What It Does
Enforce account, VPC and role boundaries in the cloud with the same rigor as network segments on the ground.
Observable indicator. Cross-account reachability matches the declared design exactly.
Where It Sits
A technique is chosen from inside a form and emplaced on one layer. Both are the catalog’s own declarations; the position is counted in catalog order.
- Form of maneuverM4 Obstacle / CanalizationForce the adversary onto ground you own and watch.
- Terrain layerT3 NetworksThe corridors. Key terrain: TIC 3.0 access points, segment boundaries, cloud VPC peering.
- Position in the form7 of 17M4 carries 17 cataloged techniques; this is the 7th in catalog order.
Phases It Is Employed In
Employed in one phase of the campaign. A phase named here means at least this technique is live in it — not that the form it belongs to is the main effort.
- Phase 0ShapeContinuous terrain preparation, zero-trust hardening, partnerships, threat intelligence.
Controls That Assess It
The controls the catalog names against this technique. They are what an assessor would test to establish that it is emplaced and working — the indicator above is what shows it is working, which is a different question.
- TM-4 Trust Zone DefinitionTerrain Management — To establish boundaries that something enforces, so that reachability and denied-path analysis rest on configuration rather than on design intent.
- TM-5 Connection and Denied-Path RegisterTerrain Management — To record connectivity as three distinct states — permitted, denied, unknown — so that reachability conclusions rest on tested denials rather than on absence of evidence.
In MITRE D3FEND
What this technique is called in MITRE’s countermeasure ontology. The join runs technique-to-technique: D3FEND catalogs countermeasures, and the thing with a countermeasure’s shape here is the technique, not the control.
- D3-APA Access Policy AdministrationIsolate tactic
- D3-NI Network IsolationIsolate tactic
That a technique reaches a D3FEND countermeasure says the two describe the same defensive act. It does not say the countermeasure is deployed, configured, or working — that is an assessment finding about your estate, not a property of the framework.
Related Techniques
The catalog declares no relation for this entry, and no other entry names it — the inverse is derived here, so an incoming edge would show up even though this one never declared it. The techniques below share its assessment surface, which is the nearest adjacency the data supports.
Assessed Alongside
Not a declared relation: these are the techniques whose assessing controls overlap this one’s, ranked by how much of the two assessment surfaces coincide. Showing 6 of 15 that share at least one control.
- 2 shared controlsM2.01 Trust Zone ArchitectureM2 Defense in Depth · T3 Networks
- TM-4
- TM-5
- 1 shared controlM4.01 MicrosegmentationM4 Obstacle / Canalization · T3 Networks
- TM-4
- 1 shared controlM4.02 East-West Deny by DefaultM4 Obstacle / Canalization · T3 Networks
- TM-5
- 1 shared controlM4.03 Egress Filtering and Allow-ListingM4 Obstacle / Canalization · T3 Networks
- TM-5
- 1 shared controlM4.06 Administrative Path RestrictionM4 Obstacle / Canalization · T3 Networks
- TM-5
- 1 shared controlM4.11 Protocol and Port RestrictionM4 Obstacle / Canalization · T3 Networks
- TM-5