Frameworks / MITRE D3FEND / MITRE-D3FEND-Harden-Tactic-Application-Credential-Message-Platform-Hardening-MFA-Encryption-Secure-Boot MITRE D3FEND
Harden Tactic - MITRE D3FEND
MITRE D3FEND MITRE-D3FEND-Harden-Tactic-Application-Credential-Message-Platform-Hardening-MFA-Encryption-Secure-Boot: MITRE D3FEND Harden Tactic + Application + Credential + Message + Platform + MFA + Encryption + Secure Boot Apply D3FEND HARDEN tactic to make compromise more difficult prior to attack. D3-AH Application Hardening (D3-DCE Dead Code Elimination + D3-EAL Exception Handler Pointer Validation + D3-PSL Pointer Authentication + D3-SU Software Update + D3-DLIC Driver Load Integrity Checking). D3-CH Credential Hardening (D3-MFA Multi-factor Authentication + D3-SPP Strong Password Policy + D3-CBM Certificate-based Authentication + D3-CRO Credential Rotation + D3-OTPC One-time Password + D3-BAN Biometric Authentication). D3-MH Message Hardening (D3-DKIM DomainKeys Identified Mail + D3-DMARC DMARC + D3-MENCR Message Encryption + D3-TBA Transfer Agent Authentication + D3-SPF Sender Policy Framework). D3-PH Platform Hardening (D3-DENCR Disk Encryption + D3-BCH Bootloader Authentication + D3-RFS RF Shielding + D3-SBP Secure Boot Protocol + D3-LH Local System Hardening + D3-TPM Trusted Platform Module + D3-MV Measurement Verification). Hardening activities include patch management + secure configuration baselines (CIS Benchmarks + DISA STIG + Microsoft Security Baselines + Apple Security Baselines + Linux/CIS) + application sandboxing + memory protection (ASLR + DEP + CFG + CET) + privilege separation + attack surface reduction + cryptographic enforcement.
Maintained by Gerard Blokdyk · Verified against the published standard 31 May 2026 · Control text last updated 21 May 2026 What else in your programme already covers this This control maps to 236 controls across 86 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
AWWA-1.3 Security Awareness and Training AWWA-2.1 User Access Management AWWA-2.2 Authentication Mechanisms AWWA-2.3 Account Management AWWA-2.4 Physical Access Controls AWWA-3.2 Remote Access Security AWWA-3.4 Encryption and Data Protection AWWA-4.1 Malware Protection ASD37-06 Email content filtering (Excellent) ASD37-12 Antivirus software with heuristics (Very Good) ASD37-16 Antivirus software with signatures (Limited) ASD37-17 TLS encryption between email servers (Limited) ASD37-18 Restrict administrative privileges (Essential) ASD37-20 Multi-factor authentication (Essential) ASD37-23 Protect authentication credentials (Excellent) BSI-01 Account management and provisioning BSI-02 Access enforcement and least privilege BSI-03 Multi-factor authentication requirements BSI-04 Remote access controls BSI-05 Wireless access restrictions BSI-08 Cryptographic protection of data BSI-14 Vulnerability scanning and management GhCSA-CII-Designation-Plan-Audit-Risk CII Designation, Registration, Cybersecurity Plan, Audit and Risk Assessment GhCSA-Implementation-Roadmap Implementation Roadmap - Organizational Roles, Tooling and Metrics GhCSA-Incident-Reporting-CERT-GH Cybersecurity Incident Reporting (24-Hour to CSA) and National CERT-GH Engagement GhCSA-Scope-CSAGhana-Defs Scope, Cyber Security Authority (CSA Ghana) and Key Definitions GhCSA-Service-Provider-Licensing-Professional Cybersecurity Service Provider Licensing and Professional Accreditation 27010-10.1 Cryptographic Protection 27010-12.2 Protection from malware 27010-8.1 Membership Onboarding 27010-9.1 Access Control to Shared Information 27010-9.2 Authentication of Sources OWASPTOP10-1 A01:2025 Broken Access Control OWASPTOP10-2 A02:2025 Cryptographic Failures and Secret Management OWASPTOP10-4 A04:2025 Insecure Design and Business Logic (incl. A11 API Abuse) OWASPTOP10-6 A06:2025 Vulnerable and Outdated Components OWASPTOP10-7 A07:2025 Identification and Authentication Failures API1164-06 Access Control API1164-07 Remote Access API1164-09 Patch and Vulnerability Management API1164-12 Incident Response CAT-D3-1 Preventative controls CAT-D3-3 Corrective controls CAT-D4-3 Third-party access controls CAT-IRP-4 Organizational characteristics IACS-UR-E26-Identify-AssetInventory-CBS-NetworkArchitecture-Risk IACS UR E26 Identify Goal - Asset Inventory of Computer Based Systems + Network Architecture Documentation + Risk-Assessable Scope IACS-UR-E26-Protect-AccessControl-Authentication-IAM-Roles IACS UR E26 Protect Goal - Access Control + Identity + Authentication + Authorization + User Management IACS-UR-E26-Protect-RemoteAccess-Wireless-Physical-Boundary IACS UR E26 Protect Goal - Remote Access + Wireless + Physical Security + Boundary Protection IACS-UR-E27-Equipment-UserAuth-Authentication-Authorization IACS UR E27 - Equipment User Authentication + Authorization + Session Management + Privileged Access 23837-1.2 Normative references 23837-1.5.2 Cryptographic module requirements 23837-1.5.3 Network device testing requirements 23837-1.7.3 Authentication and classical post-processing 27011-5.3 Segregation of duties 27011-8.1 User Endpoint Devices 27011-8.3 Cryptography and key management 27011-8.5 Vulnerability and malware management 29115-11 Mapping other authentication schemes 29115-12.1 Exchanging authentication results 29115-12.2 Controls for mitigating threats 29115-7.4 Level of Assurance 4 (LoA4) OWASPAPI-1 Broken Object Level Authorization (BOLA) and BFLA OWASPAPI-2 Broken Authentication and Token Management OWASPAPI-3 Broken Object Property Level Authorization (BOPLA) OWASPAPI-6 Security Misconfiguration and Secure API Design CJIS-10 System and Information Integrity CJIS-8 Media Protection CJIS-9 System and Communications Protection Part11.30 Controls for open systems (21 CFR §11.30) Part11.300 Controls for identification codes and passwords (21 CFR §11.300) Part11.AccessAndAuth Access control + authority + device checks (21 CFR §11.10(d) + (f) + (g) + (h)) FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c)) FTC-Safeguards-IR-Plan-BoardReporting-FTC-Notification Written Incident Response Plan + Board Reporting + FTC Breach Notification (16 CFR 314.4(h), (i), (j)) FTC-Safeguards-ServiceProvider-Evaluation Service Provider Oversight + Program Evaluation + Personnel Training (16 CFR 314.4(d-g)) FedRAMP-Baselines FedRAMP Baseline Selection (Low, Moderate, High, LI-SaaS) and Control Overlay Parameters FedRAMP-Boundary Authorization Boundary, SSP, SAR, POA&M documentation FedRAMP-ConMon Continuous Monitoring (ConMon) and Significant Change Requests 30111-1 Scope 30111-3 Terms and definitions 30111-8.1 Post-release monitoring MDS2-PHI-Data-Handling-DATA-Storage-STCF-Transmission-TXCF-TXIG-Encryption-FIPS MDS2 PHI Handling + DATA + STCF Storage + TXCF Transmission + TXIG Integrity + Encryption + FIPS MDS2-Person-Node-Authentication-Authorization-Auto-Logoff-AUTH-PAUT-NAUT MDS2 Authentication + Authorization + Auto Logoff + PAUT + NAUT + AUTH + Identity Management MDS2-Physical-Security-PLOK-Workstation-Disposal-Backup-DTBK-Disaster-Recovery MDS2 Physical Security + PLOK + Workstation + Disposal + Backup + DTBK + Disaster Recovery APPI-A26 Report of Leakage to the Commission and Notification to the Person APPI-A34 Request for Correction, Addition or Deletion FISMA-CIRCIA-ZTA-EO14028 CIRCIA, Zero Trust Architecture, EO 14028 + 14110 + OMB Memoranda FISMA-NIST-800-53-RMF-800-171-FIPS Operationalisation via NIST 800-53 + 800-37 RMF + 800-171 + FIPS 199 + FIPS 200 UAE-PDPL-Art.4_5 Lawful basis and principles for processing personal data (UAE PDPL Articles 4-5) UAE-PDPL-Art.6_7 Sensitive personal data and children's data (UAE PDPL Articles 6-7) FDBR-Scope-Defs Scope, Applicability Thresholds and Definitions (Fla. Stat. 501.701, 501.702, 501.703, 501.704) FDBR-SensitiveData-Children-VoiceFacial Sensitive Data, Children's Privacy and Voice/Facial Recognition (Fla. Stat. 501.711, 501.1735) HITECH-Coord-HIPAA-Privacy-Security-Cures-ONC HITECH Coordination with HIPAA Privacy Rule + HIPAA Security Rule (Verified Separately) + 21st Century Cures Act + ONC HITECH-SubtitleD-StrengthIndividualRights HITECH Subtitle D - Strengthened Individual Rights (Electronic Access, Accounting of Disclosures, Restrictions, Sale Prohibition) 62351-8 Role-based access control (RBAC) 62351-9 Cyber security key management IEEE1686-Section5.1-AccessControl-Accounts-Roles-Password-Session-Remote IEEE 1686 Section 5.1 - Electronic Access Account Management + Roles + Password + Failed Login + Session + Remote Access + Personnel IEEE1686-Section5.5-5.6-5.7-5.8-Firmware-ConfigSW-TimeSync-DataAtRest IEEE 1686 Section 5.5-5.8 - Firmware Quality + Configuration Software Security + Time Synchronisation + Data Protection at Rest + Patch + Malware + Hardening + Vulnerability 27400-6.1 Secure Device Design 27400-6.2 Device Identity and Authentication 29147-5.6 Advisory Content and Quality 29147-7.8 Remediation information ITAR-Part123-125-ExportLicensing-DSP-5-DSP-73-DSP-61-MLA-TAA-Classified-Information-Routed ITAR Parts 123-125 Export Licensing - DSP-5 Permanent Export + DSP-73 Temporary Export + DSP-61 Temporary Import + DSP-83 + Manufacturing License Agreements (MLA) + Technical Assistance Agreements (TAA) + Classified Information + Routed Export Transactions ITAR-TechnicalData-DefenseServices-DeemedExport-ForeignPerson-Access-USPersons-FOC-AUKUS-Exemptions ITAR Technical Data + Defense Services + Deemed Export Rule + Foreign Person Access + US Persons Only + FOCI Foreign Ownership Control Influence + AUKUS Pillar 2 Exemptions + DD-2345 MCTL BIPA-SEC5-1 Biometric Identifier Definition BIPA-SEC5-2 Biometric Information Definition MY-PDPA-Cross-Border-Transfer-Section-129-Whitelist-Abolition-2024-Adequacy-SCC-BCR-Processor-Direct-Marketing Malaysia PDPA Cross-Border + Section 129 + Whitelist Abolition 2024 + Adequacy + SCC + BCR + Processor + Marketing MY-PDPA-Sensitive-Personal-Data-Section-40-Health-Religious-Political-Sexual-Children-Explicit-Consent Malaysia PDPA Sensitive Personal Data + Section 40 + Health + Religious + Political + Children + Explicit Consent MU-DPA-Governance-DPO-Designation-Section-25-DPO-ROPA-DPIA-Codes-Section-38-Commissioner-Registration Mauritius DPA Governance + DPO + ROPA + DPIA + Codes Section 38 + Commissioner Registration MU-DPA-Sensitive-Personal-Data-Section-24-Health-Biometric-Genetic-Sexual-Section-25-Children-16 Mauritius DPA Sensitive Data + Section 24 + Health + Biometric + Genetic + Sexual + Section 25 + Children 16 MX-LFPDPPP-Governance-Officer-Reglamento-47-50-Security-Manual-57-Risk-Assessment-61-Self-Regulation-Parameters-2014 Mexico LFPDPPP Governance + Officer + Reglamento 47 + Security Manual 50 + Risk Assessment 57 + Self-Regulation Parameters 2014 MX-LFPDPPP-Sensitive-Article-3-VI-Genetic-Health-Sexual-Religious-Article-9-Minors-18-Parental-Consent Mexico LFPDPPP Sensitive Data + Article 3 Section VI + Genetic + Health + Sexual + Religious + Article 9 Minors + Parental Consent MN-CDPA-Chief-Privacy-Officer-Section-325O-06-MN-UNIQUE-Designation-Privacy-Programme-Training Minnesota CDPA Chief Privacy Officer + Section 325O.06 + MINNESOTA-UNIQUE Designation + Privacy Programme + Training MN-CDPA-Universal-Opt-Out-GPC-Sensitive-Data-Section-325O-02-Consumer-Health-Data-Children-Known-Child-Transgender Minnesota CDPA Universal Opt-Out + GPC + Sensitive + Section 325O.02 + Consumer Health Data + Children + Known Child + Transgender AMLCTF-35 Identity Verification Standard CA-ITSG33-SC-01 Security Control Catalogue LOPDP-EC-Security-Processor-Breach-Notification-Articles-37-45-Encryption-72-Hour-SPDP-Notification-CSIRT Ecuador LOPDP Security + Processor + Breach Notification + Articles 37-45 + 72-Hour FERPA-Safeguards-PTAC Data Security Safeguards for PII in Education Records (PTAC Best Practices, SPPO Guidance) GLBA-Subordinate-Rules-Operationalisation GLBA Operationalisation through FTC Safeguards Rule, Privacy Rule, SEC Reg S-P and Banking-Agency Guidelines GLI33-PAM-KYC-AML-Payments GLI-33 Player Account Management, KYC, AML, Payment Processing and Account Lifecycle HKMA-SPM-TM-Technology-TM-G-1-CRAF-Coord HKMA SPM Technology Management Modules (TM-G-1 to TM-G-4, TM-E-1) + Coordination with C-RAF IATA-IOSA-Section8-SEC-SecurityManagement-AVSEC IATA IOSA Section 8 - SEC Security Management + Aviation Security Programme (AVSEC) + ICAO Annex 17 Alignment ICAO-ANX17-Chap2-ThreatAssessment-RiskManagement-Cyber-GASeP ICAO Annex 17 Chapter 2 - Threat Assessment + Risk Management + Cyber Threats to Critical Aviation Systems (Amendment 17/18) IMO-MSC-FAL-Protect-AccessControl-NetworkSegmentation-MalwareDefence-Patch-Awareness-DataSecurity IMO MSC-FAL Protect Function - Access Control + Network Segmentation + Malware Defence + Patch Management + Awareness Training + Data Security + Crew BYOD + Removable Media 29134-9.2 Report findings and recommendations INCDPA-Security-ReasonablePractices-Breach-Notification-Records-Encryption-Pseudonymisation Indiana CDPA Security + Reasonable Practices + Breach Notification + Indiana Breach Notification Law (IC 24-4.9) + Records + Encryption + Pseudonymisation + De-Identification JP-FSA-CYB-Cybersecurity-Exercises-Drills-Annual-Tabletop-Industry-Wide-Exercise-Delta-Wall-FSA-Coordinated-Sector Japan FSA Cybersecurity Exercises + Drills + Annual Tabletop + Industry-Wide Exercise + Delta Wall + FSA Coordinated Sector-Wide + FISC Drills + Cross-Sector Crisis Coordination + International Exercises + Cyber Range LGPD-BR-Security-Article-46-48-Breach-Notification-ANPD-Reasonable-Time-Incident-Response-CSIRT Brazil LGPD Security + Article 46-48 + Breach Notification + ANPD + Incident Response DOM172-Security-Measures-Article-25-Encryption-Pseudonymization-Access-Control-Incident-Handling-Breach-Notification-Article-22 Dominican Republic Law 172-13 Security Measures + Article 25 + Encryption + Breach Notification NISTSP34-3 Preventive Controls and Recovery Strategies: Backup, Alternate Sites, Equipment AUPRV-4 APP 10-11 Quality, Security of Personal Information RUSPD-2 Lawful Basis, Consent, Notice PIPA-Cross-Border-Transfer-Articles-28-8-28-9-Adequacy-Standard-Contract-Certification-EU Korea PIPA Cross-Border Transfer + Articles 28-8 + 28-9 + Adequacy + EU 2021 TEFCAREC-1 Common Agreement Conformance and Onboarding ACE-CR-4 Cargo Release Authorization CPSC-CS.2 Authentication and Access Controls USSDWA-2 Cybersecurity Practices (Assessment, Access, Network, IR) CYB-2 Account Security Measures USMCADIGITAL-2 Personal Information Protection and Consumer Protection VERMONTAICDA-3 Bias Testing, Discrimination Prevention, Transparency Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Query this from an agent The graph holds this control, the 236 it maps to, and the evidence behind each claim, over MCP and REST.