Access Modeling
Access modeling captures and records the access permissions granted to identities (e.g., administrators, users, groups, systems) and optionally includes details on how these identities are stored, managed, and shared across systems.
MITRE D3FEND™ Learning Center
The model tactic is used to apply security engineering, vulnerability, threat, and risk analyses to digital systems. This is accomplished by creating and maintaining a common understanding of the systems being defended, the operations on those systems, actors using the systems, and the relationships and interactions between these elements.
Top-level technique families
These techniques sit directly beneath the Defensive Technique root and organize the more specific techniques in this tactic.
Asset inventorying identifies and records the organization's assets and enriches each inventory item with knowledge about their vulnerabilities.
6 direct child techniques →D3-NMNetwork mapping encompasses the techniques to identify and model the physical layer, network layer, and data exchange layers of the organization's network and their physical location, and determine allowed pathways through that network.
4 direct child techniques →D3-OAMOperational activity mapping identifies activities of the organization and the organization's suborganizations, groups, roles, and individuals that carry out the activities and then establishes the dependencies of the activities on the systems and people that perform those activities.
4 direct child techniques →D3-SYSMSystem mapping encompasses the techniques to identify the organization's systems, how they are configured and decomposed into subsystems and components, how they are dependent on one another, and where they are physically located.
4 direct child techniques →Complete tactic directory
Access modeling captures and records the access permissions granted to identities (e.g., administrators, users, groups, systems) and optionally includes details on how these identities are stored, managed, and shared across systems.
Active logical link mapping sends and receives network traffic as a means to map the whole data link layer, where the links represent logical data flows rather than physical connection
Active physical link mapping sends and receives network traffic as a means to map the physical layer.
Asset inventorying identifies and records the organization's assets and enriches each inventory item with knowledge about their vulnerabilities.
Asset vulnerability enumeration enriches inventory items with knowledge identifying their vulnerabilities.
Configuration inventory identifies and records the configuration of software and hardware and their components throughout the organization.
Analyzing a Container Image with respect to a set of policies.
Data exchange mapping identifies and models the organization's intended design for the flows of the data types, formats, and volumes between systems at the application layer.
Data inventorying identifies and records the schemas, formats, volumes, and locations of data stored and used on the organization's architecture.
Direct physical link mapping creates a physical link map by direct observation and recording of the physical network links.
Hardware component inventorying identifies and records the hardware items in the organization's architecture.
Logical link mapping creates a model of existing or previous node-to-node connections using network-layer data or metadata.
Network mapping encompasses the techniques to identify and model the physical layer, network layer, and data exchange layers of the organization's network and their physical location, and determine allowed pathways through that network.
Network node inventorying identifies and records all the network nodes (hosts, routers, switches, firewalls, etc.) in the organization's architecture.
Network traffic policy mapping identifies and models the allowed pathways of data at the network, transport, and/or application levels.
Network vulnerability assessment relates all the vulnerabilities of a network's components in the context of their configuration and interdependencies and can also include assessing risk emerging from the network's design as a whole, not just the sum of individual network node or network segment vulnerabilities.
Operational activity mapping identifies activities of the organization and the organization's suborganizations, groups, roles, and individuals that carry out the activities and then establishes the dependencies of the activities on the systems and people that perform those activities.
Operational dependency mapping identifies and models the dependencies of the organization's activities on each other and on the organization's performers (people, systems, and services.) This may include modeling the higher- and lower-level activities of an organization forming a hierarchy, or layering, of the dependencies in an organization's activities.
Operational risk assessment identifies and models the vulnerabilities of, and risks to, an organization's activities individually and as a whole.
Organization mapping identifies and models the people, roles, and groups with an organization and the relations between them.
Passive logical link mapping only listens to network traffic as a means to map the whole data link layer, where the links represent logical data flows rather than physical connections.
Physical link mapping identifies and models the link connectivity of the network devices within a physical network.
Service dependency mapping determines the services on which each given service relies.
Software inventorying identifies and records the software items in the organization's architecture.
System dependency mapping identifies and models the dependencies of system components on each other to carry out their function.
System mapping encompasses the techniques to identify the organization's systems, how they are configured and decomposed into subsystems and components, how they are dependent on one another, and where they are physically located.
System vulnerability assessment relates all the vulnerabilities of a system's components in the context of their configuration and internal dependencies and can also include assessing risk emerging from the system's design as a whole, not just the sum of individual component vulnerabilities.
Try a shorter term or clear the filters.