Mapping of the ASOM-Fed technique layer to MITRE D3FEND v1.5.0. Every ASOM-Fed technique either carries at least one D3FEND mapping or a recorded not-applicable reason; the build fails on a third state.
1. Coverage summary
| Tactic | Covered | Total | Share |
|---|---|---|---|
| Model | 27 | 27 | 100% |
| Harden | 35 | 56 | 63% |
| Detect | 80 | 90 | 89% |
| Isolate | 56 | 57 | 98% |
| Deceive | 11 | 11 | 100% |
| Evict | 19 | 19 | 100% |
| Restore | 12 | 12 | 100% |
| Total | 240 | 272 | 88% |
All seven D3FEND tactics are reached. Five are at 98 percent or above. The shortfall is concentrated in Harden and is almost entirely one cluster, explained in section 3.
2. Mapping by ASOM-Fed form
M1
| ASOM technique | Name | D3FEND techniques |
|---|---|---|
M1.01 | External Attack Surface Enumeration | D3-AI Asset Inventory, D3-NM Network Mapping, D3-NVA Network Vulnerability Assessment, D3-SYSVA System Vulnerability Assessment |
M1.02 | Shadow and Forgotten Asset Discovery | D3-AI Asset Inventory, D3-CI Configuration Inventory, D3-DI Data Inventory, D3-NNI Network Node Inventory, D3-SWI Software Inventory |
M1.03 | Certificate and Domain Watch | D3-ACA Active Certificate Analysis, D3-DNRA Domain Name Reputation Analysis, D3-HD Homoglyph Detection, D3-PCA Passive Certificate Analysis |
M1.04 | Perimeter Canary Tokens | D3-DNR Decoy Network Resource, D3-DO Decoy Object |
M1.05 | Authentication Geography Baseline | D3-IAA Identifier Activity Analysis, D3-ID Identifier Analysis, D3-UBA User Behavior Analysis, D3-UGLPA User Geolocation Logon Pattern Analysis |
M1.06 | Credential Exposure Monitoring | D3-CCSA Credential Compromise Scope Analysis, D3-IRA Identifier Reputation Analysis |
M1.07 | Partner and Advisory Intake | D3-AVE Asset Vulnerability Enumeration, D3-ORA Operational Risk Assessment |
M1.08 | Public Service Abuse Telemetry | D3-CAA Connection Attempt Analysis, D3-CSPP Client-server Payload Profiling, D3-FA File Analysis, D3-FCOA File Content Analysis, D3-ISVA Inbound Session Volume Analysis, D3-WSAA Web Session Activity Analysis |
M1.09 | Supply Chain and Vendor Watch | D3-ODM Operational Dependency Mapping, D3-SVCDM Service Dependency Mapping |
M1.10 | Named-Campaign Indicator Watch | D3-IRA Identifier Reputation Analysis, D3-NTSA Network Traffic Signature Analysis |
M1.11 | Operational Technology Asset Discovery | D3-AI Asset Inventory, D3-HCI Hardware Component Inventory, D3-IDA Input Device Analysis, D3-NNI Network Node Inventory, D3-PLLM Passive Logical Link Mapping, D3-RFUM Remote Firmware Update Monitoring |
M1.12 | Workforce Credential Exposure Monitoring | D3-CCSA Credential Compromise Scope Analysis, D3-IRA Identifier Reputation Analysis, D3-OM Organization Mapping |
M1.13 | Physical Access Anomaly Detection | D3-APLM Active Physical Link Mapping, D3-DPLM Direct Physical Link Mapping, D3-ELM Electronic Lock Monitoring, D3-MSM Motion Sensor Monitoring, D3-PHAM Physical Access Monitoring, D3-PLM Physical Link Mapping, D3-PSM Proximity Sensor Monitoring, D3-VS Video Surveillance |
M1.14 | Supplier Exposure Monitoring | D3-AVE Asset Vulnerability Enumeration, D3-CIA Container Image Analysis, D3-SWI Software Inventory |
M1.15 | Device Estate Discovery | D3-AI Asset Inventory, D3-HCI Hardware Component Inventory, D3-NNI Network Node Inventory, D3-SWI Software Inventory, D3-EHB Endpoint Health Beacon |
M2
| ASOM technique | Name | D3FEND techniques |
|---|---|---|
M2.01 | Trust Zone Architecture | D3-BDI Broadcast Domain Isolation, D3-NI Network Isolation |
M2.02 | Policy Enforcement Point Placement | D3-ACMD Access Mediation, D3-NAM Network Access Mediation |
M2.03 | Crown-Jewel Enclave | D3-NI Network Isolation, D3-NRAM Network Resource Access Mediation |
M2.04 | Independent Control Redundancy | D3-SVCDM Service Dependency Mapping, D3-SYSDM System Dependency Mapping |
M2.05 | Endpoint Detection and Response Coverage | D3-EHB Endpoint Health Beacon, D3-FIM File Integrity Monitoring, D3-MBT Memory Boundary Tracking, D3-OSM Operating System Monitoring, D3-PA Process Analysis, D3-PCSV Process Code Segment Verification, D3-SFA System File Analysis |
M2.06 | Device Posture Gating | D3-AA Agent Authentication, D3-NAM Network Access Mediation |
M2.07 | Web Application Protection | D3-BSE Byte Sequence Emulation, D3-CF Content Filtering, D3-DA Dynamic Analysis, D3-EBWSAM Endpoint-based Web Server Access Mediation, D3-EFA Emulated File Analysis, D3-ITF Inbound Traffic Filtering, D3-PBWSAM Proxy-based Web Server Access Mediation, D3-WSAM Web Session Access Mediation |
M2.08 | API Authorization Enforcement | D3-APA Access Policy Administration, D3-NRAM Network Resource Access Mediation |
M2.09 | Data-at-Rest Encryption and Key Separation | D3-DENCR Disk Encryption, D3-FE File Encryption |
M2.10 | Egress Data Loss Prevention | D3-CF Content Filtering, D3-CM Content Modification, D3-CNE Content Excision, D3-CQ Content Quarantine, D3-DEM Data Exchange Mapping, D3-OTF Outbound Traffic Filtering, D3-UDTA User Data Transfer Analysis |
M2.11 | Workload Hardening Baseline | D3-ACH Application Configuration Hardening, D3-AH Application Hardening, D3-PH Platform Hardening, D3-SCF System Call Filtering, D3-SCP System Configuration Permissions |
M2.12 | Secrets Management | D3-ANCI Authentication Cache Invalidation, D3-CH Credential Hardening, D3-CRO Credential Rotation, D3-CS Credential Scrubbing |
M2.13 | Backup Isolation and Immutability | D3-BA Bootloader Authentication, D3-DLIC Driver Load Integrity Checking, D3-HBWP Hardware-based Write Protection, D3-RDI Restore Disk Image, D3-TBI TPM Boot Integrity |
M2.14 | Control Failure Detection | D3-EHB Endpoint Health Beacon, D3-PM Platform Monitoring, D3-SDM System Daemon Monitoring |
M2.15 | Safety Instrumented Layer Integrity | D3-BMA Bus Message Authentication, D3-MAN Message Authentication, D3-MENCR Message Encryption, D3-OMM Operating Mode Monitoring, D3-OPR Operating Mode Restriction, D3-TAAN Transfer Agent Authentication |
M2.16 | Role-Based Privilege Minimization | D3-UAP User Account Permissions, D3-UGPH User Group Permissions |
M2.17 | Facility Defense in Depth | D3-EPL Physical Locking, D3-PAM Physical Access Mediation, D3-PEH Physical Enclosure Hardening |
M2.18 | Component Provenance Verification | D3-CIA Container Image Analysis, D3-SWI Software Inventory, D3-TL Trusted Library |
M3
| ASOM technique | Name | D3FEND techniques |
|---|---|---|
M3.01 | Phishing-Resistant Authentication | D3-CBAN Certificate-based Authentication, D3-MFA Multi-factor Authentication, D3-TBA Token-based Authentication |
M3.02 | Conditional Access Policy Engine | D3-ACMD Access Mediation, D3-APA Access Policy Administration |
M3.03 | Continuous Authorization | D3-APA Access Policy Administration, D3-AZET Authorization Event Thresholding |
M3.04 | Just-in-Time Privilege | D3-CRO Credential Rotation, D3-UAP User Account Permissions |
M3.05 | Privileged Access Workstations | D3-ABPI Application-based Process Isolation, D3-EI Execution Isolation, D3-HBPI Hardware-based Process Isolation, D3-KBPI Kernel-based Process Isolation, D3-PH Platform Hardening |
M3.06 | Machine and Service Identity Governance | D3-AA Agent Authentication, D3-CERO Certificate Rotation, D3-CP Certificate Pinning, D3-CRO Credential Rotation |
M3.07 | Standing Privilege Elimination | D3-UAP User Account Permissions, D3-UGPH User Group Permissions |
M3.08 | Identity Lifecycle Enforcement | D3-AL Account Locking, D3-CR Credential Revocation |
M3.09 | External-User Identity Assurance | D3-BAN Biometric Authentication, D3-CDP Change Default Password, D3-MFA Multi-factor Authentication, D3-OTP One-time Password, D3-PWA Password Authentication, D3-SPP Strong Password Policy |
M3.10 | Device-Bound Credentials | D3-CBAN Certificate-based Authentication, D3-CP Certificate Pinning, D3-TB Token Binding |
M3.11 | Session and Token Revocation Path | D3-ANCI Authentication Cache Invalidation, D3-CR Credential Revocation, D3-ST Session Termination |
M3.12 | Authorization Policy as Code | D3-APA Access Policy Administration, D3-LFP Local File Permissions, D3-UGPH User Group Permissions |
M3.13 | Federation Trust Boundary Control | D3-DTP Domain Trust Policy |
M3.14 | Entitlement Recertification | D3-JFAPA Job Function Access Pattern Analysis, D3-UAP User Account Permissions |
M3.15 | Break-Glass Account Control | D3-AL Account Locking, D3-ANET Authentication Event Thresholding |
M3.16 | Token Replay Protection | D3-CTS Credential Transmission Scoping, D3-TB Token Binding |
M3.17 | Authentication Anomaly Scoring | D3-ANET Authentication Event Thresholding, D3-UBA User Behavior Analysis, D3-UGLPA User Geolocation Logon Pattern Analysis |
M3.18 | Identity Provider Tamper Detection | D3-DAM Domain Account Monitoring, D3-SICA System Init Config Analysis |
M3.19 | Human-to-Account Binding | D3-DAM Domain Account Monitoring, D3-LAM Local Account Monitoring |
M3.20 | Supplier Identity Federation | D3-DTP Domain Trust Policy, D3-NAM Network Access Mediation |
M4
| ASOM technique | Name | D3FEND techniques |
|---|---|---|
M4.01 | Microsegmentation | D3-BDI Broadcast Domain Isolation, D3-NI Network Isolation |
M4.02 | East-West Deny by Default | D3-NI Network Isolation, D3-NTF Network Traffic Filtering |
M4.03 | Egress Filtering and Allow-Listing | D3-CF Content Filtering, D3-CFC Content Format Conversion, D3-OTF Outbound Traffic Filtering |
M4.04 | DNS Control and Sinkholing | D3-DNSAL DNS Allowlisting, D3-DNSDL DNS Denylisting, D3-FRDDL Forward Resolution Domain Denylisting, D3-HDDL Hierarchical Domain Denylisting, D3-HDL Homoglyph Denylisting |
M4.05 | Application Allow-Listing | D3-ABPI Application-based Process Isolation, D3-EAL Executable Allowlisting, D3-EDL Executable Denylisting, D3-SCF System Call Filtering |
M4.06 | Administrative Path Restriction | D3-LAMED LAN Access Mediation, D3-NAM Network Access Mediation, D3-RAM Routing Access Mediation |
M4.07 | Cloud Boundary Enforcement | D3-APA Access Policy Administration, D3-NI Network Isolation |
M4.08 | Instrumented Corridor Design | D3-NI Network Isolation, D3-NTA Network Traffic Analysis |
M4.09 | Removable Media Control | D3-IOPR IO Port Restriction, D3-LFAM Local File Access Mediation, D3-LFP Local File Permissions |
M4.10 | Bastion and Jump-Host Enforcement | D3-NAM Network Access Mediation, D3-RFAM Remote File Access Mediation |
M4.11 | Protocol and Port Restriction | D3-ITF Inbound Traffic Filtering, D3-NTF Network Traffic Filtering |
M4.12 | Denied-Path Register Enforcement | D3-NTF Network Traffic Filtering, D3-NTPM Network Traffic Policy Mapping |
M4.13 | Operational Technology Segregation | D3-BDI Broadcast Domain Isolation, D3-DNL Directional Network Link, D3-NI Network Isolation |
M4.14 | Control Protocol Constraint | D3-APCA Application Protocol Command Analysis, D3-CTS Credential Transmission Scoping, D3-OPR Operating Mode Restriction, D3-OVAR OT Variable Access Restriction |
M4.15 | Physical Zone Segregation | D3-EPL Physical Locking, D3-PAM Physical Access Mediation |
M4.16 | Maintenance Access Constraint | D3-DRA Disable Remote Access, D3-IOPR IO Port Restriction, D3-NAM Network Access Mediation |
M4.17 | Supplier Access Canalisation | D3-NAM Network Access Mediation, D3-NRAM Network Resource Access Mediation |
M5
| ASOM technique | Name | D3FEND techniques |
|---|---|---|
M5.01 | Decoy Records in the Data Layer | D3-DF Decoy File, D3-DO Decoy Object |
M5.02 | Honeytokens in Document Stores | D3-DF Decoy File, D3-DO Decoy Object |
M5.03 | Decoy Credentials | D3-DUC Decoy User Credential |
M5.04 | Honeypot Services in Corridors | D3-CHN Connected Honeynet, D3-DNR Decoy Network Resource |
M5.05 | Canary Files on Endpoints | D3-DF Decoy File |
M5.06 | Decoy Service Endpoints | D3-DNR Decoy Network Resource |
M5.07 | Identity-Plane Deception | D3-DP Decoy Persona, D3-DST Decoy Session Token, D3-DUC Decoy User Credential |
M5.08 | Decoy Cloud Resources | D3-DNR Decoy Network Resource, D3-DO Decoy Object |
M5.09 | Deception Alert Routing | D3-DE Decoy Environment |
M5.10 | Deception Coverage Measurement | D3-DE Decoy Environment |
M5.11 | Control Network Deception | D3-DNR Decoy Network Resource, D3-IHN Integrated Honeynet |
M5.12 | Phishing Deception and Reporting | D3-DP Decoy Persona, D3-DPR Decoy Public Release, D3-EF Email Filtering |
M5.13 | Physical Deception | D3-DO Decoy Object, D3-SHN Standalone Honeynet |
M6
| ASOM technique | Name | D3FEND techniques |
|---|---|---|
M6.01 | Adaptive Rate Limiting | D3-ISVA Inbound Session Volume Analysis, D3-ITF Inbound Traffic Filtering |
M6.02 | Step-Up Authentication on Anomaly | D3-ANET Authentication Event Thresholding, D3-MFA Multi-factor Authentication, D3-OTP One-time Password |
M6.03 | Bulk Export Throttling | D3-OTF Outbound Traffic Filtering, D3-UDTA User Data Transfer Analysis |
M6.04 | Session Duration Reduction Under Alert | D3-ANCI Authentication Cache Invalidation, D3-SDA Session Duration Analysis, D3-ST Session Termination |
M6.05 | Approval Gates on High-Impact Actions | D3-APA Access Policy Administration, D3-UAP User Account Permissions |
M6.06 | Tarpitting and Response Delay | D3-ITF Inbound Traffic Filtering |
M6.07 | Progressive Lockout | D3-AL Account Locking, D3-ANET Authentication Event Thresholding |
M6.08 | Change and Deploy Freeze Under Contact | D3-SU Software Update |
M6.09 | Query Complexity Limits | D3-CV Content Validation, D3-DLV Domain Logic Validation, D3-DQSA Database Query String Analysis |
M6.10 | Update Staging and Soak | D3-SU Software Update, D3-SWI Software Inventory |
M7
| ASOM technique | Name | D3FEND techniques |
|---|---|---|
M7.01 | Hypothesis-Driven Hunting | D3-NTA Network Traffic Analysis, D3-PA Process Analysis, D3-UBA User Behavior Analysis |
M7.02 | Fusion-Fed Hunt Backlog | D3-ORA Operational Risk Assessment |
M7.03 | Automated Containment Playbooks | D3-NI Network Isolation, D3-PT Process Termination, D3-ST Session Termination |
M7.04 | Host Isolation on Confirmation | D3-HR Host Reboot, D3-HS Host Shutdown, D3-NI Network Isolation |
M7.05 | Credential Reset Sweep | D3-CR Credential Revocation, D3-CRO Credential Rotation, D3-RIC Reissue Credential |
M7.06 | Build Pipeline Integrity Hunt | D3-CIA Container Image Analysis, D3-CNR Content Rebuild, D3-CNS Content Substitution, D3-SBV Service Binary Verification, D3-SEA Script Execution Analysis |
M7.07 | Persistence Sweep | D3-IBCA Indirect Branch Call Analysis, D3-PSMD Process Self-Modification Detection, D3-RKD Registry Key Deletion, D3-SDM System Daemon Monitoring, D3-SICA System Init Config Analysis, D3-SJA Scheduled Job Analysis, D3-SSC Shadow Stack Comparisons, D3-USICA User Session Init Config Analysis |
M7.08 | Lateral Path Audit | D3-ALLM Active Logical Link Mapping, D3-AM Access Modeling, D3-LLM Logical Link Mapping, D3-NM Network Mapping |
M7.09 | Detection Engineering from Hunt | D3-FCR File Content Rules, D3-NTSA Network Traffic Signature Analysis |
M7.10 | Purple-Team Validation | D3-NVA Network Vulnerability Assessment, D3-SYSVA System Vulnerability Assessment |
M7.11 | Eviction Sequencing | D3-CE Credential Eviction, D3-DNSCE DNS Cache Eviction, D3-FEV File Eviction, D3-OE Object Eviction, D3-PE Process Eviction |
M7.12 | Adversary Dwell Reconstruction | D3-FAPA File Access Pattern Analysis, D3-FCA File Creation Analysis, D3-PLA Process Lineage Analysis, D3-PSA Process Spawn Analysis, D3-RTSD Remote Terminal Session Detection, D3-SCA System Call Analysis |
M7.13 | Hunt Coverage Accounting | D3-SYSM System Mapping |
M7.14 | Process Anomaly Hunting | D3-OMM Operating Mode Monitoring, D3-OPM Operational Process Monitoring, D3-PUM Platform Uptime Monitoring |
M7.15 | Insider Risk Investigation | D3-JFAPA Job Function Access Pattern Analysis, D3-RAPA Resource Access Pattern Analysis, D3-SDA Session Duration Analysis, D3-UBA User Behavior Analysis |
M7.16 | Supply Chain Compromise Hunting | D3-CIA Container Image Analysis, D3-FCDC File Content Decompression Checking, D3-FFV File Format Verification, D3-FIM File Integrity Monitoring, D3-FISV File Internal Structure Verification, D3-FMBV File Magic Byte Verification, D3-FMCV File Metadata Consistency Validation, D3-FMVV File Metadata Value Verification, D3-SBV Service Binary Verification |
M7.17 | Malicious Message Eviction | D3-ER Email Removal, D3-EF Email Filtering |
M8
| ASOM technique | Name | D3FEND techniques |
|---|---|---|
M8.01 | Automated Segment Severing | D3-BDI Broadcast Domain Isolation, D3-NI Network Isolation |
M8.02 | Estate-Wide Session Revocation | D3-ANCI Authentication Cache Invalidation, D3-CR Credential Revocation, D3-ST Session Termination |
M8.03 | Read-Only Service Degradation | D3-OPR Operating Mode Restriction, D3-PS Process Suspension, D3-PT Process Termination |
M8.04 | Fail-Secure Default Posture | D3-APA Access Policy Administration |
M8.05 | Federation Trust Suspension | D3-DTP Domain Trust Policy |
M8.06 | Cloud Account Quarantine | D3-AL Account Locking, D3-UAP User Account Permissions |
M8.07 | Egress Blackhole | D3-FRIDL Forward Resolution IP Denylisting, D3-OTF Outbound Traffic Filtering, D3-RRID Reverse Resolution IP Denylisting |
M8.08 | Statutory Availability Floor | not applicable — see section 4 |
M8.09 | Contained Forensic Preservation | D3-FC File Carving, D3-FH File Hashing |
M8.10 | Third-Party Connection Cutout | D3-NAM Network Access Mediation, D3-NTF Network Traffic Filtering |
M8.11 | Restoration Preconditions | D3-RO Restore Object |
M8.12 | Degradation Rehearsal | not applicable — see section 4 |
M8.13 | Safe-State Isolation | D3-OMM Operating Mode Monitoring, D3-OPR Operating Mode Restriction |
M8.14 | Rapid Offboarding and Revocation | D3-AL Account Locking, D3-ANCI Authentication Cache Invalidation, D3-CR Credential Revocation |
M8.15 | Facility Isolation | D3-EPL Physical Locking, D3-PAM Physical Access Mediation |
M8.16 | Supplier Severance | D3-CR Credential Revocation, D3-NAM Network Access Mediation |
M8.17 | Device Decommissioning and Sanitization | D3-DKE Disk Erasure, D3-DKF Disk Formatting, D3-DKP Disk Partitioning, D3-CR Credential Revocation |
M9
| ASOM technique | Name | D3FEND techniques |
|---|---|---|
M9.01 | Advisory-Driven Pre-Blocking | D3-DNSDL DNS Denylisting, D3-FRDDL Forward Resolution Domain Denylisting, D3-FRIDL Forward Resolution IP Denylisting |
M9.02 | Targeted Emergency Patching | D3-AVE Asset Vulnerability Enumeration, D3-FBA Firmware Behavior Analysis, D3-FEMC Firmware Embedded Monitoring Code, D3-FV Firmware Verification, D3-PFV Peripheral Firmware Verification, D3-SFV System Firmware Verification, D3-SU Software Update |
M9.03 | Staged Infrastructure Denial | D3-DNSDL DNS Denylisting, D3-DRT Domain Registration Takedown, D3-NTCD Network Traffic Community Deviation, D3-PMAD Protocol Metadata Anomaly Detection, D3-RPA Relay Pattern Analysis, D3-RRID Reverse Resolution IP Denylisting |
M9.04 | Sector Intelligence Exchange | D3-IRA Identifier Reputation Analysis |
M9.05 | Pre-Emptive Credential Invalidation | D3-CR Credential Revocation, D3-PR Password Rotation |
M9.06 | Vendor Compromise Response | D3-NAM Network Access Mediation, D3-SVCDM Service Dependency Mapping |
M9.07 | Exploited-Vulnerability Catalog Enforcement | D3-AVE Asset Vulnerability Enumeration, D3-SU Software Update, D3-SYSVA System Vulnerability Assessment |
M9.08 | Workforce Threat Briefing | not applicable — see section 4 |
M9.09 | Supplier Advisory Pre-emption | D3-AVE Asset Vulnerability Enumeration, D3-SU Software Update |
M10
| ASOM technique | Name | D3FEND techniques |
|---|---|---|
M10.01 | Indicator-to-Detection Conversion | D3-FCR File Content Rules, D3-FHRA File Hash Reputation Analysis, D3-IRA Identifier Reputation Analysis, D3-NTSA Network Traffic Signature Analysis, D3-SMRA Sender MTA Reputation Analysis, D3-SRA Sender Reputation Analysis, D3-UA URL Analysis, D3-URA URL Reputation Analysis |
M10.02 | Avenue Closure Verification | D3-NVA Network Vulnerability Assessment, D3-SYSVA System Vulnerability Assessment |
M10.03 | Terrain Overlay Update | D3-AI Asset Inventory, D3-NM Network Mapping, D3-SYSM System Mapping |
M10.04 | Intelligence Requirement Revision | not applicable — see section 4 |
M10.05 | Community Reporting | not applicable — see section 4 |
M10.06 | Doctrine and Catalog Update | not applicable — see section 4 |
M10.07 | Supply Chain Lesson Propagation | D3-SVCDM Service Dependency Mapping |
M11
| ASOM technique | Name | D3FEND techniques |
|---|---|---|
M11.01 | Recovery Objective Declaration | D3-OAM Operational Activity Mapping, D3-ODM Operational Dependency Mapping |
M11.02 | Isolated Recovery Environment | D3-HBWP Hardware-based Write Protection, D3-NI Network Isolation |
M11.03 | Golden Image and Rebuild Path | D3-RDI Restore Disk Image, D3-RS Restore Software |
M11.04 | Identity Plane Reconstitution | D3-RA Restore Access, D3-RIC Reissue Credential, D3-RUAA Restore User Account Access, D3-ULA Unlock Account |
M11.05 | Recovery Data Integrity Verification | D3-FH File Hashing, D3-FIM File Integrity Monitoring, D3-RD Restore Database |
M11.06 | Service Restoration Sequencing | D3-RC Restore Configuration, D3-RNA Restore Network Access, D3-RS Restore Software |
M11.07 | Reconstitution Exercise | D3-RF Restore File, D3-RO Restore Object |
M11.08 | Key Personnel Continuity | D3-OM Organization Mapping |
M11.09 | Alternate Facility Activation | D3-RA Restore Access, D3-RC Restore Configuration, D3-RNA Restore Network Access |
M11.10 | Supplier-Independent Rebuild | D3-RDI Restore Disk Image, D3-RS Restore Software |
M11.11 | Mailbox and Message Restoration | D3-RE Restore Email, D3-RO Restore Object, D3-FH File Hashing |
3. D3FEND techniques not reached
32 of 272 D3FEND techniques are not reached by any ASOM-Fed technique. Each is recorded below with its reason. These are scope statements rather than gaps: ASOM-Fed operates at the maneuver-planning level of abstraction, and D3FEND descends to source-code and memory-safety countermeasures that a planning framework does not direct.
| D3FEND | Tactic | Technique | Reason not reached |
|---|---|---|---|
D3-CFI | Harden | Control Flow Integrity | Source-code and compiler hardening. ASOM-Fed excludes secure SDLC (PR.PS-06) as inherited from SA-15. |
D3-DCE | Harden | Dead Code Elimination | Compiler-level. Secure SDLC, inherited. |
D3-EHPV | Harden | Exception Handler Pointer Validation | Memory-safety countermeasure. Secure SDLC, inherited. |
D3-EMH | Harden | Electromagnetic Radiation Hardening | Electromagnetic radiation hardening — outside the archetype. |
D3-IRV | Harden | Integer Range Validation | Input-validation countermeasure at code level. Secure SDLC, inherited. |
D3-MBSV | Harden | Memory Block Start Validation | Memory-safety countermeasure. Secure SDLC, inherited. |
D3-MH | Harden | Message Hardening | Abstract parent of message-hardening techniques; children are covered via M2.15. |
D3-NPC | Harden | Null Pointer Checking | Memory-safety countermeasure. Secure SDLC, inherited. |
D3-OLV | Harden | Operational Logic Validation | Code-level logic validation. Secure SDLC, inherited. |
D3-PAN | Harden | Pointer Authentication | Memory-safety countermeasure. Secure SDLC, inherited. |
D3-PRH | Harden | Particle Radiation Hardening | Particle radiation hardening — outside the archetype. |
D3-PSEP | Harden | Process Segment Execution Prevention | Memory-safety countermeasure. Secure SDLC, inherited. |
D3-PV | Harden | Pointer Validation | Memory-safety countermeasure. Secure SDLC, inherited. |
D3-RFS | Harden | RF Shielding | RF shielding — outside the archetype. |
D3-RH | Harden | Radiation Hardening | Radiation hardening — spacecraft and high-radiation environments outside the Federal Reference Agency archetype. |
D3-RN | Harden | Reference Nullification | Memory-safety countermeasure. Secure SDLC, inherited. |
D3-SAOR | Harden | Segment Address Offset Randomization | Memory-safety countermeasure. Secure SDLC, inherited. |
D3-SCH | Harden | Source Code Hardening | Source Code Hardening is the parent of the above. Explicitly out of scope per Framework section 6. |
D3-SFCV | Harden | Stack Frame Canary Validation | Memory-safety countermeasure. Secure SDLC, inherited. |
D3-VI | Harden | Variable Initialization | Memory-safety countermeasure. Secure SDLC, inherited. |
D3-VTV | Harden | Variable Type Validation | Memory-safety countermeasure. Secure SDLC, inherited. |
D3-AEM | Detect | Application Exception Monitoring | Below the maneuver-planning level of abstraction; inherited from the SP 800-53 baseline. |
D3-ANAA | Detect | Administrative Network Activity Analysis | Below the maneuver-planning level of abstraction; inherited from the SP 800-53 baseline. |
D3-APM | Detect | Application Performance Monitoring | Below the maneuver-planning level of abstraction; inherited from the SP 800-53 baseline. |
D3-CA | Detect | Certificate Analysis | Below the maneuver-planning level of abstraction; inherited from the SP 800-53 baseline. |
D3-DNSTA | Detect | DNS Traffic Analysis | Below the maneuver-planning level of abstraction; inherited from the SP 800-53 baseline. |
D3-IPCTA | Detect | IPC Traffic Analysis | Below the maneuver-planning level of abstraction; inherited from the SP 800-53 baseline. |
D3-IPRA | Detect | IP Reputation Analysis | Subsumed by D3-IRA Identifier Reputation Analysis, which M1.06, M1.10, M9.04 and M10.01 cover. |
D3-MA | Detect | Message Analysis | Abstract parent of message-analysis techniques; children are covered via M1.08 and M5.12. |
D3-PHDURA | Detect | Per Host Download-Upload Ratio Analysis | Below the maneuver-planning level of abstraction; inherited from the SP 800-53 baseline. |
D3-RTA | Detect | RPC Traffic Analysis | Below the maneuver-planning level of abstraction; inherited from the SP 800-53 baseline. |
D3-ET | Isolate | Encrypted Tunnels | Below the maneuver-planning level of abstraction; inherited from the SP 800-53 baseline. |
4. ASOM-Fed techniques with no D3FEND equivalent
D3FEND catalogs countermeasures. The techniques below are governance, exercise and reporting activities with nothing to map to, and are recorded so that an absent mapping is distinguishable from a forgotten one.
| ASOM technique | Name | Reason |
|---|---|---|
M8.08 | Statutory Availability Floor | Statutory Availability Floor — a legal constraint on defensive action, not a countermeasure. |
M8.12 | Degradation Rehearsal | Degradation Rehearsal — an exercise activity. |
M9.08 | Workforce Threat Briefing | Workforce Threat Briefing — a human preparation activity. |
M10.04 | Intelligence Requirement Revision | Intelligence Requirement Revision — an analytic governance activity. |
M10.05 | Community Reporting | Community Reporting — an information-sharing obligation. |
M10.06 | Doctrine and Catalog Update | Doctrine and Catalog Update — a framework maintenance activity. |
5. Method and standing
The join is technique-to-technique, which is the natural one: both frameworks separate a small set of durable categories from a large set of concrete behaviors, and it is the concrete layers that correspond. Mapping at tactic level alone would be too coarse to be actionable; mapping ASOM-Fed controls to D3FEND techniques would cross abstraction levels.
Coverage is computed by the build tooling from d3fend_reference.psv and d3fend_mapping.psv and is verified on every build: an unknown D3FEND identifier, an unknown ASOM-Fed technique, or a technique with neither a mapping nor a recorded not-applicable reason all fail the build.
D3FEND is a trademark of The MITRE Corporation, which does not endorse this framework.