# 2. Security Principles

## **2.1 Defense in Depth Overview**

TheDen Home Network follows a layered defense model, with multiple safeguards that provide independent protection. Layers include OPNsense, VLAN segmentation, encrypted DNS (DoT), and Suricata IPS.

## **2.2 Zero Trust and Least Privilege**

All devices are treated as untrusted by default. Access is restricted to essential communications only, using a default-deny policy between VLANs.   
Administrative access requires authenticated HTTPS and IoT devices are limited to U.S.-based connections only.