What It Does
Make device health a precondition of access, so a compromised or non-compliant endpoint cannot spend a valid credential.
Observable indicator. Failing posture denies access rather than raising a ticket.
Where It Sits
A technique is chosen from inside a form and emplaced on one layer. Both are the catalog’s own declarations; the position is counted in catalog order.
- Form of maneuverM2 Defense in DepthEnsure no single failure is decisive.
- Terrain layerT2 DevicesThe entry fords. Key terrain: Mission-staff laptops, contractor devices, the server and VM fleet.
- Position in the form6 of 18M2 carries 18 cataloged techniques; this is the 6th in catalog order.
Phases It Is Employed In
Employed in 2 of the campaign’s six phases. A phase named here means at least this technique is live in it — not that the form it belongs to is the main effort.
Controls That Assess It
The controls the catalog names against this technique. They are what an assessor would test to establish that it is emplaced and working — the indicator above is what shows it is working, which is a different question.
- KT-2 Decisive Point Protection FloorKey Terrain and Decisive Points — To ensure designation produces protection, so that identifying a decisive point is an act with consequences rather than an annotation.
- SM-2 Maneuver AssignmentScheme of Maneuver — To bind defensive intent to specific ground, so that coverage reflects what protects which element rather than what the program has bought.
- DV-2 Device Posture as an Access PreconditionDevices Terrain — To ensure a compromised or non-compliant device cannot spend a valid credential, closing the gap `M3` Envelopment leaves when identity alone is enforced.
In MITRE D3FEND
What this technique is called in MITRE’s countermeasure ontology. The join runs technique-to-technique: D3FEND catalogs countermeasures, and the thing with a countermeasure’s shape here is the technique, not the control.
- D3-AA Agent AuthenticationHarden tactic
- D3-NAM Network Access MediationIsolate tactic
That a technique reaches a D3FEND countermeasure says the two describe the same defensive act. It does not say the countermeasure is deployed, configured, or working — that is an assessment finding about your estate, not a property of the framework.
Related Techniques
The catalog declares no relation for this entry, and no other entry names it — the inverse is derived here, so an incoming edge would show up even though this one never declared it. The techniques below share its assessment surface, which is the nearest adjacency the data supports.
Assessed Alongside
Not a declared relation: these are the techniques whose assessing controls overlap this one’s, ranked by how much of the two assessment surfaces coincide. Showing 6 of 35 that share at least one control.
- 3 shared controlsM3.10 Device-Bound CredentialsM3 Envelopment · T2 Devices
- DV-2
- KT-2
- SM-2
- 2 shared controlsM2.07 Web Application ProtectionM2 Defense in Depth · T4 Applications and Workloads
- KT-2
- SM-2
- 2 shared controlsM2.08 API Authorization EnforcementM2 Defense in Depth · T4 Applications and Workloads
- KT-2
- SM-2
- 2 shared controlsM3.04 Just-in-Time PrivilegeM3 Envelopment · T1 Identity
- KT-2
- SM-2
- 2 shared controlsM3.05 Privileged Access WorkstationsM3 Envelopment · T2 Devices
- DV-2
- KT-2
- 2 shared controlsM3.09 External-User Identity AssuranceM3 Envelopment · T1 Identity
- KT-2
- SM-2