Apply D3FEND HARDEN tactic to make compromise more difficult prior to attack. D3-AH Application Hardening (D3-DCE Dead Code Elimination + D3-EAL Exception Handler Pointer Validation + D3-PSL Pointer Authentication + D3-SU Software Update + D3-DLIC Driver Load Integrity Checking). D3-CH Credential Hardening (D3-MFA Multi-factor Authentication + D3-SPP Strong Password Policy + D3-CBM Certificate-based Authentication + D3-CRO Credential Rotation + D3-OTPC One-time Password + D3-BAN Biometric Authentication). D3-MH Message Hardening (D3-DKIM DomainKeys Identified Mail + D3-DMARC DMARC + D3-MENCR Message Encryption + D3-TBA Transfer Agent Authentication + D3-SPF Sender Policy Framework). D3-PH Platform Hardening (D3-DENCR Disk Encryption + D3-BCH Bootloader Authentication + D3-RFS RF Shielding + D3-SBP Secure Boot Protocol + D3-LH Local System Hardening + D3-TPM Trusted Platform Module + D3-MV Measurement Verification). Hardening activities include patch management + secure configuration baselines (CIS Benchmarks + DISA STIG + Microsoft Security Baselines + Apple Security Baselines + Linux/CIS) + application sandboxing + memory protection (ASLR + DEP + CFG + CET) + privilege separation + attack surface reduction + cryptographic enforcement.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.