Defense in Depth
What is Defense in Depth?
A layered security strategy that uses multiple security controls at different levels so that if one control fails, others continue to provide protection.
Terms that appear alongside defense in depth
Each of these is named in at least one of the same controls as defense in depth. The number is how many controls name both.
- zero trust 4 shared controls
- firewall 4 shared controls
- vlan 3 shared controls
- microsegmentation 3 shared controls
- authentication 3 shared controls
- dnssec 3 shared controls
- gateway 3 shared controls
- owasp 3 shared controls
Frameworks that govern defense in depth
What the standards actually require on defense in depth
Requirements naming defense in depth across 6 standards, quoted from the control text.
Apply defense in depth protective strategies to provide multiple layers of administrative, technical, and physical controls so that compromise of any single control does not adversely impact safety, security, or emergency preparedness functions.
NRC-73.54(f) · Defense in Depth →Apply multiple, layered, and complementary security controls across OT architecture so that failure of any single control does not compromise the system.
OT-ARCH-3 · Defense in Depth →Per 10 CFR 73.54 + NRC Regulatory Guide 5.71: defense-in-depth + access control + monitoring + boundary controls + integrity protection.
USNRCCYBER-4 · Defense-in-Depth and Technical Controls →Apply cloud-native security principles: defense in depth, least privilege, zero trust, immutability, and secure-by-default across the 4C layers and lifecycle.
CNCF-SA-PRINCIPLES · Security Principles →Network is segmented based on trust zones with defense in depth, including firewalls, IDS/IPS, and secure perimeter controls.
IS-IV.C.1 · Network Security Architecture →Security Planes per X.805 Clause 7.4: A Security Plane represents a certain type of network activity protected by Security Dimensions and applied across all 3 Security Layers.
X805-Planes-Management-Control-EndUser-OAM-Signalling-Network-Element-Subscriber-Data · ITU-T X.805 Security Planes - Management Plane + Control Plane + End-User Plane + OAM Operations-Administration-Maintenance + Signalling + Routing + Network Element Activity + Subscriber Data Flows + Cross-Layer Application →Questions people ask about defense in depth
What is Defense in Depth?
Why is Defense in Depth important for compliance?
Which compliance frameworks address Defense in Depth?
Where can I learn more about Defense in Depth?
See how Defense in Depth applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.