MITRE D3FEND
Model Tactic - MITRE D3FEND

MITRE D3FEND MITRE-D3FEND-Model-Tactic-System-Inventory-Network-Mapping-Identity-Discovery-Asset-Identification: MITRE D3FEND Model Tactic + System Inventory + Network Mapping + Identity Discovery + Asset Identification

Apply D3FEND MODEL tactic - establishing the digital domain that the defender intends to defend. D3-AM Asset Inventory + D3-NM Network Mapping + D3-ID Identity Discovery + D3-NM-AM Asset Mapping + D3-SI System Inventory + D3-UA User Account Inventory + D3-SWI Software Inventory + D3-DFR Data Flow Reconnaissance + D3-CSCM Cybersecurity Cartography. Model tactic provides the foundation for all subsequent defensive operations by establishing comprehensive visibility of what exists in the digital environment. Activities include: enumerating systems + cataloguing accounts + mapping network topology + identifying data flows + documenting identities + recording configurations + maintaining software bill of materials (SBOM) + understanding business processes + mapping privilege relationships. Integration with Configuration Management Database (CMDB) + IT Asset Management (ITAM) + Cybersecurity Asset Attack Surface Management (CAASM) tools (Axonius + JupiterOne + Sevco + Lansweeper + Tanium). Identity Discovery via Active Directory + Azure AD/Entra ID + LDAP + Identity Providers + SCIM. Network mapping via passive flow monitoring + active probing + topology discovery. Data flow reconnaissance via DLP discovery + database scanning + sensitivity classification.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 24 controls across 17 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • CFR211-G-122 Section 211.122 - Materials Examination and Usage Criteria
  • CFR211-G-125 Section 211.125 - Labeling Issuance
  • CFR211-G-130 Section 211.130 - Packaging and Labeling Operations
  • CPG-2.A Asset Inventory
  • CPG-2.B Prohibit Connection of Unauthorized Devices

ISO/IEC 27010:2015 · 2 controls

  • 27010-8.1 Membership Onboarding
  • 27010-8.2 Membership Termination

MITRE ATT&CK · 2 controls

API 1164 · 1 control

  • API1164-02 Risk Management Framework

BSI IT-Grundschutz · 1 control

  • BSI-15 Security categorization
  • QMSR-820.45 Device labelling and packaging controls (§820.45)

FISMA · 1 control

  • FISMA-NIST-800-53-RMF-800-171-FIPS Operationalisation via NIST 800-53 + 800-37 RMF + 800-171 + FIPS 199 + FIPS 200
  • GhCSA-Implementation-Roadmap Implementation Roadmap - Organizational Roles, Tooling and Metrics
  • IACS-UR-E26-Identify-AssetInventory-CBS-NetworkArchitecture-Risk IACS UR E26 Identify Goal - Asset Inventory of Computer Based Systems + Network Architecture Documentation + Risk-Assessable Scope
  • 60601-1.7.1 Equipment identification and marking

IEEE 1686 · 1 control

  • IEEE1686-Scope-IED-Substation-Automation-2022-IEC-NERC-NIST-Coord IEEE 1686 - Scope + Intelligent Electronic Devices (IEDs) + Substation Automation + 2022 Edition + Coordination with IEC 62351 + IEC 62443 + NERC CIP + NIST SP 800-82

IEEE 7000 · 1 control

  • IEEE7000-EthicalRisk-Identification-Analysis-Treatment-ValidationOutcomes IEEE 7000 Clauses 8 + 8.1 + 8.2 - Ethical Risk Identification + Analysis + Treatment + Validation of Ethical Outcomes + AI Safety + Robustness + Adversarial Protection

ISMAP (Japan) · 1 control

Japan AI Guidelines · 1 control

  • JP-AIG-Risk-Based-AI-System-Categorisation-Tiered-Approach-EU-AI-Act-Aligned-Generative-Foundation-Models Japan AI Guidelines Risk-Based AI System Categorisation + Tiered Approach + EU AI Act Aligned + Generative AI + Foundation Models + High-Risk + Limited-Risk + Minimal-Risk + AISI Capability-Based Thresholds

OWASP ASVS · 1 control

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 24 it maps to, and the evidence behind each claim, over MCP and REST.