It depends what layer security you want to achieve , a trade exists , if you are doing at SSL/TLS layers only application layer protocols like HTTPS/SSH etc might benefit . but if you are doing at IPSEC layer all the application protocols may achieve privacy ( say through VPN Connectivity) . You can do at Link-Link Encryption too . So it depends on what you want to achieve . I gave a talk long back on this , you may find it useful
Yes, all the layers can be involved in obtaining security servcies or Machanisms. In the recent years, the wireless communications community has turned the attention to physical layer security, as a promising new layer of defence to realize wireless secrecy communications independent of the conventional cryptosystems that typically assume limited computational complexity of attackers. The idea behind physical layer security is to exploit the uncorrelated nature of the communication medium/channel with the aim to maximize the uncertainty about the source messages at the eavesdropper. In this regard, there is increasing amount of work in authenticating wireless devices based on their physical and radiometric properties.