MITRE D3FEND
MITRE's knowledge graph of defensive cybersecurity countermeasures, explicitly mapped to the ATT&CK techniques they mitigate.
Definition
D3FEND is a knowledge graph and matrix of defensive countermeasures developed by MITRE under NSA funding. Where ATT&CK catalogs what attackers do, D3FEND catalogs what defenders can do, organized by tactic (Harden, Detect, Isolate, Deceive, Evict, Restore) and broken into specific defensive techniques with clear ontological relationships to the digital artifacts they affect. Each D3FEND technique is explicitly mapped to the ATT&CK techniques it counters, giving security teams an evidence-based bridge from threat to control.What this means in practice
For MedTech, D3FEND lets you justify a control library against the threats in your threat model. If your model identifies T1190 (Exploit Public-Facing Application) as a credible threat, D3FEND points you to specific defensive techniques (Application Hardening, Network Traffic Filtering, Process Spawn Analysis) and connects each to measurable design elements that can appear in your security architecture, IEC 81001-5-1 conformance evidence, or premarket cybersecurity submission.- •Treating D3FEND as a control catalog and ignoring its ontology, the value is in the typed relationships between artifact, technique, and digital effect.
- •Mapping controls to D3FEND in isolation without first mapping threats to ATT&CK, the bridge breaks both ways.
- •Expecting 1:1 coverage, many ATT&CK techniques have multiple D3FEND counters, and some have none.
Related terms
Grouped by themeEditor's picks
· Hand-selected related conceptsInternational standard defining secure-product-lifecycle activities for health software, including medical devices.
Knowledge base of real-world adversary tactics, techniques, and procedures organized into a matrix used to model threats and assess defenses.
A risk-based framework of cybersecurity functions and outcomes published by NIST and widely used to organize MedTech security programs.
A structured analysis that identifies how an attacker could compromise a medical device and what controls mitigate each threat.
More in Cybersecurity
· Same categoryAAMI/ANSI standard establishing requirements for medical-device cybersecurity activities throughout the lifecycle.
AAMI Technical Information Report providing MedTech-specific guidance on cybersecurity risk management.
AAMI Technical Information Report on post-market security risk management for medical device manufacturers, the operational companion to TIR57.
Unauthorized remote control of an implanted neurostimulator (e.g., DBS) to alter stimulation parameters and harm a patient.
Primary references
3 sources- 1
MITRE D3FENDVerifiedMITREd3fend.mitre.org
- 2
D3FEND ATT&CK mappingsVerifiedMITREd3fend.mitre.org
- 3
HSCC - Health Sector Coordinating CouncilVerifiedHSCChealthsectorcouncil.org
Inline markers like [1] jump to the matching reference above.