ISC2 CISSP (Certified Information Systems Security Professional)Asset SecurityHard

A software development company is implementing a new policy for handling source code, which is considered highly proprietary. The policy states that all source code files must be digitally signed by the developer upon check-in to the version control system and that an automated scan must verify the signature's validity before the code can be accepted into the main branch. Which security objective is this policy primarily designed to enforce?

  1. AConfidentiality
  2. BAvailability
  3. CIntegrity
  4. DNon-repudiation
Show answer & explanation

Correct answer: D. Non-repudiation

While digital signatures contribute to integrity (by detecting alteration) and potentially confidentiality (if used with encryption), their primary purpose in this scenario, especially with the 'signed by the developer' and 'verify the signature's validity' clauses, is to establish non-repudiation. This ensures that the developer cannot deny having performed the check-in, linking them undeniably to the action.

Why the other options are wrong

  • A. Confidentiality protects against unauthorized disclosure.
  • B. Availability ensures access to data or systems when needed.
  • C. Integrity ensures data has not been altered, but non-repudiation goes further by proving who made the change.

Non-repudiation

A security objective that ensures an individual or entity cannot deny the authenticity of their signature on a document or the sending of a message.

  • Often achieved using digital signatures.
  • Proves origin and integrity of data/action.
  • Prevents false denials of involvement.

Memory trick: CIA Protects, Non-Repudiation Connects.

More Asset Security questions