Defense in Depth
Employing multiple layers of security controls to protect assets, so that a failure in one layer does not compromise the entire system.
📜
The statement of the theorem
Let be a system asset, and let be a set of independent security controls, where protects against a specific threat . Define the failure state as the event where control is bypassed or fails. The system remains secure if the intersection of all failure events is empty: .