Homework Responses Wk 5
Defense in Depth is a security system that employs a multiple number of layered controls and mechanisms. The general premise being that if one of the layers of control fails, there will be another one after it. This defense system has been used through out history by militaries. When used as a military strategy, the primary goal was to delay an attack and buy time in order to develop and employ a more successful counter strike. This defense in depth strategy was quickly applied to physical security and information technology security. IT systems incorporate numerous different controls to keep systems and information secure. In the IT worlds, the controls incorporated into a layer defense system include firewalls, intrusion prevention, endpoint detection and response, and network segmentation (2020). Utilizing this strategy can help make network and information security much more effective, increasing the amount of time and complexity involved in compromising a system (2020).
The importance of testing detection systems is due to the fact that they are generally very expensive and are can be protecting important assets. Since the most vital features of a detection system are not typically used everyday, it can be easy fail without being known. Power outages, internet failures, and criminals are some of the reasons that systems are become compromised. Testing information security systems can be broken into three different methods. Testing, which involves exercising one or more objects while creating certain conditions to compare real time with expected behaviors (Scarfone, 2008). Examination, which assesses and studies asset or control failures (Scarfone, 2008). Interviewing is the final method used to test and assess security systems, it is the process of discussions with groups within an organization to identify and understand evidence collected in the testing and examination process (Scarfone, 2008).
References:
Vacca, J. (2017). Computer and Information Security Handbook (Third ed.) [Https://www.sciencedirect.com/book/9780128038437/computer-and-information-security-handbook]. Elsevier.
Cybersecurity Spotlight - Defense in Depth (DiD). (2020). Retrieved December 03, 2020, from https://www.cisecurity.org/spotlight/cybersecurity-spotlight-defense-in-depth-did/
Scarfone, K. (2008). Technical Guide to Information Security Testing and Assessment. Retrieved December 03, 2020, from https://www.govinfo.gov/content/pkg/GOVPUB-C13-894df23cbad6ad74af7d49c17b081dd1/pdf/GOVPUB-C13-894df23cbad6ad74af7d49c17b081dd1.pdf2