Compliance Node Overview
MITRE D3FEND D3-CDP (Change Default Password) is a Harden defensive technique. Changing the default password means replacing the factory-set credentials with a strong, unique password before the device is deployed, preventing unauthorized access. Change the default password as soon as a new device is received. The default credentials are normally documented in an instruction manual that is either packaged with the device, published online through official means, or published online through unofficial means. In the D3FEND model it hardens the ot controller; strengthens the password; strengthens the user account. It counters ATT&CK techniques T1078, T1078.001, T1078.002, T1078.003, T1078.004, T1087.001, T1087.002, T1087.004, T1098, T1098.002, and 10 more. Via the Center for Threat-Informed Defense mapping of the countered techniques, it supports NIST SP 800-53 Rev 5 controls AC-02, AC-03, AC-04, AC-05, AC-06, AC-07, AC-16, AC-20.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://d3fend.mitre.org/technique/d3f:ChangeDefaultPassword/
SHA-256 integrity: 0361c26a768fb821a5814292dd903a3b2fe35ba8ddc9e6550da177a85ddfcc9f
Primary Citations — 7 traced to source
- MITRE D3FEND Defensive Technique D3-CDP: Change Default Password (https://d3fend.mitre.org/technique/d3f:ChangeDefaultPassword/)
- MITRE D3FEND Harden Tactic (https://d3fend.mitre.org/tactic/d3f:Harden/)
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access