Glossary

    Defense in Depth

    Architecture & Design

    Defense in Depth is the practice of implementing multiple layers of security controls so that no single point of failure can compromise the entire system. If an attacker bypasses one layer, they face another.

    AWS Layers

    • Edge: CloudFront, WAF, Shield (DDoS, L7 filtering)
    • Network: VPC, subnets, security groups, NACLs, Network Firewall
    • Identity: IAM, SCPs, permission boundaries, MFA
    • Application: input validation, authentication, authorization
    • Data: encryption at rest/transit, key management, access logging
    • Monitoring: CloudTrail, GuardDuty, Security Hub, Config

    Toc Consulting: AWS Security & Cloud Architecture

    Securing your AWS estate?

    Our team helps engineering teams secure and architect AWS the right way: assessment in week one, a prioritized action plan in week two.