---
title: "D3FEND, MITRE D3FEND | MedTech Terms"
description: "MITRE's knowledge graph of defensive cybersecurity countermeasures, explicitly mapped to the ATT&amp;CK techniques they mitigate."
lang: en
json-ld: |
  {
    "@context": "https://schema.org",
    "@graph": [
      {
        "@type": "DefinedTerm",
        "@id": "https://medtechterms.com/terms/mitre-d3fend#term",
        "name": "MITRE D3FEND",
        "alternateName": "D3FEND",
        "description": "D3FEND is a knowledge graph and matrix of defensive countermeasures developed by MITRE under NSA funding. Where ATT&CK catalogs what attackers do, D3FEND catalogs what defenders can do, organized by tactic (Harden, Detect, Isolate, Deceive, Evict, Restore) and broken into specific defensive techniques with clear ontological relationships to the digital artifacts they affect. Each D3FEND technique is explicitly mapped to the ATT&CK techniques it counters, giving security teams an evidence-based bridge from threat to control.",
        "url": "https://medtechterms.com/terms/mitre-d3fend",
        "termCode": "mitre-d3fend",
        "inDefinedTermSet": {
          "@type": "DefinedTermSet",
          "name": "MedTech Terms",
          "url": "https://medtechterms.com/terms"
        }
      },
      {
        "@type": "Article",
        "@id": "https://medtechterms.com/terms/mitre-d3fend#article",
        "headline": "D3FEND, MITRE D3FEND",
        "description": "MITRE's knowledge graph of defensive cybersecurity countermeasures, explicitly mapped to the ATT&CK techniques they mitigate.",
        "url": "https://medtechterms.com/terms/mitre-d3fend",
        "mainEntityOfPage": {
          "@type": "WebPage",
          "@id": "https://medtechterms.com/terms/mitre-d3fend"
        },
        "about": {
          "@id": "https://medtechterms.com/terms/mitre-d3fend#term"
        },
        "articleSection": "Cybersecurity",
        "inLanguage": "en",
        "keywords": "MITRE D3FEND, D3FEND, Cybersecurity, medical device, MedTech",
        "author": {
          "@type": "Person",
          "name": "Christian Espinosa",
          "jobTitle": "Founder, Blue Goat Cyber",
          "url": "https://bluegoatcyber.com"
        },
        "publisher": {
          "@type": "Organization",
          "name": "MedTech Terms",
          "url": "https://medtechterms.com"
        },
        "isPartOf": {
          "@type": "WebSite",
          "name": "MedTech Terms",
          "url": "https://medtechterms.com"
        },
        "datePublished": "2026-06-20",
        "dateModified": "2026-06-20",
        "citation": [
          {
            "@type": "CreativeWork",
            "name": "MITRE D3FEND",
            "url": "https://d3fend.mitre.org/",
            "publisher": {
              "@type": "Organization",
              "name": "MITRE"
            }
          },
          {
            "@type": "CreativeWork",
            "name": "D3FEND ATT&CK mappings",
            "url": "https://d3fend.mitre.org/resources/",
            "publisher": {
              "@type": "Organization",
              "name": "MITRE"
            }
          },
          {
            "@type": "CreativeWork",
            "name": "HSCC - Health Sector Coordinating Council",
            "url": "https://healthsectorcouncil.org/",
            "publisher": {
              "@type": "Organization",
              "name": "HSCC"
            }
          }
        ],
        "mentions": [
          {
            "@type": "DefinedTerm",
            "@id": "https://medtechterms.com/terms/mitre-attack#term",
            "name": "MITRE ATT&CK",
            "alternateName": "ATT&CK",
            "url": "https://medtechterms.com/terms/mitre-attack"
          },
          {
            "@type": "DefinedTerm",
            "@id": "https://medtechterms.com/terms/threat-modeling#term",
            "name": "Threat Modeling",
            "url": "https://medtechterms.com/terms/threat-modeling"
          },
          {
            "@type": "DefinedTerm",
            "@id": "https://medtechterms.com/terms/iec-81001-5-1#term",
            "name": "IEC 81001-5-1",
            "url": "https://medtechterms.com/terms/iec-81001-5-1"
          },
          {
            "@type": "DefinedTerm",
            "@id": "https://medtechterms.com/terms/nist-csf#term",
            "name": "NIST Cybersecurity Framework",
            "alternateName": "NIST CSF",
            "url": "https://medtechterms.com/terms/nist-csf"
          }
        ]
      },
      {
        "@type": "BreadcrumbList",
        "itemListElement": [
          {
            "@type": "ListItem",
            "position": 1,
            "name": "Home",
            "item": "https://medtechterms.com/"
          },
          {
            "@type": "ListItem",
            "position": 2,
            "name": "Terms",
            "item": "https://medtechterms.com/terms"
          },
          {
            "@type": "ListItem",
            "position": 3,
            "name": "Cybersecurity",
            "item": "https://medtechterms.com/terms?cat=Cybersecurity"
          },
          {
            "@type": "ListItem",
            "position": 4,
            "name": "MITRE D3FEND",
            "item": "https://medtechterms.com/terms/mitre-d3fend"
          }
        ]
      }
    ]
  }
---

[

MedTech Terms

The authoritative reference



](/)

Browse

Learn

[Latest](/latest)

About

1.  [Home](/)
2.  /
3.  [Terms](/terms)
4.  /
5.  [Cybersecurity](/terms?cat=Cybersecurity)
6.  /
7.  MITRE D3FEND

[All terms](/terms)

Cybersecurity [Connected & Cyber-Physical Devices](/ecosystems/connected-devices)D3FEND 

# MITRE D3FEND

MITRE's knowledge graph of defensive cybersecurity countermeasures, explicitly mapped to the ATT&CK techniques they mitigate.

Reviewed by [Christian Espinosa, Founder, Blue Goat Cyber](/authors/christian-espinosa) Last reviewed June 20, 2026 

## Definition

D3FEND is a knowledge graph and matrix of defensive countermeasures developed by MITRE under NSA funding. Where  [ATT&CK](/terms/mitre-attack) catalogs what attackers do, D3FEND catalogs what defenders can do, organized by tactic (Harden, Detect, Isolate, Deceive, Evict, Restore) and broken into specific defensive techniques with clear ontological relationships to the digital artifacts they affect. Each D3FEND technique is explicitly mapped to the ATT&CK techniques it counters, giving security teams an evidence-based bridge from threat to control. 

What the regulation says

Not directly cited by FDA, but referenced in the HSCC Medical Device and Health IT Joint Security Plan and increasingly used by notified bodies reviewing EU  [MDR](/terms/mdr-reporting) Annex I cyber requirements to evidence that selected controls actually counter identified threats. 

## What this means in practice

For MedTech, D3FEND lets you justify a control library against the threats in your threat model. If your model identifies T1190 (Exploit Public-Facing Application) as a credible threat, D3FEND points you to specific defensive techniques (Application Hardening, Network Traffic Filtering, Process Spawn Analysis) and connects each to measurable design elements that can appear in your security architecture,  [IEC 81001-5-1](/terms/iec-81001-5-1) conformance evidence, or  [premarket cybersecurity submission](/terms/premarket-cybersecurity). 

Common pitfalls

-   • Treating D3FEND as a control catalog and ignoring its ontology, the value is in the typed relationships between artifact, technique, and digital effect. 
-   • Mapping controls to D3FEND in isolation without first mapping threats to ATT&CK, the bridge breaks both ways. 
-   • Expecting 1:1 coverage, many ATT&CK techniques have multiple D3FEND counters, and some have none. 

## Related terms

Grouped by theme 

### Editor's picks

· Hand-selected related concepts 

[

Cybersecurity

IEC 81001-5-1

International standard defining secure-product-lifecycle activities for health software, including medical devices.





](/terms/iec-81001-5-1)[

Cybersecurity

MITRE ATT&CK(ATT&CK) 

Knowledge base of real-world adversary tactics, techniques, and procedures organized into a matrix used to model threats and assess defenses.





](/terms/mitre-attack)[

Cybersecurity

NIST Cybersecurity Framework(NIST CSF) 

A risk-based framework of cybersecurity functions and outcomes published by NIST and widely used to organize MedTech security programs.





](/terms/nist-csf)[

Cybersecurity

Threat Modeling

A structured analysis that identifies how an attacker could compromise a medical device and what controls mitigate each threat.





](/terms/threat-modeling)

### More in Cybersecurity

· Same category 

[

Cybersecurity

AAMI SW96

AAMI/ANSI standard establishing requirements for medical-device cybersecurity activities throughout the lifecycle.





](/terms/aami-sw96)[

Cybersecurity

AAMI TIR57

AAMI Technical Information Report providing MedTech-specific guidance on cybersecurity risk management.





](/terms/aami-tir57)[

Cybersecurity

AAMI TIR97(TIR97) 

AAMI Technical Information Report on post-market security risk management for medical device manufacturers, the operational companion to TIR57.





](/terms/aami-tir97)[

Cybersecurity

Brainjacking

Unauthorized remote control of an implanted neurostimulator (e.g., DBS) to alter stimulation parameters and harm a patient.





](/terms/brainjacking)

Cited by

Where this term appears across MedTech Terms.

Ecosystems (1)

-   [Connected & Cyber-Physical Devices](/ecosystems/connected-devices)

## Primary references

3 sources 

Link health:  3 verified · last checked 2026-06-20 

MITRE· 2 HSCC· 1 

1.  [1 
    
    MITRE D3FEND
    
    Verified 
    
    MITRE · d3fend.mitre.org 
    
    
    
    ](https://d3fend.mitre.org/)
2.  [2 
    
    D3FEND ATT&CK mappings
    
    Verified 
    
    MITRE · d3fend.mitre.org 
    
    
    
    ](https://d3fend.mitre.org/resources/)
3.  [3 
    
    HSCC - Health Sector Coordinating Council
    
    Verified 
    
    HSCC · healthsectorcouncil.org 
    
    
    
    ](https://healthsectorcouncil.org/)

Inline markers like \[1\]  jump to the matching reference above.

Sponsor note

### Working on medical device cybersecurity?

Blue Goat Cyber specializes in MedTech cybersecurity - threat modeling, SBOMs, penetration testing, and FDA premarket submissions.

[Book a 30-minute discovery session](https://go.bluegoatcyber.com/meetings/blue-goat-cyber/discovery-session)

-   No obligation
-   Expert-led from minute one
-   NDA available on request

MedTech Terms is a community resource sponsored by [Blue Goat Cyber](https://bluegoatcyber.com). Definitions are independent of any vendor.

On this term

Category

Cybersecurity

Acronym

D3FEND

Sources

3

Updated

6/20/2026

[Compare with another term](/compare?a=mitre-d3fend)

Learn in 60 seconds

Card Lesson Quiz

MITRE's knowledge graph of defensive cybersecurity countermeasures, explicitly mapped to the ATT&CK techniques they mitigate.

-   · For MedTech, D3FEND lets you justify a control library against the threats in your threat model. 
-   · Each D3FEND technique is explicitly mapped to the ATT&CK techniques it counters, giving security teams an evidence-based bridge from threat to control. 

Remember this

Watch out: Treating D3FEND as a control catalog and ignoring its ontology, the value is in the typed relationships between artifact, technique, and digital effect.

Related terms

-   [MITRE ATT&CK(ATT&CK) ](/terms/mitre-attack)
-   [Threat Modeling ](/terms/threat-modeling)
-   [IEC 81001-5-1 ](/terms/iec-81001-5-1)
-   [NIST Cybersecurity Framework(NIST CSF) ](/terms/nist-csf)

You may also need

Auto-suggested from Cybersecurity and shared keywords.

-   [NIST IR 8473, Cybersecurity Framework Profile for HPH(NIST IR 8473) ](/terms/nist-cswp-35)
-   [Premarket Cybersecurity Submission ](/terms/premarket-cybersecurity)
-   [STRIDE Threat Model(STRIDE) ](/terms/stride)
-   [Common Vulnerabilities and Exposures(CVE) ](/terms/cve)
-   [Secure Product Development Framework(SPDF) ](/terms/spdf)
-   [CISA Known Exploited Vulnerabilities Catalog(KEV) ](/terms/kev)

[All Cybersecurity terms](/terms?cat=Cybersecurity)

From the Blue Goat network

Related resources and services on this topic.

-   [
    
    MedTech Cybersecurity Standards 
    
    Authoritative reference for the standards and guidances behind medical device cybersecurity.
    
    ](https://medtechcyberstandards.com)
-   [
    
    MedTech Cyber Tips 
    
    Practical, organized tips for medical device cybersecurity teams.
    
    ](https://medtechcybertips.com)
-   [
    
    MedTech Cybersecurity Crosswalk 
    
    International crosswalk of medical device cybersecurity requirements across regulators.
    
    ](https://mdccrosswalk.com)
-   [
    
    Code Blue 
    
    Real medical device cybersecurity incidents and their lessons.
    
    ](https://codebluechart.com)

MedTech Terms 

An authoritative, plain-language reference for the regulatory, quality, cybersecurity, and software terms that shape modern medical devices.

Browse

-   [All terms](/terms)
-   [A–Z index](/a-z)
-   [Categories](/categories)
-   [Ecosystems](/ecosystems)
-   [Learning paths](/paths)
-   [Compare terms](/compare)
-   [Quiz](/quiz)

Resources

-   [FDA Medical Devices](https://www.fda.gov/medical-devices)
-   [EU MDR](https://eur-lex.europa.eu/eli/reg/2017/745/oj)
-   [IMDRF](https://www.imdrf.org/)
-   [Methodology](/methodology)
-   [Changelog](/changelog)
-   [Editor: Christian Espinosa](/authors/christian-espinosa)
-   [About this site](/about)

© 2026 MedTech Terms. Reference content for educational purposes - not regulatory advice. A community resource sponsored by [Blue Goat Cyber](https://bluegoatcyber.com)