Skip to main content
Image coming soon

Broader Oversight Across Software Supply Chain Controls with SLSA

$199.00
Adding to cart… The item has been added

A tailored course, built for your situation

Broader Oversight Across Software Supply Chain Controls with SLSA

Strengthen authority in current role by owning verifiable software integrity frameworks

$199 one-time
24-hour access provisioning 30-day money-back guarantee Hand-built implementation playbook
12 modules. 12 chapters per module. 144 chapters total.
12 modules, each with 12 chapters (144 chapters total), text-based, plus downloadable templates and a hand-built implementation playbook delivered alongside course access.

Who this is for

Senior data practitioner in a high-velocity software environment leading or influencing software supply chain governance

Who this is not for

Individuals focused solely on application development or infrastructure engineering without data or governance responsibilities

What you walk away with

  • Own end-to-end SLSA framework deployment for internal projects
  • Lead vendor validation workflows with documented provenance requirements
  • Directly influence audit scope by shaping attestation artefacts
  • Establish standardised review cycles for software bill of materials (SBOM) integration
  • Gain recognition as primary decision owner in software integrity sign-offs

The 12 modules (with all 144 chapters)

Module 1. Understanding SLSA Framework Layers
Break down SLSA into actionable tiers with real-world implementation benchmarks across continuous integration systems.
12 chapters in this module
  1. What SLSA solves in modern pipelines
  2. Tier 0 vs Tier 1 build integrity
  3. Provenance generation basics
  4. Build platform trust boundaries
  5. Signing artefacts with transparency logs
  6. Metadata collection standards
  7. Example: Google's internal rollout
  8. Attestation format fundamentals
  9. Role of timestamp authorities
  10. Dependency verification scope
  11. Integration with CI triggers
  12. Common missteps in Tier assignment
Module 2. Mapping SLSA to Data Science Workflows
Adapt SLSA principles to data pipeline instrumentation, model packaging, and experiment reproducibility.
12 chapters in this module
  1. Containerising model training jobs
  2. Tracking dataset lineage under SLSA
  3. Signing model checkpoints
  4. Reproducibility as build integrity
  5. Metadata capture in Jupyter environments
  6. Versioning data transformations
  7. Secure artifact storage integration
  8. Audit trail completeness
  9. Integrating with internal registry
  10. Policy enforcement at merge
  11. Automated provenance capture
  12. Cross-team data trust
Module 3. Designing SLSA Compliance Controls
Build compliance-ready frameworks that align with NIST SSDF and support future audit requirements.
12 chapters in this module
  1. Mapping controls to SLSA tiers
  2. Evidence collection workflow
  3. Internal audit coordination
  4. Control ownership assignment
  5. Policy documentation standards
  6. Tracking control effectiveness
  7. Cross-functional ownership
  8. Version control for policies
  9. Automation thresholds
  10. Exception handling process
  11. Reporting completeness
  12. Review cycle cadence
Module 4. Provenance Generation at Scale
Implement consistent, automated provenance capture across repositories and build systems.
12 chapters in this module
  1. Integrating slsa-gen in CI
  2. Configuring build metadata
  3. Signing with fulcio
  4. Rekor transparency log use
  5. Handling multi-stage builds
  6. Metadata schema standards
  7. Provenance file structure
  8. Validating builder identity
  9. Secure key management
  10. Timestamping with rekor
  11. Logging to transparency servers
  12. Verification script templates
Module 5. Attestation and Verification Workflows
Define and enforce verification gates for third-party components and internal releases.
12 chapters in this module
  1. Types of attestations
  2. Creating SLSA attestations
  3. Storing in transparency logs
  4. Querying rekor for proofs
  5. Validating external binaries
  6. Policy engine integration
  7. Violation alerting
  8. Automated quarantine rules
  9. Manual override process
  10. Third-party attestation review
  11. Cross-signing frameworks
  12. Verification dashboard design
Module 6. Vendor and Third-Party Integration Governance
Extend SLSA oversight to external dependencies and open source components.
12 chapters in this module
  1. Vendor attestation requirements
  2. Onboarding checklist
  3. SBOM format compatibility
  4. Dependency scanning integration
  5. Trusted repository sourcing
  6. Open source license checks
  7. Security finding triage
  8. Patch compliance SLAs
  9. Escalation paths for gaps
  10. Risk-based acceptance criteria
  11. Supplier communication templates
  12. Periodic reassessment
Module 7. Internal Audit and Reporting Alignment
Shape internal audit scope by producing complete, verifiable compliance packages.
12 chapters in this module
  1. Audit evidence mapping
  2. SLSA tier achievement reports
  3. Provenance trail completeness
  4. Attestation log exports
  5. Timestamp validation records
  6. Toolchain configuration logs
  7. Access control snapshots
  8. Policy enforcement proof
  9. Remediation tracking
  10. Executive summary templates
  11. Cross-team sign-off workflow
  12. Audit response coordination
Module 8. Policy Design for Automated Enforcement
Develop policies that are machine-enforceable and reduce manual review burden.
12 chapters in this module
  1. Writing Rego for SLSA
  2. Gatekeeper integration
  3. Policy decision points
  4. Violation severity levels
  5. Automated blocking rules
  6. Exception request workflow
  7. Policy review cycle
  8. Versioning policies
  9. Testing framework setup
  10. Policy drift detection
  11. Rollout to staging
  12. Monitoring false positives
Module 9. Cross-Team Adoption and Change Management
Lead organisational rollout with clear communication, training, and feedback loops.
12 chapters in this module
  1. Identifying early adopters
  2. Team-specific onboarding
  3. Documentation standards
  4. Training session design
  5. Feedback collection process
  6. Champion network setup
  7. Milestone tracking
  8. Adoption metrics
  9. Leadership update rhythm
  10. Success story sharing
  11. Obstacle logging
  12. Iteration planning
Module 10. Threat Modeling for Supply Chain Risks
Identify and prioritise threats specific to software provenance and build integrity.
12 chapters in this module
  1. Common attack vectors
  2. Build system compromise
  3. Dependency confusion
  4. Signed artefact spoofing
  5. Private key exposure
  6. Transparency log manipulation
  7. Replay attacks
  8. MITRE ATT CK mapping
  9. Threat scenario weightings
  10. Likelihood vs impact scoring
  11. Control gap analysis
  12. Response playbook creation
Module 11. Metrics and Continuous Improvement
Track progress, identify bottlenecks, and refine implementation over time.
12 chapters in this module
  1. Adoption rate tracking
  2. Provenance coverage metric
  3. Attestation completeness
  4. Failed build rate
  5. Policy violation trends
  6. Audit finding recurrence
  7. Mean time to remediate
  8. Team feedback scores
  9. Toolchain stability
  10. Automation coverage
  11. Incident post-mortems
  12. Quarterly improvement plan
Module 12. Sustaining SLSA in Evolving Environments
Maintain framework relevance as toolchains, teams, and threats evolve.
12 chapters in this module
  1. Handling new programming languages
  2. Adapting to cloud shifts
  3. Updating policies for scale
  4. Onboarding new teams
  5. External framework alignment
  6. Version upgrade planning
  7. Deprecation process
  8. Knowledge retention
  9. Succession planning
  10. External contributor support
  11. Community engagement
  12. Long-term roadmap integration

How this maps to your situation

  • Implementing SLSA in a data science environment
  • Leading cross-functional software integrity initiative
  • Responding to increasing audit scrutiny
  • Shaping vendor governance standards

Before vs. after

Before
Limited authority over software supply chain decisions despite technical expertise
After
Direct oversight on SLSA implementation, provenance standards, and attestation workflows

What's included with your purchase

  • 12 modules with 12 chapters each (144 chapters)
  • Downloadable templates and worked examples for every module
  • Hand-built implementation playbook delivered alongside course access
  • 30-day money-back guarantee

Delivery and format

  • Course and learning environment access provisioned within 24 hours of purchase
  • Hand-built implementation playbook delivered alongside course access

Format: Text-based modules and chapters in the Art of Service learning environment, plus downloadable templates and worked examples for every chapter, plus the hand-built implementation playbook delivered alongside course access.

Time investment: Approximately 3 hours per module, designed to be completed alongside regular work over 6 weeks.

How this compares to the alternatives

Unlike generic security or compliance courses, this programme focuses specifically on expanding decision rights in software supply chain governance through SLSA framework mastery, directly increasing scope of control in current roles.

Frequently asked

Who is this course for?
Senior data scientists and technical leads influencing software supply chain integrity, especially where provenance and auditability matter.
How is the course structured?
12 modules, each containing 12 chapters (144 chapters total).
Does this course cover SBOM or NIST SSDF?
Yes, SBOM integration and alignment with NIST SSDF are covered as complementary practices to SLSA implementation.
$199 one-time. Approximately 3 hours per module, designed to be completed alongside regular work over 6 weeks..

Within 24 hours your account in the learning environment is provisioned and the tailored implementation playbook is delivered alongside it.

30-day money-back guarantee· 144 chapters· Hand-built playbook included· Account access within 24 hours