Security Architecture (Protect)

"Prevention is ideal, but detection is a must."

Security Architecture is the foundation of the Protect function of NIST CSF. It involves designing networks, systems, and applications to be inherently resistant to compromise.

Core Concepts

  1. Defense in Depth: Layering security controls (Perimeter, Network, Endpoint, Data) so that if one fails, others remain.
  2. Zero Trust: "Never trust, always verify." Assuming the network is already hostile.
  3. Least Privilege: Users and systems should only have the bare minimum access required to function.

Section Contents