Skip to main content

Defense in Depth

Place complementary controls across distinct failure domains so one failure does not expose the protected asset.

System and boundaries

Defense in depth uses complementary controls so that one failure does not produce the full harmful outcome. Each layer should block a different step, limit impact, create evidence, or improve recovery. Counting products or repeating the same rule does not establish depth.

Request and decision flow

For an administration action, layers can include phishing-resistant authentication, route authorization, upstream isolation, application permission, narrow database authority, immutable evidence, and tested recovery. Map which attack step each layer changes.

Test independence

Identify shared dependencies and control planes. Two policy engines that use the same compromised identity source are not independent against false group data. A gateway and application can provide distinct value when the gateway controls reachability and the application controls object actions.

Failure domains and residual risk

More layers add complexity, latency, operating work, and new failure modes. Controls can share hidden dependencies or create inconsistent decisions. Depth should follow the threat model and must not hide an unowned primary control.

Pomerium boundary

Pomerium can provide route-level authentication, authorization, and enforcement as one layer. Network controls should prevent direct upstream access. The application should enforce object and action permissions. Endpoint, data, key, evidence, and recovery controls remain separate layers.

Evaluation checklist

  • Does each layer address a named threat step or consequence?
  • Are the layers independent against the relevant failure?
  • Can one control-plane or identity-source compromise defeat several layers?
  • Has each layer been tested alone and in combination?
  • Does the added complexity create more risk than the layer removes?

Sources and further reading

Keep learning

Security Engineering FoundationsAuthorization and Policy

Reference Monitor

Evaluate an access-control mechanism for complete mediation, tamper resistance, and evidence-based assurance.

Learn this term
Security Operations and Risk

Endpoint Security

Endpoint security is the set of controls used to manage and protect devices that access organizational data and services.

Learn this term

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo