{
  "_note": "D3FEND v1.5.0 techniques not reached by any ASOM-Fed technique, with the reason. ASOM-Fed operates at the maneuver-planning level of abstraction; D3FEND descends to source-code and memory-safety countermeasures that a planning framework does not direct. These are scope statements, not gaps.",
  "d3fend_version": "1.5.0",
  "techniques_total": 272,
  "techniques_covered": 240,
  "uncovered": {
    "D3-AEM": {
      "tactic": "Detect",
      "technique": "Application Exception Monitoring",
      "reason": "Below the maneuver-planning level of abstraction; inherited from the SP 800-53 baseline."
    },
    "D3-ANAA": {
      "tactic": "Detect",
      "technique": "Administrative Network Activity Analysis",
      "reason": "Below the maneuver-planning level of abstraction; inherited from the SP 800-53 baseline."
    },
    "D3-APM": {
      "tactic": "Detect",
      "technique": "Application Performance Monitoring",
      "reason": "Below the maneuver-planning level of abstraction; inherited from the SP 800-53 baseline."
    },
    "D3-CA": {
      "tactic": "Detect",
      "technique": "Certificate Analysis",
      "reason": "Below the maneuver-planning level of abstraction; inherited from the SP 800-53 baseline."
    },
    "D3-CFI": {
      "tactic": "Harden",
      "technique": "Control Flow Integrity",
      "reason": "Source-code and compiler hardening. ASOM-Fed excludes secure SDLC (PR.PS-06) as inherited from SA-15."
    },
    "D3-DCE": {
      "tactic": "Harden",
      "technique": "Dead Code Elimination",
      "reason": "Compiler-level. Secure SDLC, inherited."
    },
    "D3-DNSTA": {
      "tactic": "Detect",
      "technique": "DNS Traffic Analysis",
      "reason": "Below the maneuver-planning level of abstraction; inherited from the SP 800-53 baseline."
    },
    "D3-EHPV": {
      "tactic": "Harden",
      "technique": "Exception Handler Pointer Validation",
      "reason": "Memory-safety countermeasure. Secure SDLC, inherited."
    },
    "D3-EMH": {
      "tactic": "Harden",
      "technique": "Electromagnetic Radiation Hardening",
      "reason": "Electromagnetic radiation hardening \u2014 outside the archetype."
    },
    "D3-ET": {
      "tactic": "Isolate",
      "technique": "Encrypted Tunnels",
      "reason": "Below the maneuver-planning level of abstraction; inherited from the SP 800-53 baseline."
    },
    "D3-IPCTA": {
      "tactic": "Detect",
      "technique": "IPC Traffic Analysis",
      "reason": "Below the maneuver-planning level of abstraction; inherited from the SP 800-53 baseline."
    },
    "D3-IPRA": {
      "tactic": "Detect",
      "technique": "IP Reputation Analysis",
      "reason": "Subsumed by D3-IRA Identifier Reputation Analysis, which M1.06, M1.10, M9.04 and M10.01 cover."
    },
    "D3-IRV": {
      "tactic": "Harden",
      "technique": "Integer Range Validation",
      "reason": "Input-validation countermeasure at code level. Secure SDLC, inherited."
    },
    "D3-MA": {
      "tactic": "Detect",
      "technique": "Message Analysis",
      "reason": "Abstract parent of message-analysis techniques; children are covered via M1.08 and M5.12."
    },
    "D3-MBSV": {
      "tactic": "Harden",
      "technique": "Memory Block Start Validation",
      "reason": "Memory-safety countermeasure. Secure SDLC, inherited."
    },
    "D3-MH": {
      "tactic": "Harden",
      "technique": "Message Hardening",
      "reason": "Abstract parent of message-hardening techniques; children are covered via M2.15."
    },
    "D3-NPC": {
      "tactic": "Harden",
      "technique": "Null Pointer Checking",
      "reason": "Memory-safety countermeasure. Secure SDLC, inherited."
    },
    "D3-OLV": {
      "tactic": "Harden",
      "technique": "Operational Logic Validation",
      "reason": "Code-level logic validation. Secure SDLC, inherited."
    },
    "D3-PAN": {
      "tactic": "Harden",
      "technique": "Pointer Authentication",
      "reason": "Memory-safety countermeasure. Secure SDLC, inherited."
    },
    "D3-PHDURA": {
      "tactic": "Detect",
      "technique": "Per Host Download-Upload Ratio Analysis",
      "reason": "Below the maneuver-planning level of abstraction; inherited from the SP 800-53 baseline."
    },
    "D3-PRH": {
      "tactic": "Harden",
      "technique": "Particle Radiation Hardening",
      "reason": "Particle radiation hardening \u2014 outside the archetype."
    },
    "D3-PSEP": {
      "tactic": "Harden",
      "technique": "Process Segment Execution Prevention",
      "reason": "Memory-safety countermeasure. Secure SDLC, inherited."
    },
    "D3-PV": {
      "tactic": "Harden",
      "technique": "Pointer Validation",
      "reason": "Memory-safety countermeasure. Secure SDLC, inherited."
    },
    "D3-RFS": {
      "tactic": "Harden",
      "technique": "RF Shielding",
      "reason": "RF shielding \u2014 outside the archetype."
    },
    "D3-RH": {
      "tactic": "Harden",
      "technique": "Radiation Hardening",
      "reason": "Radiation hardening \u2014 spacecraft and high-radiation environments outside the Federal Reference Agency archetype."
    },
    "D3-RN": {
      "tactic": "Harden",
      "technique": "Reference Nullification",
      "reason": "Memory-safety countermeasure. Secure SDLC, inherited."
    },
    "D3-RTA": {
      "tactic": "Detect",
      "technique": "RPC Traffic Analysis",
      "reason": "Below the maneuver-planning level of abstraction; inherited from the SP 800-53 baseline."
    },
    "D3-SAOR": {
      "tactic": "Harden",
      "technique": "Segment Address Offset Randomization",
      "reason": "Memory-safety countermeasure. Secure SDLC, inherited."
    },
    "D3-SCH": {
      "tactic": "Harden",
      "technique": "Source Code Hardening",
      "reason": "Source Code Hardening is the parent of the above. Explicitly out of scope per Framework section 6."
    },
    "D3-SFCV": {
      "tactic": "Harden",
      "technique": "Stack Frame Canary Validation",
      "reason": "Memory-safety countermeasure. Secure SDLC, inherited."
    },
    "D3-VI": {
      "tactic": "Harden",
      "technique": "Variable Initialization",
      "reason": "Memory-safety countermeasure. Secure SDLC, inherited."
    },
    "D3-VTV": {
      "tactic": "Harden",
      "technique": "Variable Type Validation",
      "reason": "Memory-safety countermeasure. Secure SDLC, inherited."
    }
  },
  "techniques_not_applicable": {
    "_note": "ASOM techniques with no D3FEND equivalent. D3FEND catalogs countermeasures; these are governance, doctrine and reporting activities with nothing to map to. Recorded so an absent mapping is distinguishable from a forgotten one.",
    "M8.08": "Statutory Availability Floor \u2014 a legal constraint on defensive action, not a countermeasure.",
    "M8.12": "Degradation Rehearsal \u2014 an exercise activity.",
    "M9.08": "Workforce Threat Briefing \u2014 a human preparation activity.",
    "M10.04": "Intelligence Requirement Revision \u2014 an analytic governance activity.",
    "M10.05": "Community Reporting \u2014 an information-sharing obligation.",
    "M10.06": "Doctrine and Catalog Update \u2014 a framework maintenance activity."
  }
}