Knowledge / hardening concepts acsc-glossary

Defence in depth

Stacked controls so one failure is not game over. Redundancy, not twelve dashboards of the same alert.

Defence in depth is multiple layers so that a single failed or bypassed control is not the whole story: identity, device, network, application, data, people, restore.

Layers that all depend on the same identity store are a stack of hats. Design independent failures. Then test one of them actually failing.

Fact source: ASD's ACSC glossary.