Code Signing – a fundamental way to secure innovation
Software is increasingly becoming the target of cyber-crime, being maliciously altered or falsified in pursuit of fraudulent or even terroristic objectives. A single breach in this ‘chain of trust’ can put an entire business at risk, resulting in loss of revenue and the need to rebuild trust with customers, partners, and investors.
Within a DevOp environment, teams may produce more machine identities than the rest of the organization combined. Software developers and distributors are therefore recommended to code-sign their software to protect end users and the reputation of the business. Digitally ‘signing’ the file that is to be distributed provides proof that the code has not been tampered with and that it is coming from a known source.
HSM-based code signing is the most secure way to physically and digitally secure code.