Defense-in-Depth (DiD)
DiD is a security strategy that places multiple layers of different forms of defense between attackers and the resources that need to be protected. Adopting a DiD strategy allows an organization to adopt a strong security posture and helps ensure that all systems, data, and users are better protected from threats and compromise.
A DiD strategy means no “single layer” of protection or security service is solely responsible for protecting resources. Multiple layers of protection in a DiD strategy can slow down an attack path by implementing several types of defenses at individual layers. Attackers may successfully breach one defensive layer but will be halted by subsequent protection layers, preventing the protected resource from being exposed.
Figure 6.5 shows DiD as a concept and that it is nothing new as a strategy, as it can be considered the medieval castle approach to protecting resources:
Figure 6.5 –...