graphgrc

SCF - NET-02 - Layered Network Defenses

Mechanisms exist to implement security functions as a layered structure that minimizes interactions between layers of the design and avoids any dependence by lower layers on the functionality or correctness of higher layers.

Mapped framework controls

ISO 27002

SOC 2

Control questions

Does the organization implement security functions as a layered structure that minimizes interactions between layers of the design and avoids any dependence by lower layers on the functionality or correctness of higher layers?