What MITRE D3FEND D3-CERO: Certificate Rotation (Defensive Tactic - Harden -> Certificate Rotation) requires
MITRE D3FEND D3-CERO (Certificate Rotation) is a Harden defensive technique. Certificate rotation involves replacing digital certificates and their private keys to maintain cryptographic integrity and trust, mitigating key compromise risks and ensuring continuous secure communications. Certificate rotation should be performed when: - Any certificate expires. - A new CA authority is substituted for the old, thus requiring a replacement root certificate. - New or modified constraints need to be imposed on one or more certificates. - A security breach has occurred. Considerations: - Managing certificate rotation across an enterprise can be complex. In the D3FEND model it regenerates the certificate. It counters ATT&CK technique T1649. Via the Center for Threat-Informed Defense mapping of the countered techniques, it supports NIST SP 800-53 Rev 5 controls IA-02, IA-05, IA-13.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://d3fend.mitre.org/technique/d3f:CertificateRotation/
SHA-256 integrity: a408546cfbd15b9c39a1a9b001193aa0b9b670ce0ae02e2f6605e0489586e039
Primary Citations — 7 traced to source
- MITRE D3FEND Defensive Technique D3-CERO: Certificate Rotation (https://d3fend.mitre.org/technique/d3f:CertificateRotation/)
- MITRE D3FEND Harden Tactic (https://d3fend.mitre.org/tactic/d3f:Harden/)
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
⚠ Important: Human Verification Required
Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.