: BC-620.20 capability_id_l1: BC-620 capability_name: Identity & Access Management confidence: 0.85 evidence: POST /v3/user 'Add User Profile V3'; PATCH /user/{id}/status/{enabled} 'Update User Status'; schemas UserProfileModel, UserProfileRoleDetailModel, CreateUserAccessKeyResponseModel reason: Operations create, update, disable and delete user accounts with roles and access keys in Prisma Cloud — administration of identities and their access, i.e. Identity & Access Management, not an HR employee-record capability. - tag: User Roles spec_file: palo-alto-networks-user-roles-api-openapi.yml capability_id: BC-620.20 capability_id_l1: BC-620 capability_name: Identity & Access Management confidence: 0.85 evidence: POST /user/role 'Add User Role'; GET /user/role/type 'List User Role Types'; schema UserRoleModel reason: CRUD over user roles (RBAC definitions) in the security platform is classic identity and access administration. - tag: Users spec_file: palo-alto-networks-users-api-openapi.yml capability_id: BC-620.20 capability_id_l1: BC-620 capability_name: Identity & Access Management confidence: 0.85 evidence: POST /seb-api/v1/users/suspend 'Suspend users'; PUT /api/v34.03/users/password 'Update User Password'; schemas api.Permissions, api.AuthType reason: Creating, suspending, re-authenticating users and managing passwords/permissions across Prisma products is administration of identities and access rights. - tag: Vms spec_file: palo-alto-networks-vms-api-openapi.yml capability_id: BC-620.40 capability_id_l1: BC-620 capability_name: Vulnerability Management confidence: 0.85 evidence: '"Get VM Image Scan Results", "Start VM Image Scan"; schemas "vuln.AllCompliance", "vulnerability.Exploits"' reason: VM image vulnerability scanning operations map to vulnerability scanning/remediation capability. - tag: Built-In Accounts spec_file: palo-alto-networks-built-in-accounts-api-openapi.yml capability_id: BC-620.20 capability_id_l1: BC-620 capability_name: Identity & Access Management confidence: 0.82 evidence: '"Creates a Service Account", "Retrieves all the Service Accounts Scopes", "Updates a Service Account credentials"' reason: Lifecycle and credential/scope management of service accounts — machine identity and access management. Clearly Identity & Access Management; not a banking or subscription capability. - tag: Containers spec_file: palo-alto-networks-containers-api-openapi.yml capability_id: BC-620.40 capability_id_l1: BC-620 capability_name: Vulnerability Management confidence: 0.82 evidence: '''Get Container Scan Results'', ''Start a Container Scan''; schemas vulnerability.Exploits, vulnerability.RiskFactors, vuln.Secret' reason: Container image/runtime vulnerability scanning with exploit and risk-factor data is squarely vulnerability scanning and remediation reporting. - tag: Hosts spec_file: palo-alto-networks-hosts-api-openapi.yml capability_id: BC-620.40 capability_id_l1: BC-620 capability_name: Vulnerability Management confidence: 0.82 evidence: '"Get Host Scan Results", "Start a Host Scan" with schemas "vulnerability.Exploits", "vulnerability.RiskFactors", "vuln.Secret"' reason: Prisma Cloud workload protection host scanning returning vulnerability and exploit findings — this is vulnerability scanning and remediation support, i.e. Vulnerability Management. - tag: IAM spec_file: palo-alto-networks-iam-api-openapi.yml capability_id: BC-620.20 capability_id_l1: BC-620 capability_name: Identity & Access Management confidence: 0.82 evidence: POST /api/v1/permission/access Get Permissions Access; schemas ExistingLeastPrivilegedAccessResponseDto, CustomLeastPrivilegedAccessDto, PermissionSearchRequestDto reason: 'Prisma Cloud CIEM surface: searching cloud identity permissions, effective accesses and least-privilege remediation. That is identity and access management (entitlement analysis), not a business-domain capability.' - tag: SAML Server Profiles spec_file: palo-alto-networks-saml-server-profiles-api-openapi.yml capability_id: BC-620.20 capability_id_l1: BC-620 capability_name: Identity & Access Management confidence: 0.82 evidence: '"Identity Services ... These APIs are used for defining and managing identity services configurations" — "Create a SAML server profile"' reason: SAML identity-provider server profiles configure federated authentication, squarely Identity & Access Management (federation). - tag: SAMLServerProfiles spec_file: palo-alto-networks-saml-server-profiles-api-openapi.yml reanchored_from: palo-alto-networks-samlserverprofiles-api-openapi.yml capability_id: BC-620.20 capability_id_l1: BC-620 capability_name: Identity & Access Management confidence: 0.82 evidence: '"Manages SAML server profiles." — "Create a SAML server profile"' reason: SAML server profile CRUD configures identity federation for the SSE platform, mapping to Identity & Access Management. - tag: Alerts spec_file: palo-alto-networks-alerts-api-openapi.yml capability_id: BC-620.30 capability_id_l1: BC-620 capability_name: Threat Detection & Response Management confidence: 0.8 evidence: palo-alto-cspm-alerts-openapi.json ... 'List Alerts', 'Dismiss Alerts', 'List Alert Counts By Policy' reason: Cloud security posture management alerts — security detection and response triage, not financial-crime alerting. Cybersecurity threat detection & response is the honest mapping. - tag: BGP Routing spec_file: palo-alto-networks-bgp-routing-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.8 evidence: '"Get BGP routing settings" / "Update BGP routing settings"; "Prisma Access Remote Network and Service Connection configurations"' reason: Routing settings for remote network / service connections — network infrastructure configuration and management. - tag: DHCP Interfaces spec_file: palo-alto-networks-dhcp-interfaces-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.8 evidence: '"These APIs are used for defining and managing network services configuration within Strata Cloud Manager"; POST /dhcp-interfaces CreateDHCPInterfaces' reason: CRUD over DHCP interface network configuration is network infrastructure management — IT Infrastructure Management (compute, storage, network). - tag: Interconnect spec_file: palo-alto-networks-interconnect-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.8 evidence: '"provision high-capacity physical and virtual links ... manage bandwidth allocations and routing parameters to ensure secure, dedicated connectivity"' reason: Provisioning of network interconnects and VLAN attachments is network infrastructure management. - tag: Issuer Certificates spec_file: palo-alto-networks-issuer-certificates-api-openapi.yml capability_id: BC-620 capability_id_l1: BC-620 capability_name: Cybersecurity Management confidence: 0.8 evidence: GET /v1/distributedissuers/intermediatecertificates "Get the details of all Issuer"; "Use the TLS Protect Cloud APIs to manage certificates, certificate requests, applications, machine identities" reason: PKI/TLS certificate authority issuer certificate retrieval — a cybersecurity control capability (machine identity / certificate management). No single L2 is unambiguously named. - tag: Issuer Configurations spec_file: palo-alto-networks-issuer-configurations-api-openapi.yml capability_id: BC-620 capability_id_l1: BC-620 capability_name: Cybersecurity Management confidence: 0.8 evidence: POST /v1/distributedissuers/configurations configurations_create "Create a new Issuer configuration"; "manage certificates, certificate requests, applications, machine identities" reason: Configuration of distributed certificate issuers within a TLS/PKI service — cybersecurity control administration rather than any business-domain capability. - tag: Issuer Sub CA Providers spec_file: palo-alto-networks-issuer-sub-ca-providers-api-openapi.yml capability_id: BC-620 capability_id_l1: BC-620 capability_name: Cybersecurity Management confidence: 0.8 evidence: POST /v1/distributedissuers/subcaproviders "Create a new Sub CA provider"; SubCaProviderPkcs11ConfigurationInformation reason: Management of subordinate certificate-authority providers (PKCS#11 backed) in a PKI service — Cybersecurity Management; L2 not clearly determined between identity and security architecture. - tag: Layer 2 Subinterfaces spec_file: palo-alto-networks-layer-2-subinterfaces-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.8 evidence: '"These APIs are used for defining and managing network services configuration within Strata Cloud Manager"; POST /layer2-subinterfaces Create a layer 2 subinterface' reason: CRUD over layer-2 network subinterfaces is network infrastructure configuration, mapping to IT Infrastructure Management (compute, storage, network). - tag: Layer 3 Subinterfaces spec_file: palo-alto-networks-layer-3-subinterfaces-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.8 evidence: POST /layer3-subinterfaces Create a layer 3 subinterface; schemas layer3-sub-interfaces-dhcp-client, ddns-config reason: Configuration of layer-3 subinterfaces with DHCP/DDNS settings is network infrastructure provisioning and management. - tag: MFA Servers spec_file: palo-alto-networks-mfa-servers-api-openapi.yml capability_id: BC-620.20 capability_id_l1: BC-620 capability_name: Identity & Access Management confidence: 0.8 evidence: '"These APIs are used for defining and managing identity services configurations" — "Create an MFA server"' reason: Configuration of multi-factor authentication servers under identity services; squarely Identity & Access Management. - tag: MFAServers spec_file: palo-alto-networks-mfa-servers-api-openapi.yml reanchored_from: palo-alto-networks-mfaservers-api-openapi.yml capability_id: BC-620.20 capability_id_l1: BC-620 capability_name: Identity & Access Management confidence: 0.8 evidence: '"Manages multi-factor authentication servers." — POST /sse/config/v1/mfa-servers "Create a MFA server"' reason: CRUD over MFA server definitions used for user authentication in Prisma Access; Identity & Access Management. - tag: ManageRulestacks spec_file: palo-alto-networks-managerulestacks-api-openapi.yml capability_id: BC-620 capability_id_l1: BC-620 capability_name: Cybersecurity Management confidence: 0.8 evidence: '"Rulestacks defines access control (App-ID, URL Filtering) and threat prevention behavior of Cloud NGFW resources"; "Commit rulestack changes"' reason: Authoring, validating and committing firewall security policy stacks — clearly cybersecurity control/policy management rather than any business-domain capability. - tag: Registry spec_file: palo-alto-networks-registry-api-openapi.yml capability_id: BC-620.40 capability_id_l1: BC-620 capability_name: Vulnerability Management confidence: 0.8 evidence: '"Get Registry Scan Results", "Start a Registry Scan"; schemas vuln.Vulnerability, vulnerability.Exploits, shared.RegistryScanProgress' reason: Container-registry image vulnerability scanning in the CWPP product — scan orchestration and vulnerability results, which is vulnerability management. 'Registry' here is an image registry, not a share/statutory register. - tag: Scans spec_file: palo-alto-networks-scans-api-openapi.yml capability_id: BC-620.40 capability_id_l1: BC-620 capability_name: Vulnerability Management confidence: 0.8 evidence: '"Get All CI Image Scan Results", "Download CI Image Scan Results", schemas vuln.Vulnerability, vulnerability.Exploits' reason: Operations trigger and retrieve CI image / code vulnerability scan results with vulnerability and exploit schemas — vulnerability scanning and remediation, not a business-domain noun. - tag: Serverless spec_file: palo-alto-networks-serverless-api-openapi.yml capability_id: BC-620.40 capability_id_l1: BC-620 capability_name: Vulnerability Management confidence: 0.8 evidence: '"Get Serverless Function Scan Results", "Start Serverless Function Scan", schema vuln.Secret' reason: Starts, stops and retrieves vulnerability/secret scans of serverless functions — vulnerability scanning of cloud workloads. - tag: Tenant spec_file: palo-alto-networks-tenant-api-openapi.yml capability_id: BC-4230.10 capability_id_l1: BC-4230 capability_name: Tenant Provisioning & Lifecycle confidence: 0.8 evidence: '"Start Tenant Onboarding", "Start Tenant Offboarding", "Get Tenant Status", "Get Tenant License Info"' reason: Onboarding/offboarding and status of tenants in the ZTNA Connector multi-tenant service — tenant provisioning and lifecycle. - tag: Tenant API spec_file: palo-alto-networks-tenant-api-api-openapi.yml capability_id: BC-4230.10 capability_id_l1: BC-4230 capability_name: Tenant Provisioning & Lifecycle confidence: 0.8 evidence: '"Create a new tenant", "Get license utilization information", "programmatically create and configure new tenants, manage license allocation"' reason: MSP-facing tenant creation and configuration in a multi-tenant SaaS — tenant provisioning and lifecycle management. - tag: UserAccounts spec_file: palo-alto-networks-user-accounts-api-openapi.yml reanchored_from: palo-alto-networks-useraccounts-api-openapi.yml capability_id: BC-620.20 capability_id_l1: BC-620 capability_name: Identity & Access Management confidence: 0.8 evidence: POST /iam/v1/sso_users 'Create an SSO account'; GET /iam/v1/sso_users 'Verify a user account' reason: IAM-path endpoints that create and verify SSO user accounts are directly identity and access management. - tag: Vulnerability Protection Profiles spec_file: palo-alto-networks-vulnerability-protection-profiles-api-openapi.yml capability_id: BC-620 capability_id_l1: BC-620 capability_name: Cybersecurity Management confidence: 0.8 evidence: '"List vulnerability protection profiles" ... "These APIs are used for defining and managing security services configurations within Strata Cloud Manager."' reason: CRUD over firewall security profiles that define exploit/vulnerability threat-prevention behaviour — a cybersecurity control configuration surface. L1 Cybersecurity Management is well supported; the specific L2 is ambiguous between threat detection/response, vulnerability management and security architecture, so no L2 is asserted. - tag: Vulnerability Protection Signatures spec_file: palo-alto-networks-vulnerability-protection-signatures-api-openapi.yml capability_id: BC-620 capability_id_l1: BC-620 capability_name: Cybersecurity Management confidence: 0.8 evidence: '"Create a vulnerability protection signature" ... schema "vulnerability-protection-signatures"' reason: Manages custom detection signatures used by the firewall's threat-prevention engine — cybersecurity control content. L1 only, since signature authoring sits between threat detection and security architecture. - tag: VulnerabilityProtectionProfiles spec_file: palo-alto-networks-vulnerability-protection-profiles-api-openapi.yml reanchored_from: palo-alto-networks-vulnerabilityprotectionprofiles-api-openapi.yml capability_id: BC-620 capability_id_l1: BC-620 capability_name: Cybersecurity Management confidence: 0.8 evidence: '"Manages [Vulnerability protection profiles](.../security-profiles/security-profile-vulnerability-protection)"' reason: 'Same surface as the Strata variant: lifecycle of network security profiles for exploit protection. Clearly Cybersecurity Management at L1; L2 not determinable from the operations.' - tag: VulnerabilityProtectionSignatures spec_file: palo-alto-networks-vulnerability-protection-signatures-api-openapi.yml reanchored_from: palo-alto-networks-vulnerabilityprotectionsignatures-api-openapi.yml capability_id: BC-620 capability_id_l1: BC-620 capability_name: Cybersecurity Management confidence: 0.8 evidence: '"Manages [Vulnerability protection signatures](.../custom-objects/spyware-and-vulnerability)"' reason: CRUD on custom spyware/vulnerability detection signatures — security control content management. L1 Cybersecurity Management only. - tag: WildFire Anti-Virus Profiles spec_file: palo-alto-networks-wildfire-anti-virus-profiles-api-openapi.yml capability_id: BC-620 capability_id_l1: BC-620 capability_name: Cybersecurity Management confidence: 0.8 evidence: '"Create a WildFire and anti-virus profile" ... "defining and managing security services configurations within Strata Cloud Manager"' reason: Manages malware-prevention (anti-virus / WildFire sandbox) security profiles applied to network policy — cybersecurity control configuration. L1 only. - tag: WildFireAntivirusProfiles spec_file: palo-alto-networks-wildfireantivirusprofiles-api-openapi.yml capability_id: BC-620 capability_id_l1: BC-620 capability_name: Cybersecurity Management confidence: 0.8 evidence: '"Manages [WildFire antivirus profiles](.../security-profiles/security-profile-wildfire)"' reason: Same anti-malware security profile lifecycle as the Strata variant; Cybersecurity Management at L1, sub-capability not clearly determined by the operations. - tag: BGP Address Family Profiles spec_file: palo-alto-networks-bgp-address-family-profiles-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.78 evidence: '"Create a BGP address family profile"; "These APIs are used for defining and managing network services configuration within Strata Cloud Manager"' reason: BGP routing protocol profile configuration is pure network infrastructure configuration — Compute/storage/network/cloud infrastructure management. No business-domain capability involved. - tag: BGP Filtering Profiles spec_file: palo-alto-networks-bgp-filtering-profiles-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.78 evidence: '"Create a BGP filtering profile" ... schema "bgp-filter"; "network services configuration"' reason: BGP route filtering configuration — network routing infrastructure management, not a security-policy or business capability. - tag: BGP Redistribution Profiles spec_file: palo-alto-networks-bgp-redistribution-profiles-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.78 evidence: '"Create a BGP redistribution profile"; "defining and managing network services configuration"' reason: Route redistribution profile CRUD is network routing configuration — IT Infrastructure Management. - tag: BGP Route Map Redistributions spec_file: palo-alto-networks-bgp-route-map-redistributions-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.78 evidence: '"Create a BGP route map redistribution"; "network services configuration within Strata Cloud Manager"' reason: Routing policy (route-map redistribution) configuration — network infrastructure management. - tag: BGP Route Maps spec_file: palo-alto-networks-bgp-route-maps-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.78 evidence: '"Create a BGP route map"; "network services configuration within Strata Cloud Manager"' reason: BGP route map CRUD is network routing configuration — IT Infrastructure Management. - tag: Credential Management spec_file: palo-alto-networks-credential-management-api-openapi.yml capability_id: BC-620.20 capability_id_l1: BC-620 capability_name: Identity & Access Management confidence: 0.78 evidence: '''Test the connection to a privileged'' ... ''Add a set of new shared'' credentials; schemas CreateCyberArkCredDetails, CreateHashiCorpCredDetails' reason: Configuration of privileged-access/credential-manager integrations (CyberArk, HashiCorp) and lifecycle of shared credentials — privileged access and credential management within IAM. - tag: DLP API spec_file: palo-alto-networks-dlp-api-api-openapi.yml capability_id: BC-620.30 capability_id_l1: BC-620 capability_name: Threat Detection & Response Management confidence: 0.78 evidence: PUT /v1/api/incidents/{incidentID}/resolution-status updateIncidentResolutionStatus; GET /v2/api/incidents getAllIncidentsV2 Get Incidents; schema IncidentAssignee reason: Data Loss Prevention incident triage, assignment and resolution is security incident detection and response, not general IT service incidents. Some ambiguity between security incident response and privacy/data-protection, so confidence moderate. - tag: Decryption Exclusions spec_file: palo-alto-networks-decryption-exclusions-api-openapi.yml capability_id: BC-620 capability_id_l1: BC-620 capability_name: Cybersecurity Management confidence: 0.78 evidence: Create a decryption exclusion; "security services configurations within Strata Cloud Manager" reason: Manages TLS decryption exclusion lists on the security enforcement platform — configuration of network security controls, so Cybersecurity Management. No L2 cleanly covers policy-object configuration, so L1 only. - tag: Decryption Profiles spec_file: palo-alto-networks-decryption-profiles-api-openapi.yml capability_id: BC-620 capability_id_l1: BC-620 capability_name: Cybersecurity Management confidence: 0.78 evidence: Create a decryption profile; "security services configurations within Strata Cloud Manager" reason: CRUD over SSL/TLS decryption profiles governing inspection behaviour — a security control configuration surface, mapped to Cybersecurity Management at L1 only. - tag: Decryption Rules spec_file: palo-alto-networks-decryption-rules-api-openapi.yml capability_id: BC-620 capability_id_l1: BC-620 capability_name: Cybersecurity Management confidence: 0.78 evidence: Create a decryption rule; Move a decryption rule; schema rule-based-move reason: Manages ordered decryption policy rules on the security platform — security policy/control configuration, i.e. Cybersecurity Management. L2 not determinable from the evidence. - tag: DecryptionExclusions spec_file: palo-alto-networks-decryption-exclusions-api-openapi.yml reanchored_from: palo-alto-networks-decryptionexclusions-api-openapi.yml capability_id: BC-620 capability_id_l1: BC-620 capability_name: Cybersecurity Management confidence: 0.78 evidence: '"Manages [decryption] exclusions"; POST /sse/config/v1/decryption-exclusions' reason: SSE configuration API for decryption exclusion objects — network security control configuration, mapped to Cybersecurity Management at L1. - tag: DecryptionProfiles spec_file: palo-alto-networks-decryptionprofiles-api-openapi.yml capability_id: BC-620 capability_id_l1: BC-620 capability_name: Cybersecurity Management confidence: 0.78 evidence: '"Manages [decryption profiles]"; Create a decryption profile' reason: SSE configuration API for TLS decryption profiles used by security policy — Cybersecurity Management at L1; no L2 unambiguously supported. - tag: Groups spec_file: palo-alto-networks-groups-api-openapi.yml capability_id: BC-620.20 capability_id_l1: BC-620 capability_name: Identity & Access Management confidence: 0.78 evidence: '"Add a Group", "Update a Group"; schemas "api.Permissions", "api.Permission", "shared.User"' reason: User group CRUD carrying permission assignments in Prisma Cloud Compute/CWPP — access administration for the platform, i.e. Identity & Access Management. - tag: Incidents API spec_file: palo-alto-networks-incidents-api-api-openapi.yml capability_id: BC-620.30 capability_id_l1: BC-620 capability_name: Threat Detection & Response Management confidence: 0.78 evidence: '"Manage and retrieve DLP incidents ... including retrieval with advanced filtering, assignment management, notes management, and resolution status tracking"' reason: 'Security (data-loss-prevention) incident lifecycle: assignment, notes, resolution status. This is security incident detection and response case handling, not IT service desk ticketing nor financial-crime alerting.' - tag: Anomalies spec_file: palo-alto-networks-anomalies-api-openapi.yml capability_id: BC-620.30 capability_id_l1: BC-620 capability_name: Threat Detection & Response Management confidence: 0.75 evidence: '''Get Anomaly Trusted List'', ''Update Anomaly Settings'', schema NetworkAnomaliesTrustedListEntry' reason: Tuning of anomaly detection policies/allow-lists in Prisma Cloud security monitoring — security threat detection configuration. - tag: Anti-Spyware Profiles spec_file: palo-alto-networks-anti-spyware-profiles-api-openapi.yml capability_id: BC-620.10 capability_id_l1: BC-620 capability_name: Security Strategy & Governance Management confidence: 0.75 evidence: '''Create an anti-spyware profile'' ... ''These APIs are used for defining and managing security services configurations within Strata Cloud Manager.''' reason: Configuration of security control profiles (anti-spyware) — cybersecurity control/policy management. - tag: AntiSpywareProfiles spec_file: palo-alto-networks-anti-spyware-profiles-api-openapi.yml reanchored_from: palo-alto-networks-antispywareprofiles-api-openapi.yml capability_id: BC-620.10 capability_id_l1: BC-620 capability_name: Security Strategy & Governance Management confidence: 0.75 evidence: '''Manages [anti-spyware profiles]'' ... ''Create an anti-spyware profile''' reason: 'Same as other anti-spyware profile surface: security policy/control profile configuration.' - tag: Application-Control spec_file: palo-alto-networks-application-control-api-openapi.yml capability_id: BC-620 capability_id_l1: BC-620 capability_name: Cybersecurity Management confidence: 0.75 evidence: '"put-application-control-host Update Host Application Control Rules"; schemas applicationcontrol.Rule, applicationcontrol.Application' reason: Host application-control rules in the CWPP workload-protection product are preventive security controls on endpoints/workloads. Cybersecurity Management L1; no single L2 is unambiguously named by the operations. - tag: AssociateRulestacks spec_file: palo-alto-networks-associaterulestacks-api-openapi.yml capability_id: BC-620 capability_id_l1: BC-620 capability_name: Cybersecurity Management confidence: 0.75 evidence: PUT /v1/config/ngfirewalls/{ngfirewallname}/globalrulestack Associate a GlobalRuleStack; 'Cloud NGFW for AWS supports local and global rulestacks' reason: Operations bind firewall rule collections to next-generation firewalls, i.e. configuration of network security controls. Clearly Cybersecurity Management at L1; the sub-capability (security architecture vs. security governance) is not pinned down by the evidence, so no L2. - tag: AssociationRulestacks spec_file: palo-alto-networks-associationrulestacks-api-openapi.yml capability_id: BC-620 capability_id_l1: BC-620 capability_name: Cybersecurity Management confidence: 0.75 evidence: PUT /v1/config/ngfirewalls/{ngfirewallname}/rulestack Associate local rulestack; 'A global rulestack configures pre-rules and post-rules on each NGFW' reason: 'Same surface as the sibling tag: associating local/global firewall rulestacks with NGFWs — management of network security policy controls. L1 cybersecurity only; no L2 is clearly evidenced.' - tag: Authentication Profiles spec_file: palo-alto-networks-authentication-profiles-api-openapi.yml capability_id: BC-620.20 capability_id_l1: BC-620 capability_name: Identity & Access Management confidence: 0.75 evidence: POST /authentication-profiles CreateAuthenticationProfiles Create an authentication profile; 'defining and managing identity services configurations' reason: CRUD over authentication profile objects in the identity services configuration surface — management of authentication mechanisms for users, i.e. Identity & Access Management. - tag: Authentication Rules spec_file: palo-alto-networks-authentication-rules-api-openapi.yml capability_id: BC-620.20 capability_id_l1: BC-620 capability_name: Identity & Access Management confidence: 0.75 evidence: POST /authentication-rules CreateAuthenticationRules Create an authentication rule; POST /authentication-rules/{id}:move Move an authentication rule reason: Authoring and ordering of authentication policy rules within identity services configuration — access control policy management, mapping to Identity & Access Management. - tag: Certificate Policy spec_file: palo-alto-networks-certificate-policy-api-openapi.yml capability_id: BC-620 capability_id_l1: BC-620 capability_name: Cybersecurity Management confidence: 0.75 evidence: '"Add an issuing template" / "Synchronize issuing templates domains with CA"; schema CertificateIssuingTemplateInformation' reason: Manages certificate issuing templates (PKI issuance policy) in a TLS/certificate management platform — a cybersecurity control capability. Which L2 (identity/PKI vs security governance) is not clearly named, so L1 only. - tag: Certificate Request spec_file: palo-alto-networks-certificate-request-api-openapi.yml capability_id: BC-620 capability_id_l1: BC-620 capability_name: Cybersecurity Management confidence: 0.75 evidence: '"Create a certificate request", "Resubmit a certificate request", "Validate a certificate request"' reason: Certificate request issuance/validation lifecycle in a certificate management product — a cybersecurity capability; specific L2 not clearly named. - tag: Certificates spec_file: palo-alto-networks-certificates-api-openapi.yml capability_id: BC-620 capability_id_l1: BC-620 capability_name: Cybersecurity Management confidence: 0.75 evidence: '"Generate a certificate", "Import a certificate", "Export a certificate", "Retrieve all certificate data"' reason: Full certificate lifecycle (generate, import, export, delete, retire) across security platforms — cybersecurity/PKI management; L2 not explicitly named. - tag: Cloud Dynamic User Groups spec_file: palo-alto-networks-cloud-dynamic-user-groups-api-openapi.yml capability_id: BC-620.20 capability_id_l1: BC-620 capability_name: Identity & Access Management confidence: 0.75 evidence: '''Cloud Dynamic User Groups (CDUG) API for managing dynamic user groups in the Directory Sync Service''; POST ''Create Cloud Dynamic User Groups''; GET /directory-sync/v1/user-attr-values ''Retrieve User Attribute Values''' reason: Operations create, update and delete directory-synced user groups and read user attributes used for access policy — identity and access management plumbing in the security domain, which maps to Identity & Access Management. - tag: DLP API (Beta) spec_file: palo-alto-networks-dlp-api-beta-api-openapi.yml capability_id: BC-620.30 capability_id_l1: BC-620 capability_name: Threat Detection & Response Management confidence: 0.75 evidence: POST /v4/api/incidents/management updateIncidents Update key details for incidents; schemas DataPattern, DataProfile, ExposureDetails reason: Beta DLP incident inventory, detail retrieval and bulk update — security incident handling for data-exposure events. Same reading as the non-beta DLP API. - tag: DataFiltering spec_file: palo-alto-networks-datafiltering-api-openapi.yml capability_id: BC-620 capability_id_l1: BC-620 capability_name: Cybersecurity Management confidence: 0.75 evidence: '"These APIs are used for defining and managing security services configurations within Strata Cloud Manager"; Create Data Filtering Profile' reason: CRUD over data-filtering (DLP) security profiles in Strata Cloud Manager — configuration of security controls, i.e. Cybersecurity Management. Which L2 (governance vs architecture) is ambiguous, so L1 only. - tag: Directory Sync Service spec_file: palo-alto-networks-directory-sync-service-api-openapi.yml capability_id: BC-620.20 capability_id_l1: BC-620 capability_name: Identity & Access Management confidence: 0.75 evidence: '"retrieve real-time user, group, and domain information from your connected directories"; "Update directory connection client secret"; schemas check_group_membership, list_users_in_particular_group' reason: 'Directory federation and identity/group lookup from connected enterprise directories to supply identity-aware context to security services — identity and access management. Not HR employee records: the entities are directory users, groups and domains.' - tag: Endpoint Policies spec_file: palo-alto-networks-endpoint-policies-api-openapi.yml capability_id: BC-620 capability_id_l1: BC-620 capability_name: Cybersecurity Management confidence: 0.75 evidence: Manage endpoint DLP policies for controlling data loss prevention on endpoint devices... policies that define DLP rules and actions for endpoint protection reason: CRUD over data-loss-prevention policies applied to endpoint devices is a security control capability (Cybersecurity Management). No single L2 fits cleanly — it straddles security governance/policy and endpoint protection controls — so only the L1 is asserted. - tag: Ethernet Interfaces spec_file: palo-alto-networks-ethernet-interfaces-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.75 evidence: '''Create an ethernet interface''; schemas ethernet-interfaces-dhcp-client, ethernet-interfaces-arp, poe' reason: CRUD over physical network interface configuration (DHCP client, ARP, PoE) — network infrastructure configuration management, an IT Infrastructure capability. - tag: File Blocking Profiles spec_file: palo-alto-networks-file-blocking-profiles-api-openapi.yml capability_id: BC-620 capability_id_l1: BC-620 capability_name: Cybersecurity Management confidence: 0.75 evidence: '"List file blocking profiles" / "Create a file blocking profiles" under "defining and managing security services configurations within Strata Cloud Manager"' reason: CRUD over firewall security profiles that block file types — a security control configuration surface, so Cybersecurity Management at L1; evidence does not clearly single out a sub-capability (not GRC policy, not detection/response). - tag: FileBlockingAction spec_file: palo-alto-networks-fileblockingaction-api-openapi.yml capability_id: BC-620 capability_id_l1: BC-620 capability_name: Cybersecurity Management confidence: 0.75 evidence: '"Allows you to identify specific file types that you want to block"; "Retrieve file blocking profile" on /config/rulestacks/{rulestackname}/fileblockingprofiles' reason: Rulestack-level configuration of file-blocking security controls on a firewall — clearly cybersecurity control management, but no single L2 is named by the operations. - tag: FileBlockingProfiles spec_file: palo-alto-networks-fileblockingprofiles-api-openapi.yml capability_id: BC-620 capability_id_l1: BC-620 capability_name: Cybersecurity Management confidence: 0.75 evidence: '"Manages file blocking profiles ... network-security/security-policy/security-profiles/security-profile-file-blocking"' reason: Same security-profile configuration surface for SSE; maps to Cybersecurity Management at L1 without a defensible L2. - tag: Incidents API (Beta) spec_file: palo-alto-networks-incidents-api-beta-api-openapi.yml capability_id: BC-620.30 capability_id_l1: BC-620 capability_name: Threat Detection & Response Management confidence: 0.75 evidence: '"Retrieve Paginated DLP Incidents", "Update Incident Management Properties", schemas ExposureDetails, DataPattern, DataProfile' reason: Beta surface over the same DLP incident inventory with batch updates and exports — security incident response management. Slightly lower confidence as much of the surface is query/export plumbing. - tag: Internal DNS Servers spec_file: palo-alto-networks-internal-dns-servers-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.75 evidence: POST /internal-dns-servers CreateInternalDNSServers Create a internal DNS server reason: DNS server configuration for Prisma Access network deployment — network infrastructure management. - tag: InternalDNSServers spec_file: palo-alto-networks-internaldnsservers-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.75 evidence: '"Manages internal DNS servers"; post-sse-config-v1-internal-dns-servers Create an internal DNS server' reason: Internal DNS server CRUD for Prisma Access service infrastructure — network infrastructure management. - tag: Kerberos Server Profiles spec_file: palo-alto-networks-kerberos-server-profiles-api-openapi.yml capability_id: BC-620.20 capability_id_l1: BC-620 capability_name: Identity & Access Management confidence: 0.75 evidence: '"These APIs are used for defining and managing identity services configurations within Strata Cloud Manager"; CreateKerberosServerProfiles "Create a Kerberos server profile"' reason: Configuration of Kerberos authentication server profiles under the vendor's identity services — authentication/directory integration, i.e. Identity & Access Management. - tag: LDAP Server Profiles spec_file: palo-alto-networks-ldap-server-profiles-api-openapi.yml capability_id: BC-620.20 capability_id_l1: BC-620 capability_name: Identity & Access Management confidence: 0.75 evidence: '"used for defining and managing identity services configurations"; CreateLDAPServerProfiles "Create an LDAP server profile"' reason: LDAP directory server profile configuration under identity services — directory/authentication integration, i.e. Identity & Access Management. - tag: Logical Routers spec_file: palo-alto-networks-logical-routers-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.75 evidence: '"These APIs are used for defining and managing network services configuration within Strata Cloud Manager" — "Create a logical router"' reason: CRUD over logical routers, i.e. network routing infrastructure configuration, which is IT Infrastructure Management (network). - tag: Loopback Interfaces spec_file: palo-alto-networks-loopback-interfaces-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.75 evidence: '"Network Services" ... "Create a loopback interface", "Update a loopback interface"' reason: CRUD over network loopback interfaces — network device/infrastructure configuration, mapping to IT Infrastructure Management. - tag: ManageNGFW spec_file: palo-alto-networks-managengfw-api-openapi.yml capability_id: BC-620 capability_id_l1: BC-620 capability_name: Cybersecurity Management confidence: 0.75 evidence: '"Create firewall resource"; "Delete firewall resource"; "Update subnet mappings"' reason: Lifecycle management of next-generation firewall resources — deployment and stewardship of network security controls. Maps to Cybersecurity Management at L1; no single L2 fits firewall provisioning cleanly. - tag: ManageNGFW-V2 spec_file: palo-alto-networks-managengfw-v2-api-openapi.yml capability_id: BC-620 capability_id_l1: BC-620 capability_name: Cybersecurity Management confidence: 0.75 evidence: '"Create V2 firewall"; "Update firewall content versions - Configure firewall features"' reason: Same firewall resource management surface at v2 — provisioning and configuring network security enforcement points, i.e. cybersecurity control management. - tag: Packages spec_file: palo-alto-networks-packages-api-openapi.yml capability_id: BC-620.40 capability_id_l1: BC-620 capability_name: Vulnerability Management confidence: 0.75 evidence: GET /code/api/v1/vulnerabilities/packages/{packageUuid}/cves getCvesByPackageUuid Get CVEs by Package UUID reason: 'Software composition analysis: inspecting code dependencies and their CVEs under a /vulnerabilities path — vulnerability identification and remediation support.' - tag: Peripherals spec_file: palo-alto-networks-peripherals-api-openapi.yml capability_id: BC-620 capability_id_l1: BC-620 capability_name: Cybersecurity Management confidence: 0.75 evidence: '"Manage peripheral device configurations and policies for DLP protection. Configure USB devices, printers, and other peripherals to enforce DLP policies"' reason: Operations configure device-level data-loss-prevention controls — a cybersecurity control capability. No single L2 fits DLP peripheral control cleanly, so L1 only. - tag: PrefixList spec_file: palo-alto-networks-prefixlist-api-openapi.yml capability_id: BC-620 capability_id_l1: BC-620 capability_name: Cybersecurity Management confidence: 0.75 evidence: '"A prefix list allows you to group specific IP addresses that require the same policy enforcement"; operations "Create prefix list" under /v1/config/rulestacks/{rulestackname}/prefixlists' reason: Firewall rulestack policy objects grouping IPs for security policy enforcement — cybersecurity control configuration. No single L2 fits network security policy object management, so L1 only. - tag: Profile Groups spec_file: palo-alto-networks-profile-groups-api-openapi.yml capability_id: BC-620 capability_id_l1: BC-620 capability_name: Cybersecurity Management confidence: 0.75 evidence: '"Security Services Profile Groups API" ... "These APIs are used for defining and managing security services configurations within Strata Cloud Manager"; "Create a profile group"' reason: CRUD over security profile groups (security service profiles attached to security policy) — cybersecurity control configuration; no precise L2. - tag: ProfileGroups spec_file: palo-alto-networks-profile-groups-api-openapi.yml reanchored_from: palo-alto-networks-profilegroups-api-openapi.yml capability_id: BC-620 capability_id_l1: BC-620 capability_name: Cybersecurity Management confidence: 0.75 evidence: '"Manages [Profile Groups](https://docs.paloaltonetworks.com/network-security/security-policy/security-profiles/security-profile-groups)"; "Create profile groups"' reason: Security profile group configuration for network security policy — cybersecurity control management; no precise L2 fits. - tag: RADIUS Server Profiles spec_file: palo-alto-networks-radius-server-profiles-api-openapi.yml capability_id: BC-620.20 capability_id_l1: BC-620 capability_name: Identity & Access Management confidence: 0.75 evidence: '"These APIs are used for defining and managing identity services configurations within Strata Cloud Manager"; ListRADIUSServerProfiles / CreateRADIUSServerProfiles' reason: RADIUS server profiles configure authentication back-ends for user/device access — identity and access management configuration, explicitly framed by the vendor as 'identity services'. - tag: RadiusServerProfiles spec_file: palo-alto-networks-radius-server-profiles-api-openapi.yml reanchored_from: palo-alto-networks-radiusserverprofiles-api-openapi.yml capability_id: BC-620.20 capability_id_l1: BC-620 capability_name: Identity & Access Management confidence: 0.75 evidence: '"Manages Radius server profiles." POST /sse/config/v1/radius-server-profiles "Create a Radius server profile"' reason: CRUD over RADIUS authentication server profiles used for user/device authentication — identity and access management configuration. - tag: ServiceAccounts spec_file: palo-alto-networks-service-accounts-api-openapi.yml reanchored_from: palo-alto-networks-serviceaccounts-api-openapi.yml capability_id: BC-620.20 capability_id_l1: BC-620 capability_name: Identity & Access Management confidence: 0.75 evidence: GET /iam/v1/service_accounts "List all service accounts"; POST "Create a service account"; "Reset a service account" reason: Lifecycle of machine identities under an /iam/ path — issuance, update, reset, deletion of service accounts. This is Identity & Access Management. Some chance it should be read as developer credential management for API access, hence 0.75 rather than higher. - tag: Tas-Droplets spec_file: palo-alto-networks-tas-droplets-api-openapi.yml capability_id: BC-620.40 capability_id_l1: BC-620 capability_name: Vulnerability Management confidence: 0.75 evidence: '"Scan TAS Droplets", "View TAS Droplets Scan Progress", schemas vuln.SecretType, vulnerability.Exploits' reason: Vulnerability scanning of Tanzu Application Service droplets with vulnerability/exploit schemas — vulnerability scanning and remediation workflow. - tag: Tenant Group Lifecycle Endpoints spec_file: palo-alto-networks-tenant-group-lifecycle-endpoints-api-openapi.yml capability_id: BC-4230.10 capability_id_l1: BC-4230 capability_name: Tenant Provisioning & Lifecycle confidence: 0.75 evidence: '"Create a tenant group", "Delete an existing tenant group", "Get the tenant group list for an MSSP"' reason: Lifecycle CRUD over groupings of tenants in the MSSP backend — tenant fleet organisation and lifecycle management in a multi-tenant service. - tag: TenantServiceGroup spec_file: palo-alto-networks-tenantservicegroup-api-openapi.yml capability_id: BC-4230.10 capability_id_l1: BC-4230 capability_name: Tenant Provisioning & Lifecycle confidence: 0.75 evidence: POST /tenancy/v1/tenant_service_groups "Create a tenant service group"; DELETE .../{tsg_id} "Delete a tenant service group"; "List tenant service group ancestors" / "children" reason: Full CRUD plus hierarchy traversal over tenant service groups under a /tenancy/ API — creation, update and decommissioning of tenants in a multi-tenant fleet, which is tenant provisioning and lifecycle rather than any security capability. - tag: Threat Prevention spec_file: palo-alto-networks-threat-prevention-api-openapi.yml capability_id: BC-620.30 capability_id_l1: BC-620 capability_name: Threat Detection & Response Management confidence: 0.75 evidence: GET /threats "Request Threat Metadata"; POST /threats "Request Threat Signature Metadata in Batch Mode"; GET /threats/cve-coverage "Request CVE Coverage Information"; schemas VulnerabilitySignature, AntivirusSignature, IpFeedDataList reason: Threat Vault surface delivering threat signature metadata, antivirus/vulnerability signatures, predefined EDLs and IP feeds that feed detection — threat intelligence supporting detection and response. Some overlap with vulnerability management (CVE coverage) hence not maximal confidence. - tag: User Management spec_file: palo-alto-networks-user-management-api-openapi.yml capability_id: BC-620.20 capability_id_l1: BC-620 capability_name: Identity & Access Management confidence: 0.75 evidence: Create a new user; Change Password; Generate password reset token; Delete an existing user reason: Administrative user account lifecycle and credential management for the platform — identity & access management. - tag: Vlan Attachment spec_file: palo-alto-networks-vlan-attachment-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.75 evidence: '"Provision Vlan Attachment"; "provision high-capacity physical and virtual links ... manage bandwidth allocations and routing parameters"' reason: Administrative provisioning of network interconnect links and bandwidth — network infrastructure management. - tag: Workload Issuance Policies spec_file: palo-alto-networks-workload-issuance-policies-api-openapi.yml capability_id: BC-620.20 capability_id_l1: BC-620 capability_name: Identity & Access Management confidence: 0.75 evidence: '"Use the TLS Protect Cloud APIs to manage certificates, certificate requests, applications, machine identities" ... "Create a new Workload Issuance policy"' reason: Policies governing certificate issuance to workloads (machine identity) — credential/identity issuance governance, which falls under Identity & Access Management. Moderate confidence since machine-identity/PKI is only loosely covered by the IAM sub-capability wording. - tag: Zone Protection Profiles spec_file: palo-alto-networks-zone-protection-profiles-api-openapi.yml capability_id: BC-620 capability_id_l1: BC-620 capability_name: Cybersecurity Management confidence: 0.75 evidence: '"Create a zone protection profile" ... "defining and managing network services configuration within Strata Cloud Manager"' reason: Firewall zone protection profiles (flood/reconnaissance protection settings) — network security control configuration. Cybersecurity Management at L1; could equally be read as network infrastructure config, so no L2 and moderate confidence. - tag: AuthenticationProfiles spec_file: palo-alto-networks-authentication-profiles-api-openapi.yml reanchored_from: palo-alto-networks-authenticationprofiles-api-openapi.yml capability_id: BC-620.20 capability_id_l1: BC-620 capability_name: Identity & Access Management confidence: 0.72 evidence: '"Manages [authentication](...) profiles." — "Create an authentication profile"' reason: Authentication profiles define how users are authenticated (auth servers, MFA) for the security platform — Identity & Access Management. - tag: BGP Authentication Profiles spec_file: palo-alto-networks-bgp-authentication-profiles-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.72 evidence: '"Create a BGP authentication profile"; "network services configuration within Strata Cloud Manager"' reason: Despite the word 'Authentication', these are BGP peer authentication (MD5 key) profiles for routing protocol configuration, not user identity management. Network infrastructure configuration. - tag: SD-WAN Error Correction Profiles spec_file: palo-alto-networks-sd-wan-error-correction-profiles-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.72 evidence: '"Network Services SD-WAN Error Correction Profiles API ... These APIs are used for defining and managing network services configuration within Strata Cloud Manager" with operations "Create an SD-WAN error correction profile"' reason: CRUD over SD-WAN network service profiles is network infrastructure configuration, best represented by IT Infrastructure Management (compute, storage, network). No business-domain capability applies. - tag: SD-WAN Path Quality Profiles spec_file: palo-alto-networks-sd-wan-path-quality-profiles-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.72 evidence: '"List SD-WAN path quality profiles" / "defining and managing network services configuration within Strata Cloud Manager"' reason: Configuration of SD-WAN link/path quality parameters is network infrastructure management, not a business capability of the buyer. - tag: SD-WAN Traffic Distribution Profiles spec_file: palo-alto-networks-sd-wan-traffic-distribution-profiles-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.72 evidence: '"Create an SD-WAN traffic distribution profile" under "Network Services" configuration APIs' reason: Load-balancing/traffic distribution profiles for SD-WAN links are network infrastructure configuration. - tag: VLAN Interfaces spec_file: palo-alto-networks-vlan-interfaces-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.72 evidence: '"List VLAN interfaces", "Create a VLAN interface"; "defining and managing network services configuration within Strata Cloud Manager"' reason: CRUD over VLAN network interfaces is network infrastructure configuration management. - tag: Anti-Spyware Signatures spec_file: palo-alto-networks-anti-spyware-signatures-api-openapi.yml capability_id: BC-620.30 capability_id_l1: BC-620 capability_name: Threat Detection & Response Management confidence: 0.7 evidence: '''Create an anti-spyware signature'' ... ''managing security services configurations within Strata Cloud Manager''' reason: Threat signature management for spyware detection — cybersecurity threat detection capability. - tag: AntiSpywareSignatures spec_file: palo-alto-networks-anti-spyware-signatures-api-openapi.yml reanchored_from: palo-alto-networks-antispywaresignatures-api-openapi.yml capability_id: BC-620.30 capability_id_l1: BC-620 capability_name: Threat Detection & Response Management confidence: 0.7 evidence: '''Manages [anti-spyware] ... signatures'' ; ''Create an anti-spyware signature''' reason: Custom threat signature definitions used for detection — cybersecurity threat detection. - tag: Application Override Rules spec_file: palo-alto-networks-application-override-rules-api-openapi.yml capability_id: BC-620.10 capability_id_l1: BC-620 capability_name: Security Strategy & Governance Management confidence: 0.7 evidence: '''Create an application override rule'', ''Move an application override rule'' ... ''managing security services configurations''' reason: Security rule/policy lifecycle management on the network security platform — cybersecurity policy and control governance. - tag: Application Settings spec_file: palo-alto-networks-application-settings-api-openapi.yml capability_id: BC-620 capability_id_l1: BC-620 capability_name: Cybersecurity Management confidence: 0.7 evidence: '"CreateGlobalProtectAgentProfiles Create a GlobalProtect agent profile"; "These APIs are used for defining and managing Prisma Access GlobalProtect services"; schemas tunnel-mtu, connect-method' reason: Configuration of GlobalProtect VPN/secure-access agent profiles (tunnel settings, connect method) is security control configuration. Cybersecurity Management at L1; the evidence does not clearly single out an L2 (secure access architecture vs identity/access). - tag: ApplicationFilters spec_file: palo-alto-networks-application-filters-api-openapi.yml reanchored_from: palo-alto-networks-applicationfilters-api-openapi.yml capability_id: BC-620 capability_id_l1: BC-620 capability_name: Cybersecurity Management confidence: 0.7 evidence: '"post-sse-config-v1-application-filters Create an application filter"; schema objects-application-filters under "/sse/config/v1/"' reason: CRUD over application-filter objects used in network security policy within Strata/SSE configuration. This realises security control configuration (Cybersecurity Management); the specific L2 is not determinable from the object-CRUD surface. - tag: ApplicationGroups spec_file: palo-alto-networks-application-groups-api-openapi.yml reanchored_from: palo-alto-networks-applicationgroups-api-openapi.yml capability_id: BC-620 capability_id_l1: BC-620 capability_name: Cybersecurity Management confidence: 0.7 evidence: '"Manages [application groups](https://docs.paloaltonetworks.com/network-security/security-policy/objects/application-groups)"; "Create an application group"' reason: Application-group objects are explicitly documented as network-security policy objects, so the surface configures security policy building blocks. L1 Cybersecurity Management only, as no L2 is evidenced. - tag: ApplicationOverrideRules spec_file: palo-alto-networks-application-override-rules-api-openapi.yml reanchored_from: palo-alto-networks-applicationoverriderules-api-openapi.yml capability_id: BC-620 capability_id_l1: BC-620 capability_name: Cybersecurity Management confidence: 0.7 evidence: '"post-sse-config-v1-app-override-rules Create an application override rule"; "Move an app override rule" with schema rule-based-move' reason: Ordered firewall/SSE policy rule management (application override rules) — configuration of network security enforcement. Cybersecurity Management at L1; no L2 clearly supported. - tag: Audits spec_file: palo-alto-networks-audits-api-openapi.yml capability_id: BC-620.30 capability_id_l1: BC-620 capability_name: Threat Detection & Response Management confidence: 0.7 evidence: GET /api/v34.03/audits/firewall/app/container Get WAAS Container Audit Events; schemas shared.RuntimeAttackType, cnnf.NetworkFirewallAttackType reason: Despite the 'Audits' name, the operations return runtime security event streams (Docker access, admission control, WAAS firewall attacks) with attack-type schemas — i.e. security detection event retrieval for threat monitoring/response. Some risk it is read-only telemetry rather than full response workflow, hence 0.7. - tag: Authentication Portals spec_file: palo-alto-networks-authentication-portals-api-openapi.yml capability_id: BC-620.20 capability_id_l1: BC-620 capability_name: Identity & Access Management confidence: 0.7 evidence: POST /authentication-portals CreateAuthenticationPortals Create an authentication portal; 'These APIs are used for defining and managing identity services configurations within Strata Cloud Manager' reason: 'Not an API-auth endpoint: these operations author identity-service configuration objects (captive/authentication portals) that govern how end users are authenticated for network access — identity and access management configuration.' - tag: Authentication Sequences spec_file: palo-alto-networks-authentication-sequences-api-openapi.yml capability_id: BC-620.20 capability_id_l1: BC-620 capability_name: Identity & Access Management confidence: 0.7 evidence: POST /authentication-sequences CreateAuthenticationSequences Create an authentication sequence; 'defining and managing identity services configurations within Strata Cloud Manager' reason: Configuration of ordered sets of authentication methods used to validate users — identity and access management configuration rather than API-level auth plumbing. - tag: AuthenticationPortals spec_file: palo-alto-networks-authentication-portals-api-openapi.yml reanchored_from: palo-alto-networks-authenticationportals-api-openapi.yml capability_id: BC-620.20 capability_id_l1: BC-620 capability_name: Identity & Access Management confidence: 0.7 evidence: '"Manages authentication portals." — "Create an authentication portal"' reason: Captive/authentication portal configuration that authenticates users before granting network access; this is identity and access control tooling within a security platform. - tag: Auto VPN Clusters spec_file: palo-alto-networks-auto-vpn-clusters-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.7 evidence: '"Network Services ... These APIs are used for defining and managing network services configuration" — "Create an Auto VPN cluster"' reason: Configuration of VPN cluster network topology; this is network infrastructure provisioning/management rather than a business capability. - tag: Bandwidth Allocations spec_file: palo-alto-networks-bandwidth-allocations-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.7 evidence: '"Allocate aggregated bandwidth", "Edit aggregated bandwidth regions", schema "BandwidthAllocation"' reason: Allocating aggregated bandwidth to Prisma Access regions is provisioning/sizing of network infrastructure capacity for the customer's connectivity fabric — IT Infrastructure Management. - tag: Certificate Approvals spec_file: palo-alto-networks-certificate-approvals-api-openapi.yml capability_id: BC-620.20 capability_id_l1: BC-620 capability_name: Identity & Access Management confidence: 0.7 evidence: '"Approve or reject pending certificate request", "Create an approval rule for certificate", "Update certificate request workflow approval rule"' reason: Approval workflow governing issuance of TLS certificates — machine identity credential issuance control, which sits under Identity & Access Management. Moderate confidence because certificate/PKI management could also be framed as security architecture. - tag: Certificate Revocation Approvals spec_file: palo-alto-networks-certificate-revocation-approvals-api-openapi.yml capability_id: BC-620 capability_id_l1: BC-620 capability_name: Cybersecurity Management confidence: 0.7 evidence: '"Update certificate revocation workflow approval ru..."; schema CertificateRevocationApprovalRuleOpenApi' reason: Approval rules governing certificate revocation workflows — certificate/PKI security control administration. L2 ambiguous between governance and identity. - tag: CertificateObjects spec_file: palo-alto-networks-certificateobjects-api-openapi.yml capability_id: BC-620 capability_id_l1: BC-620 capability_name: Cybersecurity Management confidence: 0.7 evidence: '"Cloud NGFW uses certificates to access an intelligent feed and to enable outbound decryption"; "Create certificate object"' reason: Firewall certificate object configuration used for outbound decryption — network security control configuration. L2 not clearly identifiable. - tag: CertificateProfiles spec_file: palo-alto-networks-certificate-profiles-api-openapi.yml reanchored_from: palo-alto-networks-certificateprofiles-api-openapi.yml capability_id: BC-620 capability_id_l1: BC-620 capability_name: Cybersecurity Management confidence: 0.7 evidence: '"Manages certificates profiles."; "Modify a certificate profile" under /sse/config/v1/certificate-profiles' reason: Certificate profile configuration in the SSE security platform — a cybersecurity control capability; description too thin to pin an L2. - tag: Compliance Standards spec_file: palo-alto-networks-compliance-standards-api-openapi.yml capability_id: BC-130.10 capability_id_l1: BC-130 capability_name: Regulatory Compliance Management confidence: 0.7 evidence: GET /compliance get-all-standards List Compliance Standards; POST /compliance/{complianceId}/requirement add-requirement Add Compliance Requirement reason: Lifecycle management of compliance standards, requirements and sections — the compliance obligation library underpinning regulatory compliance management. - tag: Custom-Rules spec_file: palo-alto-networks-custom-rules-api-openapi.yml capability_id: BC-620.30 capability_id_l1: BC-620 capability_name: Threat Detection & Response Management confidence: 0.7 evidence: '"Get Custom Rules", "Update a Custom Rule"; schemas mitre.Technique, customrules.VulnIDs, customrules.Rule' reason: Custom detection rules referencing MITRE techniques and vulnerability IDs in the workload protection product — authoring of threat detection logic. Mapped to threat detection & response with moderate confidence given the rules also cover vulnerability matching. - tag: DNS Security Profiles spec_file: palo-alto-networks-dns-security-profiles-api-openapi.yml capability_id: BC-620 capability_id_l1: BC-620 capability_name: Cybersecurity Management confidence: 0.7 evidence: '"These APIs are used for defining and managing security services configurations"; "Create a DNS security profile"' reason: Configuration of DNS security (threat prevention) profiles is a cybersecurity control management surface. Kept at L1 because it spans policy/control configuration rather than one named sub-capability. - tag: DNSSecurityProfiles spec_file: palo-alto-networks-dns-security-profiles-api-openapi.yml reanchored_from: palo-alto-networks-dnssecurityprofiles-api-openapi.yml capability_id: BC-620 capability_id_l1: BC-620 capability_name: Cybersecurity Management confidence: 0.7 evidence: '"Manages [DNS security profiles]"; "Create a DNS security profile", "Edit an DNS Security Profile"' reason: Same surface as the Strata DNS security profile API — management of security protection profiles, a cybersecurity control configuration capability; no single L2 is clearly named. - tag: Data Patterns spec_file: palo-alto-networks-data-patterns-api-openapi.yml capability_id: BC-620 capability_id_l1: BC-620 capability_name: Cybersecurity Management confidence: 0.7 evidence: '"Manage data patterns used for detecting sensitive information such as PII, financial data, healthcare information"; "Create Data Pattern"' reason: DLP detection pattern configuration is a cybersecurity data-protection control. No DLP-specific L2 exists in the candidate list, so L1 only. - tag: Data Profiles spec_file: palo-alto-networks-data-profiles-api-openapi.yml capability_id: BC-620 capability_id_l1: BC-620 capability_name: Cybersecurity Management confidence: 0.7 evidence: '"Create and manage data profiles that define collections of data patterns for incident detection"' reason: Grouping of DLP detection patterns into profiles for data protection — cybersecurity control configuration; no precise L2 candidate. - tag: Data Security Settings spec_file: palo-alto-networks-data-security-settings-api-openapi.yml capability_id: BC-620 capability_id_l1: BC-620 capability_name: Cybersecurity Management confidence: 0.7 evidence: '"Add Data Pattern", "List Data Profiles", "Update Data Scan Config", "List Data Resources"' reason: Configuration of DLP data patterns, profiles and scan settings — cybersecurity data-protection control management; no DLP-specific L2 candidate exists. - tag: Device Operations spec_file: palo-alto-networks-device-operations-api-openapi.yml capability_id: BC-600.40 capability_id_l1: BC-600 capability_name: IT Operations Management confidence: 0.7 evidence: '"These APIs can be used to retrieve operational data on your devices, for management and troubleshooting purposes"; "Initiate a job to retrieve route table from device(s)"' reason: Operational data retrieval (route table, FIB, interfaces, logging forwarding status) and local config versions for managed network devices — day-to-day IT operations and troubleshooting. - tag: Discovery and Exposure Management spec_file: palo-alto-networks-discovery-and-exposure-management-api-openapi.yml capability_id: BC-620.40 capability_id_l1: BC-620 capability_name: Vulnerability Management confidence: 0.7 evidence: '"CDEM APIs help you in identifying unmanaged or exposed assets that must be secured"; POST /asm/api/v1/asset/{asset_id}/finding "Get Findings of an Asset"' reason: 'Attack-surface / exposure management: inventory of unmanaged assets plus per-asset findings with snooze/reopen workflow — this is vulnerability and exposure remediation management rather than SOC incident response.' - tag: DoS Protection Profiles spec_file: palo-alto-networks-dos-protection-profiles-api-openapi.yml capability_id: BC-620 capability_id_l1: BC-620 capability_name: Cybersecurity Management confidence: 0.7 evidence: '"Create a DoS protection profile"; "These APIs are used for defining and managing security services configurations within Strata Cloud Manager"' reason: CRUD over firewall denial-of-service protection profiles — configuration of preventive network security controls, so Cybersecurity Management at L1. Evidence does not pin a specific L2 (control configuration spans architecture and threat prevention). - tag: DoS Protection Rules spec_file: palo-alto-networks-dos-protection-rules-api-openapi.yml capability_id: BC-620 capability_id_l1: BC-620 capability_name: Cybersecurity Management confidence: 0.7 evidence: '"Create a DoS protection rule"; "defining and managing security services configurations within Strata Cloud Manager"' reason: 'Same as the profiles surface: lifecycle management of DoS protection policy rules, a preventive security control configuration. L1 Cybersecurity Management only.' - tag: Email DLP API spec_file: palo-alto-networks-email-dlp-api-api-openapi.yml capability_id: BC-620 capability_id_l1: BC-620 capability_name: Cybersecurity Management confidence: 0.7 evidence: '"Get Email Incident Details"; "To prevent sensitive data exfiltration, Enterprise Data Loss Prevention (E-DLP) performs inline inspection of all outbound emails"' reason: Retrieval and status handling of data-loss-prevention incidents on outbound email — a security detection/response surface. Mapped to Cybersecurity Management at L1; DLP incident handling does not map cleanly onto a single listed L2. - tag: Errors spec_file: palo-alto-networks-errors-api-openapi.yml capability_id: BC-620.40 capability_id_l1: BC-620 capability_name: Vulnerability Management confidence: 0.7 evidence: '''Submit Remediation and Suppression Actions''; ''Get Code Issues from Periodic Scans''; ''Get Fixed Resource Code using the selectedFix''' reason: Despite the generic tag name, the operations expose code-security scan findings (CVEs, secrets, IaC violations) with remediation and suppression workflows — vulnerability identification and remediation. Some overlap with software quality engineering, so confidence moderated. - tag: HIP Objects spec_file: palo-alto-networks-hip-objects-api-openapi.yml capability_id: BC-620 capability_id_l1: BC-620 capability_name: Cybersecurity Management confidence: 0.7 evidence: '"These APIs are used for defining and managing policy object configurations within Strata Cloud Manager" — "Create a HIP object" (Host Information Profile)' reason: Host Information Profile objects are security policy objects used to evaluate endpoint posture in a SASE/firewall policy; this is cybersecurity control configuration. Which L2 (security architecture vs access management) is not clear enough from the surface, so L1 only. - tag: HIP Profiles spec_file: palo-alto-networks-hip-profiles-api-openapi.yml capability_id: BC-620 capability_id_l1: BC-620 capability_name: Cybersecurity Management confidence: 0.7 evidence: '"Create a HIP profile" — "defining and managing policy object configurations within Strata Cloud Manager"' reason: HIP profiles group host posture objects for use in security policy enforcement — cybersecurity control configuration. L1 only as the specific sub-capability is ambiguous. - tag: HIPObjects spec_file: palo-alto-networks-hipobjects-api-openapi.yml capability_id: BC-620 capability_id_l1: BC-620 capability_name: Cybersecurity Management confidence: 0.7 evidence: '"Manages [HIP objects](https://docs.paloaltonetworks.com/network-security/security-policy/objects/hip-objects)"' reason: Documented explicitly as network-security security-policy objects; endpoint posture criteria for security enforcement. Cybersecurity management at L1. - tag: HIPProfiles spec_file: palo-alto-networks-hipprofiles-api-openapi.yml capability_id: BC-620 capability_id_l1: BC-620 capability_name: Cybersecurity Management confidence: 0.7 evidence: '"Manages [HIP Profiles](https://docs.paloaltonetworks.com/network-security/security-policy/objects/hip-profiles)"' reason: HIP profile CRUD for security-policy matching on host posture — cybersecurity control configuration; no single L2 clearly indicated. - tag: IntelligentFeed spec_file: palo-alto-networks-intelligentfeed-api-openapi.yml capability_id: BC-620.30 capability_id_l1: BC-620 capability_name: Threat Detection & Response Management confidence: 0.7 evidence: '"An intelligent feed, also called an external dynamic list ... The NGFW checks the hosted list at hourly or daily intervals, and enforces your security rules based on the latest entries"' reason: Threat-intelligence feed (EDL) management driving firewall enforcement — sits within cybersecurity threat detection/response tooling. Some ambiguity vs security architecture/policy, hence moderate confidence. - tag: Interconnect Throughput spec_file: palo-alto-networks-interconnect-throughput-api-openapi.yml capability_id: BC-600.40 capability_id_l1: BC-600 capability_name: IT Operations Management confidence: 0.7 evidence: '"deliver real-time visibility and performance analytics for all configured interconnect resources through the monitoring plane ... track health, bandwidth throughput"' reason: Network monitoring metrics for interconnects — IT operations monitoring of infrastructure. - tag: Interconnect Traffic spec_file: palo-alto-networks-interconnect-traffic-api-openapi.yml capability_id: BC-600.40 capability_id_l1: BC-600 capability_name: IT Operations Management confidence: 0.7 evidence: POST /mt/sp-interconnect/monitor/interconnects/traffic Get Interconnect Data Transfer reason: Traffic/data-transfer monitoring of network interconnects — IT operations monitoring. - tag: Interface Management Profiles spec_file: palo-alto-networks-interface-management-profiles-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.7 evidence: '"These APIs are used for defining and managing network services configuration within Strata Cloud Manager"; CreateInterfaceManagementProfiles' reason: Network interface management profile configuration — network infrastructure configuration. - tag: KerberosServerProfiles spec_file: palo-alto-networks-kerberos-server-profiles-api-openapi.yml reanchored_from: palo-alto-networks-kerberosserverprofiles-api-openapi.yml capability_id: BC-620.20 capability_id_l1: BC-620 capability_name: Identity & Access Management confidence: 0.7 evidence: '"Manages Kerberos server profiles"; POST /sse/config/v1/kerberos-server-profiles "Create a Kerberos server profile"' reason: Kerberos authentication server profile CRUD in the SSE config API — authentication source configuration, mapping to Identity & Access Management. Slightly thinner description than the SCM variant. - tag: LDAPServerProfiles spec_file: palo-alto-networks-ldap-server-profiles-api-openapi.yml reanchored_from: palo-alto-networks-ldapserverprofiles-api-openapi.yml capability_id: BC-620.20 capability_id_l1: BC-620 capability_name: Identity & Access Management confidence: 0.7 evidence: '"Manages LDAP server profiles"; POST /sse/config/v1/ldap-server-profiles "Create an LDAP server profile"' reason: CRUD over LDAP directory connection profiles used for user authentication/lookup in the SSE platform — Identity & Access Management. - tag: LocalUsers spec_file: palo-alto-networks-local-users-api-openapi.yml reanchored_from: palo-alto-networks-localusers-api-openapi.yml capability_id: BC-620.20 capability_id_l1: BC-620 capability_name: Identity & Access Management confidence: 0.7 evidence: '"Manages local users." — POST /sse/config/v1/local-users "Create a local user"' reason: Local user account CRUD within the Prisma Access SSE security configuration; these are authentication principals used for access control, which is Identity & Access Management within the cybersecurity domain rather than HR employee records. - tag: ManageCustomURLCategories spec_file: palo-alto-networks-managecustomurlcategories-api-openapi.yml capability_id: BC-620 capability_id_l1: BC-620 capability_name: Cybersecurity Management confidence: 0.7 evidence: You can use the custom URL categories as a security policy match criteria reason: Creates and maintains custom URL filtering categories used as match criteria in firewall security policy rules — configuration of a network security control, i.e. Cybersecurity Management at L1. No candidate L2 cleanly covers network URL filtering. - tag: ManageFileBlockingActions spec_file: palo-alto-networks-managefileblockingactions-api-openapi.yml capability_id: BC-620 capability_id_l1: BC-620 capability_name: Cybersecurity Management confidence: 0.7 evidence: File blocking actions allow you to identify specific file types that you want to block. reason: Lists and updates file-blocking profile actions enforced by the NGFW — direct configuration of a preventive security control, hence Cybersecurity Management at L1 with no clean L2 match. - tag: PackagesAlerts spec_file: palo-alto-networks-packagesalerts-api-openapi.yml capability_id: BC-620.40 capability_id_l1: BC-620 capability_name: Vulnerability Management confidence: 0.7 evidence: POST /code/api/v1/packagesAlerts/affectedByPackages getAffectedResourcesByPackages Alert Items List for Packages reason: Lists resources affected by vulnerable packages, licences and policy violations in code security scanning — vulnerability findings management. Not financial-crime alerting despite the 'Alerts' noun. - tag: Physical Connection spec_file: palo-alto-networks-physical-connection-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.7 evidence: '"Provision Physical Connection" ... "provision high-capacity physical and virtual links" for Service Provider Interconnects to Prisma Access' reason: Provisioning dedicated network interconnect links is network/cloud infrastructure management, not a security control per se. - tag: Policies spec_file: palo-alto-networks-policies-api-openapi.yml capability_id: BC-620.10 capability_id_l1: BC-620 capability_name: Security Strategy & Governance Management confidence: 0.7 evidence: '"Save New Policy", "Get Continuous Integration (CI) Image Compliance Policy", "Get Container Compliance Policy"' reason: Authoring and maintaining security/compliance policy rules for code and workload security is security governance and policy management. - tag: Policy spec_file: palo-alto-networks-policy-api-openapi.yml capability_id: BC-620.10 capability_id_l1: BC-620 capability_name: Security Strategy & Governance Management confidence: 0.7 evidence: '"Add Policy", "Update Policy Status", "List Policy Compliance Standards", schema ComplianceMetadataModel' reason: CSPM security policy lifecycle and mapping to compliance standards — security policy/GRC governance. - tag: Private Key Import spec_file: palo-alto-networks-private-key-import-api-openapi.yml capability_id: BC-620 capability_id_l1: BC-620 capability_name: Cybersecurity Management confidence: 0.7 evidence: '"Use the TLS Protect Cloud APIs to manage certificates, certificate requests, applications, machine identities, users, teams"; "Import a list of certificates"' reason: Certificate/machine-identity lifecycle management is a cybersecurity capability. Sits between identity management and security architecture, so L1 only. - tag: Profiles spec_file: palo-alto-networks-profiles-api-openapi.yml capability_id: BC-620 capability_id_l1: BC-620 capability_name: Cybersecurity Management confidence: 0.7 evidence: '"Get Runtime Container Profiles", "Learn Runtime Container Profiles", "Get Runtime Host Profiles", schema "shared.AppEmbeddedRuntimeProfile"' reason: Cloud workload runtime security profiles (CWPP) used to baseline and detect anomalous container/host behaviour — cybersecurity capability; L2 ambiguous between threat detection and security architecture. - tag: Quarantined Devices spec_file: palo-alto-networks-quarantined-devices-api-openapi.yml capability_id: BC-620 capability_id_l1: BC-620 capability_name: Cybersecurity Management confidence: 0.7 evidence: '"List quarantined devices", "Create a quarantined device", "Delete a quarantined device"; "defining and managing policy object configurations"' reason: Managing the quarantine list of devices blocked from network access is a security enforcement/response control; L2 ambiguous between access control and threat response. - tag: Remediations spec_file: palo-alto-networks-remediations-api-openapi.yml capability_id: BC-620.40 capability_id_l1: BC-620 capability_name: Vulnerability Management confidence: 0.7 evidence: POST /code/api/v1/remediations/buildtime "Remediation for Build time"; GET .../{fixId} "Get Remediation Fix Code" reason: Generates and retrieves code fixes for security findings detected at build time in Prisma Cloud code security — remediation of identified vulnerabilities/misconfigurations. Sits adjacent to software construction, so not maximal confidence. - tag: Remote Networks spec_file: palo-alto-networks-remote-networks-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.7 evidence: POST /v1/remote-networks "Create IPSec tunnels"; schemas IpsecTunnel, IkeCryptoProfiles, RemoteNetworksProtocolBgp reason: Provisioning and modification of IPSec tunnels and remote-network sites (SASE branch connectivity) — network infrastructure configuration under IT infrastructure management. - tag: RemoteNetworks spec_file: palo-alto-networks-remote-networks-api-openapi.yml reanchored_from: palo-alto-networks-remotenetworks-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.7 evidence: '"Manages Remote Networks." POST /sse/config/v1/remote-networks "Create remote networks"' reason: CRUD over remote-network (branch site) connectivity configuration in the SSE/Prisma Access config plane — network infrastructure configuration. - tag: SCEP Profiles spec_file: palo-alto-networks-scep-profiles-api-openapi.yml capability_id: BC-620.20 capability_id_l1: BC-620 capability_name: Identity & Access Management confidence: 0.7 evidence: '"Identity Services SCEP Profiles API ... defining and managing identity services configurations" — "Create a SCEP profile"' reason: SCEP certificate-enrolment profiles issue device/user credentials, treated as identity and credential (access) management within the security platform. - tag: SCEPProfiles spec_file: palo-alto-networks-scep-profiles-api-openapi.yml reanchored_from: palo-alto-networks-scepprofiles-api-openapi.yml capability_id: BC-620.20 capability_id_l1: BC-620 capability_name: Identity & Access Management confidence: 0.7 evidence: '"Manages SCEP profiles." — "Create SCEP profiles"' reason: SCEP profile CRUD configures certificate enrolment for authenticating endpoints/users, mapping to Identity & Access Management. - tag: SD-WAN Rules spec_file: palo-alto-networks-sd-wan-rules-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.7 evidence: '"Create an SD-WAN rule" under "Network Services ... configuration within Strata Cloud Manager"' reason: SD-WAN traffic steering rules are network configuration objects; maps to IT Infrastructure Management. 'Rules' here is networking policy, not compliance policy. - tag: SD-WAN SaaS Quality Profiles spec_file: palo-alto-networks-sd-wan-saas-quality-profiles-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.7 evidence: '"Create an SD-WAN SaaS quality profile" / "managing network services configuration"' reason: Despite the 'SaaS' noun, these operations configure SD-WAN path monitoring toward SaaS applications — network infrastructure configuration, not SaaS tenant or subscription management. - tag: Scan Reports spec_file: palo-alto-networks-scan-reports-api-openapi.yml capability_id: BC-620.30 capability_id_l1: BC-620 capability_name: Threat Detection & Response Management confidence: 0.7 evidence: '"Retrieve Threat Scan Reports"; schemas ThreatScanReportObject, MalwareReportObject, CmdInjectReportObject, UrlFilterReportObject' reason: Retrieval of threat detection reports (malware, command injection, URL filtering) from AI runtime security — threat detection and response reporting. - tag: Security Zones spec_file: palo-alto-networks-security-zones-api-openapi.yml capability_id: BC-620 capability_id_l1: BC-620 capability_name: Cybersecurity Management confidence: 0.7 evidence: '"Create a security zone", description "defining and managing network services configuration within Strata Cloud Manager"' reason: Security zone definitions are firewall network-security segmentation constructs, so cybersecurity configuration; no single L2 is clearly named. - tag: Ssl Decryption Settings spec_file: palo-alto-networks-ssl-decryption-settings-api-openapi.yml capability_id: BC-620.50 capability_id_l1: BC-620 capability_name: Security Architecture Management confidence: 0.7 evidence: GET /ssl-decryption-settings getSslDecryptionSettings ... These APIs are used for defining and managing security services configurations within Strata Cloud Manager. reason: Manages SSL/TLS decryption inspection settings — a security control configuration for inspecting encrypted traffic, fitting security architecture/control design rather than any other candidate. - tag: Stats spec_file: palo-alto-networks-stats-api-openapi.yml capability_id: BC-620.40 capability_id_l1: BC-620 capability_name: Vulnerability Management confidence: 0.7 evidence: GET /api/v34.03/stats/vulnerabilities Get Vulnerability (CVEs) Stats ... types.VulnerabilityStats reason: Aggregated statistics over CVE vulnerabilities, impacted resources and compliance posture from Prisma Cloud CWPP — vulnerability posture reporting, closest to Vulnerability Management; some spread into compliance stats hence 0.7. - tag: TACACS Server Profiles spec_file: palo-alto-networks-tacacs-server-profiles-api-openapi.yml capability_id: BC-620.20 capability_id_l1: BC-620 capability_name: Identity & Access Management confidence: 0.7 evidence: '''Identity Services ... These APIs are used for defining and managing identity services configurations'' with ''Create a TACACS server profile''' reason: TACACS server profiles configure AAA/authentication back-ends, which is identity and access management configuration; sub-capability supported by the 'Identity Services' framing. - tag: TACACSServerProfiles spec_file: palo-alto-networks-tacacsserverprofiles-api-openapi.yml capability_id: BC-620.20 capability_id_l1: BC-620 capability_name: Identity & Access Management confidence: 0.7 evidence: '''Manages Terminal Access Controller Access-Control System (TACACS) server profiles.''' reason: Managing TACACS (access-control/authentication) server profiles is identity and access management infrastructure configuration. - tag: Tunnel Interfaces spec_file: palo-alto-networks-tunnel-interfaces-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.7 evidence: '"These APIs are used for defining and managing network services configuration"; CreateTunnelInterfaces / UpdateTunnelInterfacesByID' reason: CRUD over network tunnel interfaces is network infrastructure configuration, mapping to IT Infrastructure Management (compute, storage, network). Not a business capability beyond IT. - tag: URL Access Profiles spec_file: palo-alto-networks-url-access-profiles-api-openapi.yml capability_id: BC-620.10 capability_id_l1: BC-620 capability_name: Security Strategy & Governance Management confidence: 0.7 evidence: '"Create a URL access profile" under "defining and managing security services configurations within Strata Cloud Manager"' reason: URL filtering/access security policy profiles — a cybersecurity control configuration. L1 Cybersecurity is solid; the security-policy sub-capability choice is less certain, hence 0.7. - tag: URL Categories spec_file: palo-alto-networks-url-categories-api-openapi.yml capability_id: BC-620.10 capability_id_l1: BC-620 capability_name: Security Strategy & Governance Management confidence: 0.7 evidence: Create a custom URL category — "These APIs are used for defining and managing security services configurations within Strata Cloud Manager." reason: Custom URL categories are security policy objects used in web-filtering enforcement; this is cybersecurity control configuration, best fitting security governance/policy configuration rather than any business capability. - tag: URLAccessProfiles spec_file: palo-alto-networks-urlaccessprofiles-api-openapi.yml capability_id: BC-620.10 capability_id_l1: BC-620 capability_name: Security Strategy & Governance Management confidence: 0.7 evidence: '"Manages URL access profiles" ... security-profile-url-filtering; Create a URL access profile' reason: Security profile configuration governing permitted web access — cybersecurity policy/control management. - tag: URLCategories spec_file: palo-alto-networks-urlcategories-api-openapi.yml capability_id: BC-620.10 capability_id_l1: BC-620 capability_name: Security Strategy & Governance Management confidence: 0.7 evidence: '"Manages URL Categories" ... custom-objects/url-category; Create a custom URL categories' reason: Custom URL category objects for security policy; cybersecurity control configuration.