Defence in Depth
What is Defence in Depth?
A security strategy that uses multiple layers of controls to protect assets. If one layer fails, others continue to provide protection.
Terms that appear alongside defence in depth
Each of these is named in at least one of the same controls as defence in depth. The number is how many controls name both.
- security architecture 5 shared controls
- integrity 2 shared controls
- resilience 2 shared controls
- owasp 2 shared controls
- security controls 2 shared controls
- iec 62443 2 shared controls
- dmz 2 shared controls
- isolation 2 shared controls
Frameworks that govern defence in depth
What the standards actually require on defence in depth
Requirements naming defence in depth across 6 standards, quoted from the control text.
Defence in depth and in breadth. Protection should apply layered (defence in depth) and broad (defence in breadth) measures across people, processes and technology for both IT and OT.
BIMCO-7.1 · Defence in depth and in breadth →NSS-17 + NSS-42-G require facility computer security architecture organised by Computer Security Zones (CSZs) implementing IAEA zone model.
IAEA-NSS17-Architecture-Zones-DefenceInDepth-Segmentation · IAEA NSS-17 - Computer Security Architecture + Zone Model + Defence in Depth + Network Segmentation + Boundary →Design and operate OT network architecture per NIST SP 800-82 Rev 3 Chapter 6 (OT Security Architecture). Apply the Purdue Enterprise Reference Architecture as the foundational structure: Level 0 Physical Process + Level 1 Basic Control + Level 2 Area Supervis...
NISTSP82-3 · OT Network Architecture: Zoned Architecture, Conduits, Segmentation, and Defence-in-Depth →Product supplier applies secure-by-design principles including defence in depth, least privilege, secure default configurations, security architecture review and attack surface minimisation.
62443-4-1-SD · Secure by Design →350.0-G-3 sec.5.7: combining security options across layers to achieve defence in depth without unnecessary duplication.
CCSDS350-5.7 · Security Option Combinations →Apply defence in depth against network attack, covering prevention, detection and timely response, through defined and evaluated processes.
CCM-IVS-09 · Network Defense →Questions people ask about defence in depth
What is Defence in Depth?
Why is Defence in Depth important for compliance?
Which compliance frameworks address Defence in Depth?
Where can I learn more about Defence in Depth?
See how Defence in Depth applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.