Apply D3FEND ISOLATE tactic to create logical or physical barriers in a system to reduce attack opportunities and impact. D3-EI Execution Isolation (D3-HBPI Hardware-based Process Isolation + D3-SCF System Call Filtering + D3-IBCA IO Channel Authentication + D3-MAC Mandatory Access Control + D3-OSM Operating System Monitor). D3-NI Network Isolation (D3-OTF Outbound Traffic Filtering + D3-DNSDL DNS Denylisting + D3-DNSAL DNS Allowlisting + D3-EHB Email Header Blocking + D3-EI Encrypted Tunnels + D3-FBE Forward Resolution Domain Denylisting + D3-HDDL Hierarchical Domain Denylisting + D3-HDAL Hierarchical Domain Allowlisting + D3-ITF Inbound Traffic Filtering + D3-NTF Network Traffic Filtering + D3-RTA Reverse Resolution IP Denylisting + D3-RTAA Reverse Resolution IP Allowlisting + D3-RDR Routing Rule). Isolation activities include process sandboxing (Bromium + Sandboxie + Microsoft Application Guard) + container security (Docker + Kubernetes Pod Security + gVisor + Kata Containers) + microsegmentation (Illumio + Guardicore + Cisco ACI + VMware NSX) + Zero Trust Network Access (ZTNA) + Secure Service Edge (SSE) + Secure Access Service Edge (SASE) + DNS filtering (Cisco Umbrella + DNSFilter + Quad9 + Cloudflare 1.1.1.1 for Families) + Browser Isolation (Cloudflare + Menlo + Talon + Island.io) + Just-In-Time (JIT) access + Privileged Access Workstation (PAW).
Maintained by Gerard Blokdyk·Verified against the published standard ·Control text last updated
What else in your programme already covers this
This control maps to 29 controls across 18 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.