This paper is from the SANS Institute Reading Room site. Reposting is not permitted without express written permission. How Spyware fits into Defense in Depth The layered approach to defending network systems, Defense in Depth, is the best approach to protecting the assets of a company or individual, but remember that this is not 100 % secure. No network is completely secured against electronic, or physical attacks regardless of what solutions are used to protect it. New spyware programs crop up everyday, and the attackers are ever evolving in the ways that they try to attack system vulnerabilities, which is why our network defenses and corporate policies have to be ever evol... Copyright SANS Institut