TIER 3 · DEFENSIVE COUNTERMEASURE ONTOLOGY

MITRE D3FEND to AITBM Mapping

Uses defensive countermeasures to organize evidence routes while AITBM tests determine the actual score.

How to use this crosswalk

External requirements, controls, threats, and practices identify evidence to collect or tests to run. Only measured evidence from the assessed deployment determines AITBM rubric placements, IVP, ORP, ACI, MVT findings, and ERS.

Mapping content last verified 2026-08-13. No endorsement by the external framework owner is implied.

MITRE D3FEND

Defensive countermeasure ontology

MITRE D3FEND (Detection, Denial, and Disruption Framework Empowering Network Defense) · The MITRE Corporation

D3FEND supplies a seven-tactic ontology of general defensive countermeasures. Ontology 1.5.0 is the current release; this AITBM-authored crosswalk remains explicitly pinned to D3FEND 1.0 and routes measured implementation evidence from that declared basis and the independent, AI-specialized AIDEFEND catalogue, while counting overlapping evidence only once.

D3FEND Tactic Primary AITBM Sub-Metrics Evidence Use / Notes
Model (Asset Inventory, System Mapping)Tr-4Cn-1Inventory and topology evidence may support Tr-4, Cn-1, ACI provenance, and the SDG; no automatic score
Harden (Message/App Hardening, Agent Authentication)Ro-1Cn-3Cn-5Cn-4Ro-4Measured hardening effectiveness may support the listed rubrics; no fixed anchor or ERS change
Detect (Process/User Behavior Analysis, Monitoring)Tr-3Ro-3Cn-1Cn-2Telemetry may support Tr-3 and monitoring/freshness evidence when coverage and health rules are met
Isolate (Execution Isolation, Network Isolation)Cn-1Cn-4Isolation evidence informs Cn-1/Cn-4, As, and SDG reachability; Cp remains graph-derived
Deceive (Decoy Environment, Decoy Object)Tr-3Cn-2Decoy evidence may support detection, audit, and remediation testing; no fixed ERS change
Evict (Process/Credential Eviction)Cn-2Measured eviction and quarantine performance may inform Cn-2 and Rf
Restore (Restore Object/rollback, Restore Access)ORP RfMeasured rollback and recovery evidence may inform Rf; no fixed ERS change
Harden :: Agent Authentication (1.x) [standout]Cn-5ISSR and attestation-coverage evidence may support Cn-5; no automatic anchor

Key findings

  • A D3FEND countermeasure is an implementable control, not a score. Measured implementation evidence may support an AITBM rubric; no fixed anchor or ERS reduction is inherent to the control.
  • D3FEND (general cyber defense) and AIDEFEND (AI-specialized, modeled on D3FEND's same seven tactics) are concentric, not redundant; a D3FEND control and its AIDEFEND twin targeting the same sub-metric are scored once, never double-counted.
  • Harden and Isolate carry the most IVP-moving weight (especially Agent Authentication -> Cn-5), while Detect/Deceive/Evict/Restore act largely through the ORP layer (Rf, As, Cp) and by sustaining ACI freshness.
  • The D3FEND worked example is retained on its dated 21-sub-metric, pre-GDCP basis. A current assessment must derive Cn-6, Cp, ACI, and ERS under the current specification.

MITRE D3FEND reference →