CompTIA SecurityX (CAS-005)Security ArchitectureMedium
A security architect is designing a secure software supply chain for a critical aerospace system. The company needs to ensure that all software components (libraries, modules, binaries) used in the system originate from trusted sources, have not been tampered with, and can be verified at any point in their lifecycle. Which security mechanism is most effective for providing verifiable authenticity and integrity of these software components?
- AVersion Control Systems
- BDigital Signatures
- CFirewall Rules
- DChecksums
Show answer & explanationAnswer & explanation
Correct answer: B. Digital Signatures
Digital signatures use asymmetric cryptography to provide both authenticity (proving the origin of the software component) and integrity (ensuring it hasn't been tampered with since being signed). A trusted third party (Certificate Authority) typically issues the signing certificate, allowing for verifiable trust in the supply chain.
Why the other options are wrong
- A. Version control systems manage code changes but don't inherently provide cryptographic authenticity or integrity protection against malicious modifications post-commit/release.
- C. Firewall rules control network traffic but are unrelated to verifying the authenticity and integrity of software components themselves.
- D. Checksums provide integrity verification but do not confirm the origin (authenticity) of the software component.
Digital Signatures
A mathematical scheme for demonstrating the authenticity of digital messages or documents. A valid digital signature gives a recipient reason to believe that the message was created by a known sender (authenticity) and was not altered in transit (integrity).
- Provides authenticity (origin verification).
- Provides integrity (non-tampering verification).
- Uses asymmetric cryptography (private key to sign, public key to verify).
- Crucial for software supply chain security.
Memory trick: Digital Signatures are like a tamper-proof seal and a trusted sender's mark on your software package.