Certified Information Security Manager (CISM)Information Security ProgramEasy
An organization is developing a new information security architecture. The CISO emphasizes the need for a 'defense-in-depth' strategy. Which of the following principles is MOST critical to successfully implementing defense-in-depth?
- ADeploying a single, highly advanced unified threat management (UTM) appliance.
- BEnsuring redundancy and diversity of security controls across multiple layers.
- CPrioritizing the implementation of strong perimeter security controls.
- DCentralizing all security logging and monitoring functions into one system.
Show answer & explanationAnswer & explanation
Correct answer: B. Ensuring redundancy and diversity of security controls across multiple layers.
Defense-in-depth relies on multiple, diverse security controls at various layers. This redundancy and diversity ensure that if one control fails, others are in place to provide protection, preventing a single point of failure.
Why the other options are wrong
- A. A single UTM, no matter how advanced, represents a single point of failure, which contradicts the defense-in-depth principle.
- C. While perimeter security is important, defense-in-depth extends protection beyond the perimeter to internal systems and data, not just focusing on the boundary.
- D. Centralizing logging is good for management, but it's an operational aspect and does not directly relate to the multi-layered control strategy of defense-in-depth itself.
Defense-in-Depth
A strategy that employs multiple layers of security controls (administrative, technical, physical) to protect information and systems, ensuring that if one control fails, others are in place to provide protection.
- Aims to prevent single points of failure.
- Requires diverse and redundant controls.
- Applies to all layers of an organization's infrastructure.
Memory trick: Like an onion, security has many layers; if one peels away, others still protect the core.