The principle of defense in depth is that layered security mechanisms increase security of a
system as a whole. If an attack causes one security mechanism to fail, other mechanisms
may still provide the necessary security to protect the system [19]. This is a process that
involves people, technology, and operations as key components to its success; however, those
are only part of the picture. These organizational layers are difficult to translate into
specific technological layers of defenses, and they leave out areas such as security monitoring
and metrics. Figure 1.9 shows a mind map that organizes the major categories from both
the organizational and technical aspects of defense in depth and takes into account
people, policies, monitoring, and security metrics.