Certified Information Security Manager (CISM)Information Security ProgramEasy

An organization is developing a new information security architecture. The CISO emphasizes the need for a 'defense-in-depth' strategy. Which of the following principles is MOST critical to successfully implementing defense-in-depth?

  1. ADeploying a single, highly advanced unified threat management (UTM) appliance.
  2. BEnsuring redundancy and diversity of security controls across multiple layers.
  3. CPrioritizing the implementation of strong perimeter security controls.
  4. DCentralizing all security logging and monitoring functions into one system.
Show answer & explanation

Correct answer: B. Ensuring redundancy and diversity of security controls across multiple layers.

Defense-in-depth relies on multiple, diverse security controls at various layers. This redundancy and diversity ensure that if one control fails, others are in place to provide protection, preventing a single point of failure.

Why the other options are wrong

  • A. A single UTM, no matter how advanced, represents a single point of failure, which contradicts the defense-in-depth principle.
  • C. While perimeter security is important, defense-in-depth extends protection beyond the perimeter to internal systems and data, not just focusing on the boundary.
  • D. Centralizing logging is good for management, but it's an operational aspect and does not directly relate to the multi-layered control strategy of defense-in-depth itself.

Defense-in-Depth

A strategy that employs multiple layers of security controls (administrative, technical, physical) to protect information and systems, ensuring that if one control fails, others are in place to provide protection.

  • Aims to prevent single points of failure.
  • Requires diverse and redundant controls.
  • Applies to all layers of an organization's infrastructure.

Memory trick: Like an onion, security has many layers; if one peels away, others still protect the core.

More Information Security Program questions