ASOM-Fedv6.1Open the explorer
D3-NI · Isolate tactic · MITRE D3FEND v1.5.0

Network Isolation

Where It Sits in the Scheme

11 ASOM-Fed techniques reach this countermeasure, across 5 forms of maneuver.

This is the direction the forward mapping cannot answer. A reader who works in D3FEND arrives holding D3-NI and needs to know where it is employed in a scheme of maneuver — not which of MITRE's tactics it belongs to, which they already know.

Reached By

  • M2.01 Trust Zone ArchitectureM2 Defense in Depth · T3 Networks

    Define trust zones that reflect real boundaries and assurance differences, and record which elements sit in which.

  • M2.03 Crown-Jewel EnclaveM2 Defense in Depth · T5 Data

    Isolate the decisive data behind its own enforcement point, with its own authorization policy and its own telemetry.

  • M4.01 MicrosegmentationM4 Obstacle / Canalization · T3 Networks

    Reduce reachability between workloads to what is declared, so lateral movement requires defeating policy rather than finding a route.

  • M4.02 East-West Deny by DefaultM4 Obstacle / Canalization · T3 Networks

    Make the default answer between segments "no", with exceptions declared, owned and expiring.

  • M4.07 Cloud Boundary EnforcementM4 Obstacle / Canalization · T3 Networks

    Enforce account, VPC and role boundaries in the cloud with the same rigor as network segments on the ground.

  • M4.08 Instrumented Corridor DesignM4 Obstacle / Canalization · T3 Networks

    Deliberately leave the paths you want an adversary to take, and instrument them heavily.

  • M4.13 Operational Technology SegregationM4 Obstacle / Canalization · T6 Operational Technology

    Separate control-system networks from the enterprise with an enforced, inspectable boundary rather than a documented intention.

  • M7.03 Automated Containment PlaybooksM7 Counterattack · TX Cross-Cutting

    Encode containment as tested automation so the decision, not the execution, is the slow step.

  • M7.04 Host Isolation on ConfirmationM7 Counterattack · T2 Devices

    Sever a host from the network on confirmed compromise while preserving it for analysis.

  • M8.01 Automated Segment SeveringM8 Isolation / Retrograde · T3 Networks

    Hold a tested capability to sever a segment or zone on decision, without an unplanned outage of everything else.

  • M11.02 Isolated Recovery EnvironmentM11 Reconstitution · T5 Data

    Hold the means of recovery outside the blast radius of the production identity plane, so compromise cannot reach what rebuilds you.

Forms That Arrive Here

A countermeasure reached from more than one form is employed more than one way. D3FEND has no notion of a form, so this join exists only here.

  • M2 Defense in DepthThe formEnsure no single failure is decisive.
  • M4 Obstacle / CanalizationThe formForce the adversary onto ground you own and watch.
  • M7 CounterattackThe formSeize the initiative and evict before the adversary reaches the objective.
  • M8 Isolation / RetrogradeThe formGive ground deliberately to preserve the force. Degrade gracefully; never fail open.
  • M11 ReconstitutionThe formRestore the mission on evidence, not on hope — and prove it before you need it.

What This Does Not Claim

That a technique reaches a D3FEND countermeasure says the two describe the same defensive act. It does not say the countermeasure is deployed, configured, or working — that is an assessment finding about your estate, not a property of the framework.

MITRE's own entry for this technique is at d3fend.mitre.org, and it is the authority on what the countermeasure is. This page is the authority only on where it sits in ASOM-Fed. D3FEND™ and ATT&CK® are trademarks of The MITRE Corporation. This mapping is published by threatDefendr and is neither produced nor endorsed by MITRE.