| |
|
|
| |
| 5. |
Utilizes Security
in Depth |
|
Security-in-depth methodologies reduce
organizational vulnerabilities by avoiding reliance on any one
defensive technique. Redundant layers of protection are deployed
so the failure of a single security measure wont cause
failure of the system security as a whole.
A robust anti-virus configuration provides an illustration of
security in depth: |
 |
Incoming electronic mail messages are scanned
for viruses when they enter the network. Recognizably
viral attachments are removed; unsafe email attachments
are removed even if they arent recognizably viral. |
|
Desktop anti-virus tools scan
email attachments for viruses before the attachments are
detached or opened. |
|
For a security-in-depth approach to be beneficial, the layered
components must be designed to work in concert. |