ISC2 Certified in Cybersecurity (CC)Security PrinciplesHard

A software developer signs a digitally signed code module before releasing it to production. This signature allows anyone to verify that the code has not been altered since it was signed and confirms the identity of the developer. Which security principle is primarily enforced by this digital signature process?

  1. AAvailability
  2. BConfidentiality
  3. CAccess Control
  4. DNon-repudiation
Show answer & explanation

Correct answer: D. Non-repudiation

Non-repudiation provides undeniable proof that a specific action or event has occurred and that a specific individual or entity performed it. A digital signature on a code module serves as proof that the developer signed it and that it hasn't been tampered with, preventing them from denying their actions.

Why the other options are wrong

  • A. Availability ensures systems are accessible, which is unrelated to digital signatures.
  • B. Confidentiality protects against unauthorized disclosure, which is not the primary function of a digital signature.
  • C. Access Control manages who can access resources, while a digital signature verifies integrity and origin.

Non-repudiation

The assurance that someone cannot deny the validity of something (e.g., an action, a message) they have done or said.

  • Prevents individuals from falsely denying having performed an action.
  • Often implemented using digital signatures and cryptographic hashes.
  • Critical for legal enforceability and accountability in digital transactions.

Memory trick: CIA are the basics, Non-repudiation proves who did it.

More Security Principles questions