DefenseinDepth
Defense in depth, sometimes written as defenseindepth, is a security strategy that uses multiple, overlapping layers of protection to reduce the likelihood that a breach succeeds and to mitigate damage when a component is compromised. The core idea is that no single control provides complete protection; instead, a defender relies on diversity and redundancy across people, processes, and technology.
Layers typically span physical security, perimeter and network controls, host and application hardening, identity and access
Origin and adoption: the concept has military roots and was adapted to information security as networks grew
Implementation considerations: conduct risk and asset mapping, apply the principle of least privilege, segment networks, enforce
Benefits and limitations: benefits include reduced chances of a successful attack and greater resilience, but defense
See also: layered security, zero trust security. Defense in depth is a general principle rather than a