A Guide to an Effective code and Software Signing Policy

Code signing is a critical step in the process of building and protecting software—but many developer and engineering teams struggle with implementing consistent signing practices, largely because there’s a misconception that signing that interferes with the time-to-market goals of agile development practices.

This guide will help you formulate a strategy that combines software, process, and policy to achieve end-to-end security in your signing practices. To create this guide, we surveyed and interviewed dozens of DevOps experts, team leads, and software security professionals. Hailing from organizations of different sizes, industries, and geographies, these experts helped us build a useful signing baseline that can be applied to virtually any software development team in any organization.

Subscribe to the Developer Insider Newsletter

From the hottest programming languages to commentary on the Linux OS, get the developer and open source news and tips you need to know. Delivered Tuesdays and Thursdays

Subscribe to the Developer Insider Newsletter

From the hottest programming languages to commentary on the Linux OS, get the developer and open source news and tips you need to know. Delivered Tuesdays and Thursdays

Resource Details

DigiCert logo
Provided by:
DigiCert
Topic:
Software
Format:
PDF