Security & governance · Glossary term

What is Defense in Depth?

Using independent preventive, detective, and corrective controls at several system boundaries so one failed control does not determine the outcome.

Why does Defense in Depth matter?

AI systems combine probabilistic models, untrusted content, tools, and external services, making any single filter or prompt an inadequate security boundary.

Defense in Depth in practice

Pair instruction controls with narrow permissions, sandboxing, schema validation, approval for consequential actions, monitoring, and a tested recovery path.

What is the common confusion about Defense in Depth?

More controls are not automatically better. Layers should address distinct failure modes and remain testable rather than repeat the same assumption.

Learn Defense in Depth in the course

No lesson links to this term yet. Search the course catalog for it.

  • GuardrailsSystem controls that constrain inputs, tool use, outputs, permissions, and escalation.
  • SandboxAn isolated execution environment that restricts an agent's access to files, processes, network destinations, credentials, and host…
  • Least PrivilegeGiving a model, agent, tool, or user only the permissions required for the current task, for only as long as those permissions are needed.
  • Trust BoundaryAn interface where data, instructions, identity, or authority crosses between components or principals that operate under different trust…

Sources

More terms in Security & governance

Open the Security & governance list in the glossary

This entry comes from glossary/terms.md on GitHub. Browse all 250 glossary terms.