MITRE D3FEND
MITRE D3FEND is a knowledge base/graph that catalogs cybersecurity countermeasures and maps them to ATT&CK techniques.
MITRE D3FEND is a compliance framework from International with 8 domains and 8 controls that map to 137 other frameworks. The largest domains are Deceive Tactic - MITRE D3FEND (1 controls), Detect Tactic - MITRE D3FEND (1 controls), Evict Tactic - MITRE D3FEND (1 controls). Every control below carries what it requires and what an assessor expects to see.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (8)
Deceive Tactic - MITRE D3FEND
| Code | Title |
|---|---|
| MITRE-D3FEND-Deceive-Tactic-Decoy-Environment-Decoy-Object-Honeypots-Honey-Tokens-Decoy-Network | MITRE D3FEND Deceive Tactic + Decoy Environment + Decoy Object + Honeypots + Honey Tokens + Decoy Network |
Detect Tactic - MITRE D3FEND
| Code | Title |
|---|---|
| MITRE-D3FEND-Detect-Tactic-File-Process-Network-Identifier-Message-Platform-Analysis-SIEM-EDR | MITRE D3FEND Detect Tactic + File + Process + Network + Identifier + Message + Platform Analysis + SIEM + EDR |
Evict Tactic - MITRE D3FEND
| Code | Title |
|---|---|
| MITRE-D3FEND-Evict-Tactic-Credential-Process-Eviction-Containment-Incident-Response-Recovery | MITRE D3FEND Evict Tactic + Credential + Process Eviction + Containment + Incident Response + Recovery |
Harden Tactic - MITRE D3FEND
| Code | Title |
|---|---|
| MITRE-D3FEND-Harden-Tactic-Application-Credential-Message-Platform-Hardening-MFA-Encryption-Secure-Boot | MITRE D3FEND Harden Tactic + Application + Credential + Message + Platform + MFA + Encryption + Secure Boot |
Integration and Mapping - MITRE D3FEND
| Code | Title |
|---|---|
| MITRE-D3FEND-Integration-Mapping-ATTACK-CWE-CVE-CAPEC-NIST-CSF-CIS-ISO-27001-STIX-OpenC2 | MITRE D3FEND Integration + Mapping + ATT&CK + CWE + CVE + CAPEC + NIST CSF + CIS + ISO 27001 + STIX + OpenC2 |
Isolate Tactic - MITRE D3FEND
| Code | Title |
|---|---|
| MITRE-D3FEND-Isolate-Tactic-Execution-Network-Isolation-Sandboxing-Microsegmentation-DNS-Filtering | MITRE D3FEND Isolate Tactic + Execution + Network Isolation + Sandboxing + Microsegmentation + DNS Filtering |
Model Tactic - MITRE D3FEND
| Code | Title |
|---|---|
| MITRE-D3FEND-Model-Tactic-System-Inventory-Network-Mapping-Identity-Discovery-Asset-Identification | MITRE D3FEND Model Tactic + System Inventory + Network Mapping + Identity Discovery + Asset Identification |
Scope and Foundation - MITRE D3FEND
| Code | Title |
|---|---|
| MITRE-D3FEND-Scope-MITRE-NSA-2021-CC-BY-4-0-Countermeasure-Knowledge-Graph-Companion-ATTACK-Ontology | MITRE D3FEND Scope + MITRE + NSA 2021 + CC BY 4.0 + Countermeasure Knowledge Graph + Companion to ATT&CK + Ontology |
Your Compliance Coverage
If you comply with MITRE D3FEND, you already cover:
OWASP ASVS
75%
6 controls mapped
Compare →ISMAP (Japan)
75%
6 controls mapped
Compare →MITRE ATT&CK
75%
6 controls mapped
Compare →+ 134 more: IACS Unified Requirements E26/E27 - Cyber Resilience of Ships and On-Board Systems (63%), HKMA SPM (50%)
See all 137 mapped frameworks ↓Maps to 137 other frameworks
What is MITRE D3FEND and who does it apply to?
MITRE D3FEND is a compliance framework from International with 8 domains and 8 controls. MITRE D3FEND is a knowledge base/graph that catalogs cybersecurity countermeasures and maps them to ATT&CK techniques. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
What does MITRE D3FEND actually require?
MITRE D3FEND has 8 controls organised across 8 domains. The largest domains are Deceive Tactic - MITRE D3FEND (1 controls), Detect Tactic - MITRE D3FEND (1 controls), Evict Tactic - MITRE D3FEND (1 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
If I already comply with another framework, how much of MITRE D3FEND do I already cover?
MITRE D3FEND maps to 137 other compliance frameworks. The top mapping partners are OWASP ASVS (75% coverage), ISMAP (Japan) (75% coverage), MITRE ATT&CK (75% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I implement MITRE D3FEND?
Start your MITRE D3FEND compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about MITRE D3FEND requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 8 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 686 frameworks.
Get Started Free →Free forever — no credit card required