Information Assurance: Managing Organizational IT Security Risks

Identify the elements of the DoD's Defense in Depth strategy
Establish a working model of IA elements
Discuss physical security requirements
Outline technical countermeasures used within virtual boundaries
The U.S. Department of Defense (DoD) has adopted a Global Network Information Environment (GNIE) IA strategy called "Defense in Depth" (IATF, 1999, p. 1.1). The approach is based on the ancient principle that multiple layers of protection are better than a single point of failure. Medieval castles incorporated a combination of moat, drawbridge, fortified walls, watchtowers, armed guards, and supplies. Likewise, good computer network defense cannot depend on a single firewall or simple passwords, but rather requires multiple controls and safeguards to provide an acceptable level of defense.
The DoD strategy breaks down IA into three basic elements people, technology, and operations.
People are the most crucial aspect of IA. The challenge is to provide the right amount and type of training to all the people and to develop a human resources strategy that brings the right people to bear at the right time and place.... [Operations consists of] two main aspects: system management and situation awareness (IATF, 1999, p. 1.2.3).
Operations also include the security procedures required to ensure that system defenses quickly adapt in response to changing threats. The element of technology is where the Defense in Depth layers are applied: within the network at...