What It Does
Give non-human identities owners, expiry and scope on the same terms as human ones.
Observable indicator. Every service account has a named owner and an expiry date.
Where It Sits
A technique is chosen from inside a form and emplaced on one layer. Both are the catalog’s own declarations; the position is counted in catalog order.
- Form of maneuverM3 EnvelopmentMake identity, not network location, the decisive plane — surround the adversary with policy.
- Terrain layerT1 IdentityThe high ground. Key terrain: The ICAM policy decision point, privileged accounts, external-user and mission-staff identities.
- Position in the form6 of 20M3 carries 20 cataloged techniques; this is the 6th in catalog order.
Phases It Is Employed In
Employed in one phase of the campaign. A phase named here means at least this technique is live in it — not that the form it belongs to is the main effort.
- Phase 0ShapeContinuous terrain preparation, zero-trust hardening, partnerships, threat intelligence.
Controls That Assess It
The controls the catalog names against this technique. They are what an assessor would test to establish that it is emplaced and working — the indicator above is what shows it is working, which is a different question.
- TM-7 Terrain OwnershipTerrain Management — To attach every element to a person who can be asked to act, so that findings convert into work rather than accumulating.
- SM-3 Implementation State TrackingScheme of Maneuver — To make the coverage figure reflect what is defending the estate rather than what is intended to, by weighting mitigation by implementation state.
- ID-2 Credential Strength and BindingIdentity Terrain — To ensure the credential is as strong as the access behind it, so that proofing and authentication assurance are matched rather than assumed.
In MITRE D3FEND
What this technique is called in MITRE’s countermeasure ontology. The join runs technique-to-technique: D3FEND catalogs countermeasures, and the thing with a countermeasure’s shape here is the technique, not the control.
- D3-AA Agent AuthenticationHarden tactic
- D3-CP Certificate PinningHarden tactic
- D3-CRO Credential RotationHarden tactic
- D3-CERO Certificate RotationHarden tactic
That a technique reaches a D3FEND countermeasure says the two describe the same defensive act. It does not say the countermeasure is deployed, configured, or working — that is an assessment finding about your estate, not a property of the framework.
Related Techniques
The catalog declares no relation for this entry, and no other entry names it — the inverse is derived here, so an incoming edge would show up even though this one never declared it. The techniques below share its assessment surface, which is the nearest adjacency the data supports.
Assessed Alongside
Not a declared relation: these are the techniques whose assessing controls overlap this one’s, ranked by how much of the two assessment surfaces coincide. Showing 6 of 12 that share at least one control.
- 2 shared controlsM2.12 Secrets ManagementM2 Defense in Depth · T4 Applications and Workloads
- ID-2
- SM-3
- 1 shared controlM1.09 Supply Chain and Vendor WatchM1 Screen / Guard · TX Cross-Cutting
- TM-7
- 1 shared controlM3.07 Standing Privilege EliminationM3 Envelopment · T1 Identity
- SM-3
- 1 shared controlM3.08 Identity Lifecycle EnforcementM3 Envelopment · T1 Identity
- SM-3
- 1 shared controlM3.14 Entitlement RecertificationM3 Envelopment · T1 Identity
- SM-3
- 1 shared controlM3.12 Authorization Policy as CodeM3 Envelopment · T1 Identity
- SM-3