Skip to main content
Image coming soon

Influence across more engineering teams with SLSA

$199.00
Adding to cart… The item has been added

What is the Influence across more engineering teams course about?

Engineers build fast, but assurance workflows lag. Frameworks get treated as compliance checkboxes rather than enablers of velocity and trust. Without clear implementation paths, SLSA stays siloed, even when the need is organization-wide.

What situation is the Influence across more engineering teams for?

Engineers build fast, but assurance workflows lag. Frameworks get treated as compliance checkboxes rather than enablers of velocity and trust. Without clear implementation paths, SLSA stays siloed, even when the need is organization-wide.

Who is the Influence across more engineering teams course for?

Senior software engineer or platform builder driving secure software delivery at scale, working across domains with growing responsibility for supply chain integrity and cross-team alignment.

What do you take away from the Influence across more engineering teams course?

Apply SLSA Level 3+ controls consistently across repositories and build systems Produce signed, verifiable build attestations that integrate with existing CI/CD Lead cross-team alignment on artifact provenance without central mandates Document implementation decisions that survive team rotation and scale Position yourself as the go-to practitioner when new services require SLSA adoption.

How does this map to your situation?

After rolling out SLSA in one team When onboarding new services to the standard During audit preparation cycles When security incidents raise scrutiny on build systems.

What's included with your purchase?

12 modules with 12 chapters each (144 chapters) Downloadable templates and worked examples for every module Hand-built implementation playbook delivered alongside course access 30-day money-back guarantee.

What does the Influence across more engineering teams cover on delivery and format?

Format: Text-based modules and chapters in the Art of Service learning environment, plus downloadable templates and worked examples for every chapter, plus the hand-built implementation playbook delivered alongside course access. Time investment: Approximately 3-4 hours per module, designed to be consumed incrementally alongside regular work.

How does this compare to the alternatives?

Unlike generic security courses, this is built for engineers who ship code at scale. Compared to vendor-led training, it's independent, implementation-focused, and designed to create influence across teams, not just pass a certification.

Closely related courses: More Defensible Financial Outputs with SLSA, Influence across more business units with SLSA, More Defensible Software Supply Chain Outputs with SLSA.

More answers: what you get with every course, refund policy, all help answers.

A tailored course, built for your situation

Influence across more engineering teams with SLSA

Build trusted software supply chains that scale across domains and elevate your role

$199 one-time
24-hour access provisioning 30-day money-back guarantee Hand-built implementation playbook
12 modules. 12 chapters per module. 144 chapters total.
12 modules, each with 12 chapters (144 chapters total), text-based, plus downloadable templates and a hand-built implementation playbook delivered alongside course access.
Frustration when security standards stall at team boundaries

The situation this course is for

Engineers build fast, but assurance workflows lag. Frameworks get treated as compliance checkboxes rather than enablers of velocity and trust. Without clear implementation paths, SLSA stays siloed, even when the need is organization-wide.

Who this is for

Senior software engineer or platform builder driving secure software delivery at scale, working across domains with growing responsibility for supply chain integrity and cross-team alignment

Who this is not for

Entry-level developers, compliance auditors without engineering context, or executives seeking high-level overviews

What you walk away with

  • Apply SLSA Level 3+ controls consistently across repositories and build systems
  • Produce signed, verifiable build attestations that integrate with existing CI/CD
  • Lead cross-team alignment on artifact provenance without central mandates
  • Document implementation decisions that survive team rotation and scale
  • Position yourself as the go-to practitioner when new services require SLSA adoption

The 12 modules (with all 144 chapters)

Module 1. Why SLSA is becoming the baseline for trusted services
Understand how recent shifts in supply chain attacks and regulatory scrutiny make SLSA adoption inevitable, and how early adopters gain influence before mandates arrive.
12 chapters in this module
  1. The Log4j effect on software assurance
  2. Google's internal shift to SLSA
  3. How Atlassian-scale systems face higher scrutiny
  4. SLSA vs SBOM: what each solves
  5. Where NIST SSDF aligns with SLSA
  6. The cost of retrofitting trust
  7. Regulator focus on build integrity
  8. Vendor pressure to prove provenance
  9. Developer resistance patterns
  10. Winning early buy-in from peers
  11. Case: First cloud service to achieve SLSA 3
  12. Key decision: When to upgrade from Level 2
Module 2. Mapping SLSA to your current stack
Adapt SLSA requirements to your repository structure, CI pipelines, and deployment gates, without overhauling existing systems.
12 chapters in this module
  1. Identifying high-risk repos for SLSA 3
  2. Build system compatibility matrix
  3. What 'reproducible build' really means
  4. Signing without breaking CI speed
  5. Attestation storage patterns
  6. Metadata retention policies
  7. Mapping controls to JFrog or Artifactory
  8. Handling legacy services
  9. Version branching strategies
  10. Dependency freeze workflows
  11. Approval gate integration
  12. Documentation trail for auditors
Module 3. Designing for automatic verification
Shift from manual checks to self-validating systems that enforce SLSA compliance by default, reducing toil and drift.
12 chapters in this module
  1. Automated SLSA level detection
  2. Slack alerts for non-compliant builds
  3. Enforcement at pull request stage
  4. CI pipeline health dashboard
  5. Golden image validation
  6. Binary origin verification
  7. SBOM generation triggers
  8. Attestation freshness checks
  9. Time-based signing windows
  10. Role-based attestation rights
  11. Auto-remediation for drift
  12. Audit readiness through automation
Module 4. Leading adoption without authority
Drive SLSA implementation across teams by building consensus, demonstrating value, and reducing friction.
12 chapters in this module
  1. Finding natural allies in SRE teams
  2. Pitching to tech leads without mandates
  3. Demonstrating reduced incident response time
  4. Showcasing compliance as velocity
  5. Internal documentation hubs
  6. Workshop format for rollout
  7. Handling pushback on build times
  8. Security as an enabler narrative
  9. Tracking adoption across squads
  10. Celebrating public SLSA 3 milestones
  11. Linking to promotion criteria
  12. Building a community of practice
Module 5. Generating audit-ready attestations
Produce tamper-proof, time-stamped, and cryptographically signed records that satisfy internal and external reviewers.
12 chapters in this module
  1. Choosing signing keys and rotation
  2. Timestamp authority integration
  3. In-toto attestation structure
  4. Metadata completeness checks
  5. Human-readable attestation summaries
  6. Machine-verifiable outputs
  7. Storing attestations durably
  8. Versioning across releases
  9. Attestation access controls
  10. Integrating with SIEM tools
  11. Preparing for surprise audits
  12. Common gaps in attestation logs
Module 6. Aligning SLSA with CI/CD pipelines
Integrate SLSA controls directly into build workflows to prevent non-compliant releases from propagating.
12 chapters in this module
  1. Pre-merge SLSA checks
  2. Build service identity setup
  3. Provenance generation at compile
  4. Signing step placement
  5. Keyless signing options
  6. Google Artifact Registry integration
  7. GitHub Actions compatibility
  8. Jenkins pipeline additions
  9. Error states and retries
  10. Logging attestation failures
  11. Pipeline speed impact mitigation
  12. Rollback procedures with attestations
Module 7. Securing build environments
Harden CI systems to meet SLSA Level 3+ requirements for build integrity and operator trust.
12 chapters in this module
  1. Principle of least privilege for build agents
  2. Immutable build containers
  3. Network isolation for CI
  4. Secrets management at scale
  5. Build environment checksums
  6. Operator MFA enforcement
  7. Session recording for audit
  8. Break-glass access controls
  9. Automated config drift detection
  10. Centralized build monitoring
  11. Incident response for build systems
  12. Recovery plan for compromised agents
Module 8. Managing dependencies with SLSA
Ensure third-party and open source components meet the same assurance bar as in-house code.
12 chapters in this module
  1. Trusted source list for dependencies
  2. Automated SBOM ingestion
  3. Dependency provenance checks
  4. Vetting public registry packages
  5. Approval workflows for new deps
  6. Binary vs source trust gap
  7. SLSA for transitive dependencies
  8. Minimum attestation level policy
  9. Handling unmaintained libraries
  10. Forking strategies for control
  11. Dependency freeze during audits
  12. Attestation gap reporting
Module 9. Scaling SLSA across regions and services
Adapt controls for global teams, data residency, and multi-cloud environments while maintaining consistency.
12 chapters in this module
  1. Regional compliance variations
  2. Data locality for attestations
  3. Multi-cloud build environments
  4. Cross-region signing policies
  5. Legal team coordination
  6. Export control considerations
  7. Incident response jurisdiction
  8. Language and documentation access
  9. Timezone-aware review gates
  10. Global service ownership models
  11. Central vs local enforcement
  12. Metrics for global adoption
Module 10. Documenting implementation for longevity
Create living artifacts that survive team changes and scale as new services adopt SLSA.
12 chapters in this module
  1. Runbook for SLSA onboarding
  2. Architecture decision records
  3. Visual workflow diagrams
  4. Policy exception process
  5. Training materials for new hires
  6. FAQ for common questions
  7. Versioned playbooks
  8. Internal certification process
  9. Feedback loop from audits
  10. Lessons learned aggregation
  11. Retention and archiving
  12. Handover package structure
Module 11. Responding to auditor queries
Answer questions confidently with documented systems, clear narratives, and verifiable outputs.
12 chapters in this module
  1. Top auditor questions about SLSA
  2. Preparing evidence packages
  3. Narrative for incomplete levels
  4. Gap justification templates
  5. Timeline of adoption proof
  6. Operator training verification
  7. Build environment walkthrough
  8. Attestation sampling method
  9. Third-party validation options
  10. Regulator communication prep
  11. Responding to non-compliance findings
  12. Turnaround time benchmarks
Module 12. Driving continuous improvement
Evolve your SLSA posture from compliance to competitive advantage through measurement, iteration, and visibility.
12 chapters in this module
  1. Defining maturity metrics
  2. SLSA level distribution dashboard
  3. Mean time to remediate gaps
  4. Adoption velocity tracking
  5. Feedback from incident response
  6. Benchmarking against peers
  7. Quarterly maturity review
  8. Roadmap for Level 4 adoption
  9. Internal recognition programs
  10. Sharing wins externally
  11. Contributing to open source tooling
  12. Mentoring next practitioners

How this maps to your situation

  • After rolling out SLSA in one team
  • When onboarding new services to the standard
  • During audit preparation cycles
  • When security incidents raise scrutiny on build systems

Before vs. after

Before
SLSA treated as a compliance hurdle, applied inconsistently, with limited cross-team recognition
After
You lead consistent adoption, produce verifiable attestations, and become the reference point across engineering

What's included with your purchase

  • 12 modules with 12 chapters each (144 chapters)
  • Downloadable templates and worked examples for every module
  • Hand-built implementation playbook delivered alongside course access
  • 30-day money-back guarantee

Delivery and format

  • Course and learning environment access provisioned within 24 hours of purchase
  • Hand-built implementation playbook delivered alongside course access

Format: Text-based modules and chapters in the Art of Service learning environment, plus downloadable templates and worked examples for every chapter, plus the hand-built implementation playbook delivered alongside course access.

Time investment: Approximately 3-4 hours per module, designed to be consumed incrementally alongside regular work.

If nothing changes
Continued fragmentation in software integrity practices leaves teams exposed to compromise and audit failure, while practitioners miss the chance to lead in a high-impact domain.

How this compares to the alternatives

Unlike generic security courses, this is built for engineers who ship code at scale. Compared to vendor-led training, it's independent, implementation-focused, and designed to create influence across teams, not just pass a certification.

Frequently asked

Do I need prior SLSA experience?
No. The course starts with practical context and builds to advanced implementation, ideal for engineers already working with CI/CD and supply chain security.
How is the course structured?
12 modules, each containing 12 chapters (144 chapters total).
Will this help me lead beyond my current team?
Yes. The course focuses on artifacts, communication, and patterns that build credibility and influence across domains.
$199 one-time. Approximately 3-4 hours per module, designed to be consumed incrementally alongside regular work..

Within 24 hours your account in the learning environment is provisioned and the tailored implementation playbook is delivered alongside it.

30-day money-back guarantee· 144 chapters· Hand-built playbook included· Account access within 24 hours