What MITRE D3FEND D3-CRO: Credential Rotation (Defensive Tactic - Evict) requires
MITRE D3FEND D3-CRO (Credential Rotation) is a defensive technique that regularly changes or replaces authentication credentials (passwords, API keys, certificates) to minimise risk of unauthorised access. Counters ATT&CK T1110 (Brute Force), T1003 (OS Credential Dumping), T1078 (Valid Accounts), T1550 (Use Alternate Authentication Material), T1134 (Access Token Manipulation), T1528 (Steal Application Access Token). Required under NIST SP 800-53 IA-5, ISO 27001 A.5.17, PCI DSS Req 8, NIST SP 800-63B.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://d3fend.mitre.org/technique/d3f:CredentialRotation/
SHA-256 integrity: 3e90511d23b989c89b2b3d603802bbfb254753111c623b261471a3249e38a5fc
Primary Citations — 8 traced to source
- MITRE D3FEND D3-CRO: Credential Rotation (https://d3fend.mitre.org/technique/d3f:CredentialRotation/)
- NIST SP 800-53 Rev 5: IA-5 Authenticator Management
+ 6 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
⚠ Important: Human Verification Required
Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.