Compliance Node Overview
MITRE D3FEND D3-CP (Certificate Pinning) is a defensive technique that persists a server X.509 certificate or public key and compares against the server presented identity to allow greater client confidence in remote server identity for SSL/TLS connections. Counters certificate substitution, AiTM, certificate authority compromise, forged authentication certificates. Counters ATT&CK T1557 (Adversary-in-the-Middle), T1649 (Steal or Forge Authentication Certificates). Required for mobile and IoT clients per OWASP MASVS V5.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://d3fend.mitre.org/technique/d3f:CertificatePinning/
SHA-256 integrity: c26592b43c680be665a746ba52abd53c3697002d736595e02daf05ea8f809eda
Primary Citations — 8 traced to source
- MITRE D3FEND D3-CP: Certificate Pinning (https://d3fend.mitre.org/technique/d3f:CertificatePinning/)
- NIST SP 800-53 Rev 5: SC-17 PKI Certificates, SC-8 Transmission Confidentiality
+ 6 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
⚠ Important: Human Verification Required
Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.