Defense in Depth
A security strategy that layers independent preventive, detective, and containment controls so failure of one control does not expose the entire system.
Security Context
Defense in depth combines controls that fail in different ways: authentication, network segmentation, least privilege, application validation, monitoring, containment, and recovery. The objective is to keep the failure of one control from exposing the entire system.
Independence Boundary
Several controls built on the same weak assumption are not independent defense layers. Layering is valuable when the controls cover distinct failure modes and provide prevention, detection, or containment at different points.