10 August 2024

信息安全技术有五个重要的原则,分别是

  • defense in depth
  • least privilege
  • separation of duties
  • secure in design
  • economy of mechanism

在产品安全开发生命周期标准中(International Electrotechnical Commission(IEC) 2009)简单介绍了 defense in depth:

Defense in depth provides one or more layers of security to thwart security threats.

层层防护是指提供多层的安全保护阻挠安全威胁。

这里用了 thwart 阻挠。比如he was thwarted in love.他恋爱受挫。

在该标准分册的后面(International Electrotechnical Commission(IEC) 2009)还用到了这个词:

Threat mitigation testing is creating and executing plans for attempting to thwart each mitigation.

风险规避测试就是构建一个测试执行计划尝试阻挠这些规避安全的措施。通过攻击者视角审查防范措施是不是实施到位。

A Euro-Zone Inflation Hiccup Is Unlikely to Thwart ECB Rate Cut. (Stirling and Rinneby 2024) 这则新闻是说欧洲德法西三国通胀指数略微上涨的小问题,不会导致 ECB 降息。

thwart 的本意据说是跟 transverse 里的 verse 相似,有穿过的意思。也可能跟拉丁语 torquere 转动,twist 相关。有点乃意会,大概就是这样子。

References

International Electrotechnical Commission(IEC). 2009. “Industrial Communication Networks – Network and System Security – Part 4-1: Secure Product Development Lifecycle Requirements.”
Stirling, Craig, and Joel Rinneby. 2024. “A Euro-Zone Inflation Hiccup Is Unlikely to Thwart ECB Rate Cut.” Bloomberg News.