跟读练习: Zero Trust Explained in 4 mins - 通过视频学习英语口语
正在创建课程...
1
Zero Trust is a security strategy that says you shouldn't grant implicit trust to a user,
2
device or an application based solely around some property about them, like their network location.
3
Over the next few minutes, I'll explain exactly what we mean by this and how IBM can help.
4
But let's be really clear upfront.
5
Zero Trust isn't something that can simply be delivered by implementing a new piece of technology, nor is it a point product or service that you can just go out and buy.
6
It's a security strategy that has three core principles.
7
But before I come on to those, let me explain why organisations are increasingly moving on from the previous popular model of perimeter security.
8
Firstly, there's this somewhat medieval notion
9
that you have a perimeter to your network where you build the walls as high as possible
10
and try and stop malicious actors at the gates.
11
This no longer works because employees are working from home more than they're working from the office,
12
and because hybrid cloud is now clearly the preeminent platform for enterprise infrastructure.
13
So it's an increasingly complex problem to even define a perimeter.
14
Secondly, the concept of trust is a very human one that we've taught computers to adapt to.
15
For example, if I see Helen every day in the office wearing her employee badge, I trust that she's an employee and is there for the right reasons.
16
In reality, I don't actually know that she wasn't let go last week for misconduct, and is now back in the office trying to steal corporate data.
17
So a computer security model based on a human definition of trust is inherently flawed,
18
particularly in a world where attackers are finding it easier than ever to steal credentials and disguise themselves as trustworthy.
19
Without a zero trust security model, once an attacker is in the corporate network, they can move laterally to new systems with relative ease.
20
This brings me on to the first defining principle of the Zero Trust model: Never trust Always verify.
21
Just because somebody's on your corporate network and is carrying
22
that badge with an employee name on it doesn't mean that they are who they say they are, or that they're necessarily well -intentioned.
23
So this always verified piece refers to the fact that every time something like a user, device or application tries to make a new connection attempt,
24
that attempt should be rigorously authenticated and authorised, and not simply trusted because it's coming from inside the corporate network, for example.
25
Implement least privilege is the second core principle of a zero trust architecture, which says you should only grant users and applications the minimum amount of access
26
that they need to perform their job effectively and no more.
27
Privileged access management is a great way of implementing least privilege for admin users, for example.
28
And then finally, assume breach.
29
This is my favourite of the zero trust principles
30
because it encourages teams to plan for the worst case scenario
31
and build robust and tested incident response plans so that when attacks do occur, the time to respond is rapid and well practised.
32
Not only this, but this principle encourages organisations to shrink the target
33
and the impact zone of an attack through networking principles like micro -segmentation.
34
So how can IBM security help?
35
We recognize that different clients will have different business drivers and priorities for why they want to deploy Zero Trust.
36
So we've created four actionable blueprints depending on where you want to start.
37
They are Reduce the risk of insider threat.
38
Secure the remote workforce.
39
preserve customer privacy, and protect the hybrid cloud.
40
You can download these with no form filling required from IBM .com.
📺 同频道
✨ 推荐视频
這支影片適合誰?
這是一支適合中高階英語學習者的影片,尤其適合想提升商務英語理解與口語表達的人。影片內容圍繞資安策略,用詞專業但解釋淺顯,能幫助學習者熟悉科技領域的實用表達。透過「看YouTube學英語」,不僅能積累專業詞彙,還能練習聽懂快速且清晰的商業用語,非常適合搭配shadowing練習(影子跟讀)來提升口語流利度。
值得借鑑的詞彙與短語
- implicit trust:隱含信任。指未經驗證就給予的信任,如影片中提到的「不應僅憑網絡位置就給予隱含信任」。
- lateral movement:橫向移動。在資安領域指攻擊者入侵後在網絡內部擴散,可延伸用於描述「擴展影響範圍」。
- least privilege:最小權限。指僅授予完成工作所需的最低權限,是商務談判與團隊管理中常用的概念。
- assume breach:假設入侵。一種預防性思維,類似於「未雨綢繆」,可用於討論風險管理。
如何掌握發音與語調?
這位講者的發音清晰,語速中等,適合做shadow speech練習。以下是兩個關鍵點:
- 重讀關鍵詞:講者在解釋核心原則時,會加重「Never trust, Always verify」「assume breach」等短語的語氣。練習時可模仿這種重讀,突出語義重點。
- 連讀與弱讀:如「it's a security strategy」中「it's a」會連讀為/ɪtsə/,「for example」中的「for」弱讀為/fə/。透過shadowing site上的逐句跟讀功能,反覆練習這些細節,能讓口語更自然。
建議每天花10分鐘,用shadow speak方式跟讀影片片段,專注於語速與節奏的匹配。堅持一周,就能明顯感受到口語流暢度的提升。
视频中的语法
说话人最常用的结构,并附上视频中的原话:
| 结构 | 视频中的用法 |
|---|---|
| 现在完成时 have/has + 过去分词 — 过去发生但与现在仍有关联的事 | we've taught · we've created |
| 被动语态 be + 过去分词 — 强调发生了什么,而不是谁做的 | be delivered · wasn't let |
什么是跟读法?
跟读法 (Shadowing) 是一种有科学依据的语言学习技巧,最初开发用于专业口译员的培训,并由多语言者Alexander Arguelles博士普及。这个方法简单而强大:您在听英语母语原声的同时立即大声重复——就像是一个延迟1-2秒紧跟说话者的影子。与被动听力或语法练习不同,跟读法强迫您的大脑和口腔肌肉同时处理并模仿真实的讲话模式。研究表明它能显着提高发音准确性,语调,节奏,连读,听力理解和口语流利度——使其成为雅思口语备考和真实英语交流最有效的方法之一。
























