1 / 5100%
Running Head: LAYERING ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad
ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad 1
Information security principle – Layering
LAYERING ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad
ad ad ad ad ad a ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad
ad ad ad ad ad a ad ad ad ad ad ad ad ad ad 2
Principle
The layering information security principle has been selected as it combines
numerous mitigating security control mechanisms to safeguard resources and data.
This principle has been favored as it can be implemented in any kind of
environment, starting from individuals to organizations. As a diverse range of
security controls are employed in this security mechanism at varying levels, the
quality of security is superior in nature.
Explanation
Layer security understands that a single security approach might not be
sufficient to protect digital data and online assets. Thus a robust security scheme is
implemented which involves a series of well-planned and complementary levels of
security approaches (Fennelly & Perry, 2016).
As per ASIS International Glossary of Security, layered security has been
defined as a ‘physical security approach that requires a criminal to penetrate or
overcome a series of security layers before reaching the target. In the prevailing
environment which is full of unpredictability and contingency, the layering security
approach can play a key role to offer adequate protection in various kinds of
scenarios (Fennelly & Perry, 2016). Some of the main advantages of the layered
security mechanism include the implementation of the right kind of defense model at
the right time, and strengthening the overall effectiveness of the cybersecurity
framework (The Benefits of Layered Security and How It Can Improve Your
Business, 2019). ad
Case example
The layering security mechanism can be employed in varying situations. A
common example is the use of the security approach is the installation of firewalls,
LAYERING ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad
ad ad ad ad ad a ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad
ad ad ad ad ad a ad ad ad ad ad ad ad ad ad 3
malware scanners, intrusion detection systems, and local storage encryption tools to
safeguard against the attack by cybercriminals (Perrin, 2015). Since all the security
measures act as a blanket, a potential attacker has to pass through each and every
security layer in order to compromise the system’s security. This makes it
challenging for cybercriminals to attack and compromise the security posture.
Limits
The layered security approach has a number of limitations that can give an
upper hand to the cyber-criminal. One of the major limitations of the security
principles is the complication in usability due to the existence of additional security
layers. There is a possibility that such a security approach can slow the entire
system and reduce the level of efficiency to a substantial extent (Gregg, 2019).
Sometimes, these set of security approaches might have unintended consequences
which can increase the level of vulnerability for the user. The integration of a wide
range of security mechanisms might be full of challenges that might be difficult for
the Information Technology (IT) team of an organization to overcome (Korolov,
2015). Similarly, the increases in the total number of security layers intensify the
chances of technical breakdown which can lead to the loss of confidential and
sensitive data. There is a chance of data overload as well as processing due to the
duplication in the functionality aspect. Such limitations can adversely affect the
quality of the security posture.
Relation to other principle
The Least Privilege security principle refers to the concept and practice of
limiting the access rights of the users and computing processes to only the specific
resources that are required by them to perform the authorized functions. By
restricting the internal activities that are to be performed, it creates a simpler path
LAYERING ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad
ad ad ad ad ad a ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad
ad ad ad ad ad a ad ad ad ad ad ad ad ad ad 4
for compliance (What is Least Privilege, or the Principle of Least Privilege (PoLP),
2019). Layering, on the other hand, introduces various security measures at different
levels to minimize threats from various sources. Both principles can work together
and act as a comprehensive security solution.
Example
The sales team of a business must only have access to sales data and not on
the entire finance records. The least privilege principle can be employed to restrict
the privilege of the sales team. The layering technique can also be used to safeguard
all the digital assets of the firm.
LAYERING ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad
ad ad ad ad ad a ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad
ad ad ad ad ad a ad ad ad ad ad ad ad ad ad 5
References
Fennelly, L. J., & Perry, M. (2016). Physical security: 150 things you should know.
Butterworth-Heinemann.
Gregg, M. (2019). Disadvantages to a layered approach. Retrieved November 30,
2019, from https://searchnetworking.techtarget.com/answer/Disadvantages-to-a-
layered-approach.
Korolov, M. (2015, November 13). The dark side of layered security. Retrieved
November 30, 2019, from https://www.csoonline.com/article/3004856/the-dark-side-
of-layered-security.html.
Perrin, C. (2015, July 28). Understanding layered security and defense in depth.
Retrieved November 30, 2019, from https://www.techrepublic.com/blog/it-
security/understanding-layered-security-and-defense-in-depth/.
The Benefits of Layered Security and How It Can Improve Your Business. (2019,
July 25). Retrieved November 30, 2019, from https://www.gosolis.com/blog/the-
benefits-of-layered-security-and-how-it-can-improve-your-business/.
What is Least Privilege, or the Principle of Least Privilege (PoLP)? (2019).
Retrieved November 30, 2019, from
https://www.beyondtrust.com/resources/glossary/least-privilege.
Students also viewed