MITRE D3FEND
Isolate Tactic - MITRE D3FEND

MITRE D3FEND MITRE-D3FEND-Isolate-Tactic-Execution-Network-Isolation-Sandboxing-Microsegmentation-DNS-Filtering: MITRE D3FEND Isolate Tactic + Execution + Network Isolation + Sandboxing + Microsegmentation + DNS Filtering

Apply D3FEND ISOLATE tactic to create logical or physical barriers in a system to reduce attack opportunities and impact. D3-EI Execution Isolation (D3-HBPI Hardware-based Process Isolation + D3-SCF System Call Filtering + D3-IBCA IO Channel Authentication + D3-MAC Mandatory Access Control + D3-OSM Operating System Monitor). D3-NI Network Isolation (D3-OTF Outbound Traffic Filtering + D3-DNSDL DNS Denylisting + D3-DNSAL DNS Allowlisting + D3-EHB Email Header Blocking + D3-EI Encrypted Tunnels + D3-FBE Forward Resolution Domain Denylisting + D3-HDDL Hierarchical Domain Denylisting + D3-HDAL Hierarchical Domain Allowlisting + D3-ITF Inbound Traffic Filtering + D3-NTF Network Traffic Filtering + D3-RTA Reverse Resolution IP Denylisting + D3-RTAA Reverse Resolution IP Allowlisting + D3-RDR Routing Rule). Isolation activities include process sandboxing (Bromium + Sandboxie + Microsoft Application Guard) + container security (Docker + Kubernetes Pod Security + gVisor + Kata Containers) + microsegmentation (Illumio + Guardicore + Cisco ACI + VMware NSX) + Zero Trust Network Access (ZTNA) + Secure Service Edge (SSE) + Secure Access Service Edge (SASE) + DNS filtering (Cisco Umbrella + DNSFilter + Quad9 + Cloudflare 1.1.1.1 for Families) + Browser Isolation (Cloudflare + Menlo + Talon + Island.io) + Just-In-Time (JIT) access + Privileged Access Workstation (PAW).

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 29 controls across 18 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • ASD37-20 Multi-factor authentication (Essential)
  • ASD37-22 Network segmentation (Excellent)
  • ASD37-25 Software firewall - inbound (Very Good)
  • CPG-1.D Revoking Credentials for Departing Employees
  • CPG-8.A Network Segmentation

ISO/IEC 27011:2024 · 2 controls

  • 27011-6.3 Awareness and Training
  • 27011-8.2 Network security and segregation

API 1164 · 1 control

  • API1164-13 Business Continuity and Recovery
  • CAT-D3-1 Preventative controls

GLBA · 1 control

  • GLBA-Subordinate-Rules-Operationalisation GLBA Operationalisation through FTC Safeguards Rule, Privacy Rule, SEC Reg S-P and Banking-Agency Guidelines

HKMA SPM · 1 control

  • HKMA-SPM-TM-Technology-TM-G-1-CRAF-Coord HKMA SPM Technology Management Modules (TM-G-1 to TM-G-4, TM-E-1) + Coordination with C-RAF
  • IACS-UR-E26-Protect-NetworkSegmentation-Zones-Conduits-Boundary IACS UR E26 Protect Goal - Network Segmentation + Zones + Conduits + Boundary Defence + Data Diodes

IEEE 1686 · 1 control

  • IEEE1686-Section5.2-5.3-AuditLog-Retention-Export-Monitoring IEEE 1686 Section 5.2 + 5.3 - Audit Trail Records + Retention + Export + Supervisory Monitoring and Control + Network Security Monitoring

ISMAP (Japan) · 1 control

ISO/IEC 27010:2015 · 1 control

  • 27010-13.1 Communications Security
  • LAOS-CC-Network-Security-Information-Security-Obligations-Article-21-Service-Provider-Duties Laos Cybercrime Network Security + Information Security Obligations + Article 21 + Service Provider Duties

MITRE ATT&CK · 1 control

OWASP ASVS · 1 control

  • CPSC-CS.1 Network Security for Connected Products
  • USSDWA-2 Cybersecurity Practices (Assessment, Access, Network, IR)

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 29 it maps to, and the evidence behind each claim, over MCP and REST.