Skip to content

Defence in Depth

What is Defence in Depth?

A security strategy that uses multiple layers of controls to protect assets. If one layer fails, others continue to provide protection.

Information Security

Each of these is named in at least one of the same controls as defence in depth. The number is how many controls name both.

What the standards actually require on defence in depth

Requirements naming defence in depth across 6 standards, quoted from the control text.

Defence in depth and in breadth. Protection should apply layered (defence in depth) and broad (defence in breadth) measures across people, processes and technology for both IT and OT.

BIMCO-7.1 · Defence in depth and in breadth

Design and operate OT network architecture per NIST SP 800-82 Rev 3 Chapter 6 (OT Security Architecture). Apply the Purdue Enterprise Reference Architecture as the foundational structure: Level 0 Physical Process + Level 1 Basic Control + Level 2 Area Supervis...

NISTSP82-3 · OT Network Architecture: Zoned Architecture, Conduits, Segmentation, and Defence-in-Depth
IEC 624432 controls

Product supplier applies secure-by-design principles including defence in depth, least privilege, secure default configurations, security architecture review and attack surface minimisation.

62443-4-1-SD · Secure by Design

350.0-G-3 sec.5.7: combining security options across layers to achieve defence in depth without unnecessary duplication.

CCSDS350-5.7 · Security Option Combinations

Apply defence in depth against network attack, covering prevention, detection and timely response, through defined and evaluated processes.

CCM-IVS-09 · Network Defense

Questions people ask about defence in depth

What is Defence in Depth?
A security strategy that uses multiple layers of controls to protect assets. If one layer fails, others continue to provide protection.
Why is Defence in Depth important for compliance?
Defence in Depth is a key concept in Information Security. Understanding defence in depth helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address Defence in Depth?
Defence in Depth appears in the requirement text of BIMCO Cyber Security, IAEA Nuclear Security Series - Computer Security at Nuclear Facilities (NSS-17-T Rev 1), NIST SP 800-82 Revision 3: Guide to Industrial Control Systems (ICS) Security, IEC 62443, CCSDS 350.0-G-3 - Space Communications Security (Consultative Committee for Space Data Systems). Across these standards we have identified 7 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about Defence in Depth?
Explore our compliance framework pages to see how defence in depth applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how Defence in Depth applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.