ISC2 CISSP (Certified Information Systems Security Professional)Security OperationsMedium
A security architect is designing a new physical security system for a data center. The design includes multiple layers: a perimeter fence with CCTV, badge access control at the building entrance, biometric scanners for the server room, and individual rack locks. Which principle of physical security is BEST exemplified by this design?
- ALeast Privilege
- BDefense-in-Depth
- CSeparation of Duties
- DFail-Safe Defaults
Show answer & explanationAnswer & explanation
Correct answer: B. Defense-in-Depth
The design incorporates multiple, independent layers of security controls (fence, badge, biometrics, rack locks) to protect the data center. This layered approach, where the failure of one control does not compromise the entire system, is the core principle of Defense-in-Depth.
Why the other options are wrong
- A. Least Privilege applies to granting minimum necessary access, usually in logical systems, not primarily physical layering.
- C. Separation of Duties divides critical tasks among multiple individuals to prevent fraud or error, not physical access layering.
- D. Fail-Safe Defaults means that if a system fails, it defaults to a secure state, which is not what multiple physical layers represent.
Defense-in-Depth (Physical Security)
Defense-in-Depth (also known as 'layered security') in physical security involves implementing multiple, independent layers of security controls to protect an asset, such that if one control fails, others remain to provide protection.
- Multiple, overlapping security controls.
- Aims to slow down or deter attackers.
- Reduces reliance on a single point of failure.
Memory trick: Layered Defenses make it a 'Castle' of security.