Unit content
Defense in depth
Defense in depth uses multiple security controls so one failed assumption does not immediately become a total compromise.
Different layers can enforce different boundaries. Hardware memory isolation can separate processes, protected network transport can constrain eavesdropping and tampering, identity checks can distinguish accounts, and operation-specific permission checks can limit what each account may do.
The value comes from partial independence: bypassing one control should still leave another meaningful barrier.
More layers are not automatically better. Each mechanism adds complexity and may introduce new failure modes or operational dependencies.
A useful layered design therefore asks what attack or failure each control contains and whether another layer still matters after that control is bypassed.
Defense in depth complements prevention. The system should still remove known vulnerabilities rather than relying on downstream mitigations to make exploitation inconvenient.