Skip to content

Defense in Depth

What is Defense in Depth?

A layered security strategy that uses multiple security controls at different levels so that if one control fails, others continue to provide protection.

Information Security

Each of these is named in at least one of the same controls as defense in depth. The number is how many controls name both.

What the standards actually require on defense in depth

Requirements naming defense in depth across 6 standards, quoted from the control text.

Apply defense in depth protective strategies to provide multiple layers of administrative, technical, and physical controls so that compromise of any single control does not adversely impact safety, security, or emergency preparedness functions.

NRC-73.54(f) · Defense in Depth

Apply multiple, layered, and complementary security controls across OT architecture so that failure of any single control does not compromise the system.

OT-ARCH-3 · Defense in Depth

Per 10 CFR 73.54 + NRC Regulatory Guide 5.71: defense-in-depth + access control + monitoring + boundary controls + integrity protection.

USNRCCYBER-4 · Defense-in-Depth and Technical Controls

Apply cloud-native security principles: defense in depth, least privilege, zero trust, immutability, and secure-by-default across the 4C layers and lifecycle.

CNCF-SA-PRINCIPLES · Security Principles

Network is segmented based on trust zones with defense in depth, including firewalls, IDS/IPS, and secure perimeter controls.

IS-IV.C.1 · Network Security Architecture

Questions people ask about defense in depth

What is Defense in Depth?
A layered security strategy that uses multiple security controls at different levels so that if one control fails, others continue to provide protection.
Why is Defense in Depth important for compliance?
Defense in Depth is a key concept in Information Security. Understanding defense in depth helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address Defense in Depth?
Defense in Depth appears in the requirement text of NRC 10 CFR 73.54 - Nuclear Facility Cybersecurity, NIST SP 800-82 Rev 3, US NRC 10 CFR 73.54 - Cyber Security for Nuclear Power Plants, CNCF Security Technical Advisory Group (TAG), FFIEC IT Examination Handbook. Across these standards we have identified 7 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about Defense in Depth?
Explore our compliance framework pages to see how defense in depth applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how Defense in Depth applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.