What does defense in depth mean on the CPA exam?
Defense in depth. Layering independent controls so that no single failure exposes the asset. The point is not that any layer is strong, but that an attacker must defeat all of them.
Defined against NIST SP 800-53.
Which CPA exam sections use defense in depth?
Defense in depth appears in the ISC section of the CPA exam.
Other names for defense in depth
layered security
Related terms
- least privilege: Giving each user and process only the access it needs to do its job, and no more.
- operating lease: A lease that does not transfer control.
- SOC 1 Type 1 report: A report on the fairness of the description and the suitability of the design of controls, at a point in time.