MemotivaCISSP Flashcards: Security Architecture, Models, Frameworks, Defense in Depth

What is defense in depth and why is it important?

CISSP Flashcards: Security Architecture, Models, Frameworks, Defense in Depth

Audio flashcard · 0:26

Nortren·

What is defense in depth and why is it important?

0:26

Defense in depth is a security strategy that deploys multiple layers of controls so that if one layer fails, others continue to protect the asset. Layers typically include perimeter defenses like firewalls, network segmentation, host-based controls like endpoint protection, application security, data protection like encryption, and physical security. The concept comes from military strategy where multiple defensive lines slow and weaken an attacker. No single control is perfect, so layering compensates for individual weaknesses.
csrc.nist.gov