Defense in depth is a security concept that deploys multiple, overlapping layers of protection to complicate attacks and limit impact. It combines organizational measures, technical controls and operational processes. The approach is technology-agnostic and applies to networks, applications and organizational workflows.
Use this profile to understand the building block briefly, place it in the model, and switch to the 360° assessment when needed.
Theoretical construct: explains a term, principle, or mental model.
What you need to understand to reason about a domain.
Defense in depth is a security concept that combines several overlapping layers of protection so that one failed control does not immediately open a path to compromise.
The term comes from military defense in depth: instead of relying on a single front line, defenders use successive positions to slow an attacker and spread pressure across the force. Security architecture adopted the same logic for systems where one barrier cannot reliably absorb misconfiguration, insider risk, or component failure. The goal became layered risk reduction, not a single perfect control.
Think of a path with successive gates, cameras, and response teams. The outer layer makes access harder, inner layers limit movement, monitoring spots anomalies, and response measures contain the incident. The system is safer because each layer covers a different failure mode and buys time for investigation and recovery.
Several measures intentionally cover the same risk so that no single failure is decisive.
Layers can block attacks, make them visible, or trigger handling; the combination matters more than any single barrier.
Systems and permissions are separated so that an incident cannot spread unchecked.
If one control fails, the scope, duration, and effect of the incident stay as small as possible.
It clarifies which threats and protection goals justify the choice and depth of the layers.
The concept helps when designing security architectures, cloud and platform designs, procurement decisions, and critical operational processes. It is especially useful when one control point is not enough or when misconfiguration, insider risk, and failures must be accounted for. More layers also mean more complexity, coordination effort, and operational overhead; without risk assessment, the result can easily become security theater.
Where this building block is located in the topic model.
Explore how this building block connects to concepts, methods, technologies, and tools.
These sources establish the term and its professional meaning.
All direct connections of the current building block in a compact text view.
This classification shows where the building block typically matters, how demanding it is, and what kind of impact it has in the model.
The level within the organization (enterprise, domain, team) at which the AssetBlock is applied.