Defence in depth
Stacked controls so one failure is not game over. Redundancy, not twelve dashboards of the same alert.
Defence in depth is multiple layers so that a single failed or bypassed control is not the whole story: identity, device, network, application, data, people, restore.
Layers that all depend on the same identity store are a stack of hats. Design independent failures. Then test one of them actually failing.
Fact source: ASD's ACSC glossary.
