Term:Defense in Depth

From FISMApedia
Revision as of 01:01, 26 October 2009 by DanPhilpott (talk)
(diff) ← Older revision | Latest revision (diff) | Newer revision → (diff)
Jump to: navigation, search


Defense in Depth - An approach for establishing an adequate IA posture whereby (1) IA solutions integrate people, technology and operations; (2) IA solutions are layered within and among IT assets; and (3) IA solutions are selected based on their relative level of robustness. Implementation of this approach recognizes that the highly interactive nature of information systems and enclaves creates a shared risk environment; therefore, the adequate assurance of any single asset is dependent upon the adequate assurance of all interconnecting assets.