問題文
An asset review asks what sits on a developer's own machine and what has to be put around it. Which pair of answers does NIST SP 800-204D give?
選択肢
- Source code, credentials and access to sensitive material such as signing keys sit there, and the firm has to name its critical assets, then put access control, multi-factor authentication and encryption around them, in that desk-side inventory.
- Just the working copy of the code sits there, with the secrets left in the pipeline vault, and the firm has to name its critical assets, then put access control, multi-factor authentication and encryption around them and their backups, in that desk-side inventory.
- Source code, credentials and access to sensitive material such as signing keys sit there, and the firm has to move that material onto a hardened build-side server that developers reach through a thin client and nothing else, in that desk-side inventory.
- Just the working copy of the code sits there, with the secrets left in the pipeline vault, and the firm has to move that material onto a hardened build-side server and its vault that developers reach through a thin client and nothing else, in that desk-side inventory.