Apply defense-in-depth by layering multiple independent security controls. Use when reviewing system architecture, evaluating whether a single control is the only barrier, or assessing blast radius of a component compromise.