Defense in Depth: A Sanity Check

Defense in depth means multiple layers. Audit yours.

Layers

Defense in depth is the security principle that protection should not depend on any single control. If one layer fails, others contain the damage. The defense-in-depth check is the periodic exercise of confirming that the layers actually exist, are independent, and would each catch the kind of attacker the team expects.

What the layers actually are:

The layered model is the conceptual framework. The check is the verification that each layer actually exists and works.

Audit

Auditing defense in depth is per-layer: for each layer, what is the specific control, how do we know it works, when was it last tested? The audit produces a structured assessment that the team and auditors can both reference.

The audit is the discipline that converts "we have defense in depth" from belief into demonstrated fact.

Gaps

The check inevitably surfaces gaps. Layers that exist but are not tested. Layers that depend on a single control that could fail. Compensating layers that exist on paper but not in practice. Closing gaps is the value the check produces.

The defense-depth check is the discipline that prevents security architecture from drifting between audits. Nova AI Ops integrates with security tooling across all layers, surfaces gaps automatically, and produces the per-layer audit report that compliance and engineering both reference.