A tailored course, built for your situation
Broader Oversight Across Software Supply Chain Controls with SLSA
Strengthen authority in current role by owning verifiable software integrity frameworks
Who this is for
Senior data practitioner in a high-velocity software environment leading or influencing software supply chain governance
Who this is not for
Individuals focused solely on application development or infrastructure engineering without data or governance responsibilities
What you walk away with
- Own end-to-end SLSA framework deployment for internal projects
- Lead vendor validation workflows with documented provenance requirements
- Directly influence audit scope by shaping attestation artefacts
- Establish standardised review cycles for software bill of materials (SBOM) integration
- Gain recognition as primary decision owner in software integrity sign-offs
The 12 modules (with all 144 chapters)
- What SLSA solves in modern pipelines
- Tier 0 vs Tier 1 build integrity
- Provenance generation basics
- Build platform trust boundaries
- Signing artefacts with transparency logs
- Metadata collection standards
- Example: Google's internal rollout
- Attestation format fundamentals
- Role of timestamp authorities
- Dependency verification scope
- Integration with CI triggers
- Common missteps in Tier assignment
- Containerising model training jobs
- Tracking dataset lineage under SLSA
- Signing model checkpoints
- Reproducibility as build integrity
- Metadata capture in Jupyter environments
- Versioning data transformations
- Secure artifact storage integration
- Audit trail completeness
- Integrating with internal registry
- Policy enforcement at merge
- Automated provenance capture
- Cross-team data trust
- Mapping controls to SLSA tiers
- Evidence collection workflow
- Internal audit coordination
- Control ownership assignment
- Policy documentation standards
- Tracking control effectiveness
- Cross-functional ownership
- Version control for policies
- Automation thresholds
- Exception handling process
- Reporting completeness
- Review cycle cadence
- Integrating slsa-gen in CI
- Configuring build metadata
- Signing with fulcio
- Rekor transparency log use
- Handling multi-stage builds
- Metadata schema standards
- Provenance file structure
- Validating builder identity
- Secure key management
- Timestamping with rekor
- Logging to transparency servers
- Verification script templates
- Types of attestations
- Creating SLSA attestations
- Storing in transparency logs
- Querying rekor for proofs
- Validating external binaries
- Policy engine integration
- Violation alerting
- Automated quarantine rules
- Manual override process
- Third-party attestation review
- Cross-signing frameworks
- Verification dashboard design
- Vendor attestation requirements
- Onboarding checklist
- SBOM format compatibility
- Dependency scanning integration
- Trusted repository sourcing
- Open source license checks
- Security finding triage
- Patch compliance SLAs
- Escalation paths for gaps
- Risk-based acceptance criteria
- Supplier communication templates
- Periodic reassessment
- Audit evidence mapping
- SLSA tier achievement reports
- Provenance trail completeness
- Attestation log exports
- Timestamp validation records
- Toolchain configuration logs
- Access control snapshots
- Policy enforcement proof
- Remediation tracking
- Executive summary templates
- Cross-team sign-off workflow
- Audit response coordination
- Writing Rego for SLSA
- Gatekeeper integration
- Policy decision points
- Violation severity levels
- Automated blocking rules
- Exception request workflow
- Policy review cycle
- Versioning policies
- Testing framework setup
- Policy drift detection
- Rollout to staging
- Monitoring false positives
- Identifying early adopters
- Team-specific onboarding
- Documentation standards
- Training session design
- Feedback collection process
- Champion network setup
- Milestone tracking
- Adoption metrics
- Leadership update rhythm
- Success story sharing
- Obstacle logging
- Iteration planning
- Common attack vectors
- Build system compromise
- Dependency confusion
- Signed artefact spoofing
- Private key exposure
- Transparency log manipulation
- Replay attacks
- MITRE ATT CK mapping
- Threat scenario weightings
- Likelihood vs impact scoring
- Control gap analysis
- Response playbook creation
- Adoption rate tracking
- Provenance coverage metric
- Attestation completeness
- Failed build rate
- Policy violation trends
- Audit finding recurrence
- Mean time to remediate
- Team feedback scores
- Toolchain stability
- Automation coverage
- Incident post-mortems
- Quarterly improvement plan
- Handling new programming languages
- Adapting to cloud shifts
- Updating policies for scale
- Onboarding new teams
- External framework alignment
- Version upgrade planning
- Deprecation process
- Knowledge retention
- Succession planning
- External contributor support
- Community engagement
- Long-term roadmap integration
How this maps to your situation
- Implementing SLSA in a data science environment
- Leading cross-functional software integrity initiative
- Responding to increasing audit scrutiny
- Shaping vendor governance standards
Before vs. after
What's included with your purchase
- 12 modules with 12 chapters each (144 chapters)
- Downloadable templates and worked examples for every module
- Hand-built implementation playbook delivered alongside course access
- 30-day money-back guarantee
Delivery and format
- Course and learning environment access provisioned within 24 hours of purchase
- Hand-built implementation playbook delivered alongside course access
Format: Text-based modules and chapters in the Art of Service learning environment, plus downloadable templates and worked examples for every chapter, plus the hand-built implementation playbook delivered alongside course access.
Time investment: Approximately 3 hours per module, designed to be completed alongside regular work over 6 weeks.
How this compares to the alternatives
Unlike generic security or compliance courses, this programme focuses specifically on expanding decision rights in software supply chain governance through SLSA framework mastery, directly increasing scope of control in current roles.
Frequently asked
Within 24 hours your account in the learning environment is provisioned and the tailored implementation playbook is delivered alongside it.