Resources
OMS Coverage Map
Where Palo Fits in Optiv's Framework
A complete mapping of Palo Alto Networks solutions to the Optiv Market System (OMS) — 10 security domains (including AI Security), every sub-domain, with coverage levels and PA ownership.
What Is the Optiv Market System (OMS)?
The Optiv Market System (OMS) is Optiv's reference architecture and security taxonomy. It organizes the entire cybersecurity landscape into 9 core security domains (plus AI Security as an emerging 10th) — from Infrastructure and Operations to Identity, Risk, and Physical Security.
Optiv uses the OMS during SPL (Strategic Partner Landscape) assessments to map vendor coverage across these domains, identify gaps, and guide technology investments. Understanding where Palo Alto Networks maps — and where gaps exist — is essential for positioning deals through Optiv's framework.
At a Glance
Coverage Across Key Domains
A quick view of Palo Alto Networks' presence in each OMS domain.
Detailed Mapping
Domain-by-Domain Breakdown
Every sub-domain mapped to PAN solutions, coverage level, and PA ownership.
Infrastructure
StrongNetwork, cloud, endpoint, and OT/IoT security — the foundational layer of any security architecture.
| Sub-Domain | PAN Solution | Coverage | PA Owner |
|---|---|---|---|
| Network Security | Strata NGFWs on PAN-OS 12.2 "Ceres"Next-Generation Firewalls — hardware and virtual firewalls with ML-powered threat prevention, App-ID, and security subscriptions. PA-5450 end-of-sale Nov 22, 2026 (replacement PA-5500 Series)., Strata Cloud ManagerThe single management console for all Palo Alto network security — NGFWs, SASE, and subscriptions in one pane. Two tiers only: Essentials (free) and Pro (paid); SCM Pro ships in the ESA via a single auth code., CDSS SubscriptionsCloud-Delivered Security Services for NGFWs: Advanced Threat Prevention, Advanced IP Defense (GA Aug 4, 2026), Advanced Virtual Patching, DNS Security, Advanced WildFire, IoT/OT Security, Advanced URL Filtering, Enterprise DLP, SD-WAN. | Strong | Ford, Chad, Charles |
| Secure Access / SASE | Prisma Access 6.2Cloud-delivered secure access — ZTNA, SWG, CASB, and FWaaS in one service, managed through SCM. GlobalProtect is not retired; the Prisma Access Agent is a migration path., Prisma SD-WANSoftware-defined WAN with intelligent path selection, app-aware routing, and integrated security., Prisma BrowserSecure enterprise browser with DLP, isolation, and SaaS visibility. Current official name is Prisma Browser (not "Prisma Access Browser"). Native integration with Cortex XDR and XSIAM shipped in XDR 5.2., Enterprise CASB and Enterprise DLPSASE-delivered SaaS control and data protection., ADEMAutonomous Digital Experience Management — end-to-end visibility into user-to-app performance. | Strong | Ford |
| Cloud Security | Cortex Cloud 2.2Unified CNAPP + CDR across four modules: Application Security, Cloud Posture Security, Cloud Runtime Security, Security Operations. Prisma Cloud is legacy — the official path is upgrade to Cortex Cloud. CN-Series end-of-sale Nov 1, 2026, replaced by AI Runtime Firewall. (CNAPP + CDR) | Strong | Chad |
| Endpoint Security | Cortex XDR 5.2Extended Detection and Response. Current licensing is Cortex XDR Pro EP and Cortex XDR EP Cloud on an Enterprise Runtime Security (XDR) + Core Analytics base. Agentic Endpoint Security (AES) is integral to the agent from 5.2; ITDR 2.0 also shipped in 5.2., XSIAM agentUnified endpoint agent combining XDR detection, prevention, and forensics capabilities. | Strong | Charles |
| OT/ICS | PA-400R and PA-50R ruggedized NGFWsRuggedized firewalls for OT/ICS environments — manufacturing, energy, and critical infrastructure. The K2-Series reached end-of-life Feb 28, 2026; do not quote it., IoT/OT Security subscriptionAuto-discovers and classifies IoT and OT devices, then enforces least-privilege security policies. PAN-OS 12.2 adds proactive OT microsegmentation. | Moderate | Ford |
| IoT | IoT/OT SecurityAuto-discovers and classifies IoT and OT devices on the network and enforces least-privilege policies. subscription, PA-400R / PA-50R ruggedized NGFWs (K2-Series end-of-life Feb 28, 2026) | Moderate | Ford |
Operations
StrongSecurity operations center capabilities — detection, response, automation, threat intelligence, and incident management.
| Sub-Domain | PAN Solution | Coverage | PA Owner |
|---|---|---|---|
| TDR | XSIAM 3.6AI-driven SOC platform unifying SIEM and SOAR, with XDR, ASM, Exposure Management and ITDR as modules. Tiers are NG-SIEM, Enterprise and Premium (Enterprise Plus is retired). 3.6 GA Jul 20, 2026 adds frontier AI model choice, Cortex XTI and natural-language dashboards., Cortex XDR 5.2Extended Detection and Response — endpoint agent for cross-data-source detection, investigation, and response., Advanced Email SecurityAI-powered email security detecting phishing, BEC, and malware — included in XSIAM. | Strong | Charles |
| Orchestration & Automation | Cortex AgentiX 1.4Positioned by Palo Alto as the evolution of its SOAR platform, though XSOAR is still sold standalone. Licensed per user per year: Enterprise (4 users / 800 CU) or Base (2 users / 400 CU). FedRAMP Moderate and High., 1,300+ playbooks, MCPModel Context Protocol — enables AgentiX agents to securely communicate with on-premise systems. | Strong | Charles |
| Analytics | XSIAM analytics, XQL, Cortex XDL 2.0Cortex Data Lake 2.0 — centralizes logs and telemetry from firewalls, endpoints and cloud; 15+ PB/day across 1,100+ integrations. XSIAM alone ingests >17 PB/day., Federated SearchQuery data across Splunk, S3, etc. without requiring data migration. | Strong | Charles |
| Threat Intelligence | Unit 42Palo's elite threat intelligence and incident response team., TIM add-onThreat Intelligence Management — aggregates and operationalizes threat intel feeds., WildFireCloud-based malware sandbox detonating suspicious files to identify zero-day threats. | Strong | Charles |
| Incident Response | Unit 42 IR, XSIAM case mgmt, Forensics | Strong | Charles |
| Insider Threat & Fraud | ITDR 2.0Identity Threat Detection and Response, shipped in XDR 5.2 as an add-on module — Conditional Access Policies (Okta, Entra, on-prem AD), Active Directory Security Posture Management, 17 new detectors, granular RBAC., UEBAUser and Entity Behavior Analytics — ML-powered detection of anomalous user behavior. | Strong | Charles |
| Digital Brand Protection | Xpanse Expander 2.14 / XSIAM ASMAttack Surface Management — discovers internet-facing assets to find exposures. Exposure Management is now a distinct XSIAM/XDR module, separate from Xpanse/ASM. + Digital Risk Protection | Moderate | Charles |
| AML | No PAN solution | None | N/A |
| Observability | ChronosphereAcquisition closed Jan 29, 2026 for $3.35B; brand retained, >$300M ARR. There is no product called "Cortex Observability" — the Cortex AgentiX integration is announced but not yet GA. Embrace (mobile RUM) intent announced Jul 21, 2026. — Telemetry PipelineChronosphere data routing — filters and routes observability data, 30%+ noise reduction., metrics, logs, traces, 30%+ noise reduction | Strong | Ford, Chad, Charles |
Identity
Strong NewIdentity security across access management, governance, PAM, and lifecycle — powered by Idira (formerly CyberArk; ~$25B acquisition closed Feb 11, 2026, rebranded and GA May 12, 2026).
| Sub-Domain | PAN Solution | Coverage | PA Owner |
|---|---|---|---|
| Digital Access Management | Idira access management (SSO, MFA) | Strong | TBD |
| Identity Governance | Idira identity governanceIdentity Governance — automates access reviews and role-based provisioning. | Strong | TBD |
| User/Entity Lifecycle | Idira identity lifecycleFull identity lifecycle — joiner/mover/leaver with automated provisioning., ITDR 2.0Identity Threat Detection and Response — shipped in XDR 5.2 as an add-on module. | Strong | TBD |
| Identity Orchestration | Idira identity orchestrationLow-code identity orchestration across apps and infrastructure., Cortex AgentiX 1.4Agentic AI SOAR — autonomous agents that investigate, triage, and remediate incidents without human intervention. | Moderate | TBD |
| PAM | Idira Privileged Access ManagerPrivileged Access Management — vaults, rotates, and monitors credentials. Idira Endpoint Privilege Manager integrates with XSIAM via Cortex Marketplace (XSIAM 3.5). Also confirmed: Idira Secrets Hub, Certificate Manager, Idira Secure AI Agents. (human+machine+agentic) | Strong | TBD |
| CIAM | Idira customer identityCIAM for external/customer-facing identity with adaptive authentication. | Moderate | TBD |
| OCM | No PAN solution (services play) | None | N/A |
Data Protection
ModerateData security and governance — protecting sensitive information across the enterprise.
| Sub-Domain | PAN Solution | Coverage | PA Owner |
|---|---|---|---|
| Data Security | Enterprise DLPDLP delivered through Prisma Access for network-level data protection., Cortex DLPDLP in XSIAM — prevents sensitive data exposure across endpoints and cloud. Cortex XDR 5.2 raised DLP file inspection to 300 MB., NGFW DLPDLP at the firewall — inspects traffic for sensitive data and blocks exfiltration. | Strong | Ford / Charles |
| Data Governance | No direct solution | Gap | N/A |
Application Security
ModerateSecuring the software development lifecycle and application runtime environments.
| Sub-Domain | PAN Solution | Coverage | PA Owner |
|---|---|---|---|
| Secure SDLC | Cortex Cloud ASPMApplication Security Posture Management — finds risks across code, dependencies, and pipelines., code-to-cloud | Moderate | Chad |
| App Operations & Security | Prisma AIRS 3.0 AI Runtime SecurityReal-time LLM protection — guards against prompt injection, data leakage, and hallucination. Portkey (closed May 29, 2026) is the AI Gateway., Cortex Cloud 2.2Unified CNAPP + CDR platform for cloud security, workload protection, and runtime defense., WildFireCloud-based malware sandbox detonating suspicious files to identify zero-day threats. | Moderate | Chad |
AI Security
Strong NewSecuring AI models, agents, LLM applications, and the entire AI lifecycle — a new frontier in the security landscape.
| Sub-Domain | PAN Solution | Coverage | PA Owner |
|---|---|---|---|
| AI Model Security | Prisma AIRS 3.0 — AI Model Security: model scanning (35+ file types, 25+ threat categories); Protect AI technology now fully absorbed | Strong | Ford, Chad, Charles |
| AI Red Teaming | Prisma AIRS 3.0 — AI Red Teaming: automated adversarial testing, prompt injection detection | Strong | Ford, Chad, Charles |
| AI Posture Management | Prisma AIRS 3.0 — AI-SPM: discover shadow AI, map data flows, model/pipeline inventory | Strong | Ford, Chad, Charles |
| AI Runtime Protection | Prisma AIRS 3.0 — AI Runtime Security: real-time LLM guardrails, data leakage prevention, hallucination detection; AI Runtime Firewall replaces CN-Series (end-of-sale Nov 1, 2026) | Strong | Ford, Chad, Charles |
| AI Agent Security | Prisma AIRS 3.0 AI Agent Security + Koi-based Agentic Endpoint Security (Koi acquisition closed Apr 14, 2026; the ~$400M price is press-reported and officially undisclosed) — identity, tool misuse, memory manipulation for AI agents. AES is now integral to the Cortex XDR agent from 5.2 with zero additional deployment. | Moderate | Ford, Chad, Charles |
Risk
LightRisk management, compliance operations, and cyber insurance — organizational risk governance.
| Sub-Domain | PAN Solution | Coverage | PA Owner |
|---|---|---|---|
| Compliance | Cortex Cloud complianceContinuous compliance against CIS, SOC2, HIPAA, PCI and other frameworks., SCM Compliance CentreSCM dashboard tracking posture compliance across managed firewalls and SASE. | Moderate | Chad |
| Risk Governance | No PAN solution | None | N/A |
| Risk Operations | XSIAM 3.6AI-driven SOC platform. Exposure Management is now a distinct XSIAM/XDR module, separate from Xpanse/ASM. Exposure Management, ASMAttack Surface Management — discovers internet-facing assets to find exposures. | Moderate | Charles |
| Cyber Insurance | No PAN solution | None | N/A |
Offensive Security
LightProactive security testing — red teaming, attacker simulation, and readiness assessments.
| Sub-Domain | PAN Solution | Coverage | PA Owner |
|---|---|---|---|
| Attacker Simulation | Prisma AIRS AI Red TeamingAutomated adversarial testing for AI — finds prompt injection and jailbreak vulns., Unit 42Palo's elite threat intelligence and incident response team. Frontier AI Defense services launched 2026: Exposure Analysis, Autonomous Security Blueprint, Agentic Defense Transformation. | Moderate | Charles |
| Readiness | Unit 42 readiness, XSIAMAI-driven SOC platform unifying SIEM, SOAR, XDR, ASM, and ITDR with ML-powered alert grouping. detection validation | Moderate | Charles |
| OEM Security | No PAN solution | None | N/A |
Privacy
LightPrivacy operations, governance, and regulatory compliance for data privacy mandates.
| Sub-Domain | PAN Solution | Coverage | PA Owner |
|---|---|---|---|
| Privacy Operations | Enterprise DLPData Loss Prevention — detects and prevents sensitive data exfiltration., Prisma BrowserCurrent official name is Prisma Browser, not "Prisma Access Browser". (mask/block/prevent) | Moderate | Ford |
| Privacy Governance | No PAN solution | None | N/A |
| Privacy Regulations | No PAN solution | None | N/A |
Physical Security
NonePhysical security controls — access control systems, surveillance, and facility protection. No PAN coverage.
| Sub-Domain | PAN Solution | Coverage | PA Owner |
|---|---|---|---|
| All sub-domains | No PAN solution | None | N/A |