A tailored course, built for your situation
Mastering SLSA for Software Supply Chain Governance Practitioners
Build verifiable, enterprise-grade software integrity with SLSA frameworks that scale across distributed toolchains
The situation this course is for
As software supply chain regulations tighten, teams struggle to prove build integrity without manual, error-prone processes. Without standardized provenance, even compliant pipelines face scrutiny during audits.
Who this is for
Software supply chain governance professionals in tech-first enterprises implementing SLSA, SBOM, or zero-trust build standards
Who this is not for
Developers focused solely on application code, not build infrastructure or compliance traceability
What you walk away with
- Generate SLSA Level 3+ compliant provenance for any CI/CD pipeline
- Map build environments to SLSA attestation requirements with confidence
- Lead internal reviews on software integrity with reference-quality documentation
- Translate technical build controls into audit-ready narratives
- Serve as the go-to resolver for cross-functional SLSA escalations
The 12 modules (with all 144 chapters)
- What SLSA aims to solve
- Key stakeholders in SLSA adoption
- SLSA vs regulatory expectations
- The four SLSA levels explained
- When to apply SLSA in the SDLC
- Integration with DevOps culture
- Common misconceptions about SLSA
- SLSA and zero-trust principles
- Relation to NIST SSDF
- Role of automation in SLSA
- Audit expectations by level
- Real-world SLSA implementations
- Defining a hermetic build
- Controlling build inputs
- Isolating build environments
- Versioning build tools
- Managing dependency chains
- Secure credential handling
- Build metadata standards
- Immutable build logs
- Build worker trust model
- Container integrity checks
- Language-specific build risks
- Baseline for Level 1
- What constitutes provenance
- In-toto attestation format
- Signing build outputs
- Timestamping with RFC 3161
- Linking source to build config
- Including environment details
- Metadata schema design
- Automating provenance capture
- Validating third-party provenance
- Storing provenance securely
- Human-readable summaries
- Provenance lifecycle management
- Two-person review patterns
- Separation of duties in CI
- Approval workflows for builds
- Verified merge request process
- Provenance signing keys
- Key rotation policies
- Audit trail completeness
- Toolchain access logs
- Immutable storage for attestations
- Verifiable timestamps
- Evidence retention period
- Internal validation checklist
- Deterministic build definition
- Removing build time variation
- Container base image control
- Minimal build environments
- Hardened worker security
- Network egress controls
- Immutable infrastructure
- Signed build environment images
- Remote attestation use cases
- Zero-standing privileges in CI
- Cross-repo build isolation
- Path to Level 4
- CI platform trust model
- GitHub Actions provenance
- GitLab CI integration
- Jenkins attestation plugin
- Argo Workflows setup
- Tekton with SLSA
- Custom pipeline instrumentation
- Monitoring build attestations
- Handling pipeline failures
- Rebuild policies
- Multi-stage verification
- Pipeline drift detection
- Using slsa-verifier tool
- Policy-based verification
- Keyless signing validation
- Fulcio and Rekor integration
- Checking provenance format
- Signature chain validation
- Timestamp authority checks
- Automated compliance gates
- Manual review protocols
- Third-party validation readiness
- Common validation failures
- Audit walkthrough preparation
- Mapping SLSA to SOX controls
- FDA software validation overlap
- NIST CSF alignment
- HIPAA build environment rules
- Financial sector expectations
- Government procurement standards
- Export control implications
- Third-party vendor assessments
- Supply chain due diligence
- Internal audit coordination
- Regulator-facing documentation
- Cross-border data flows
- Executive summary templates
- Risk narrative for leadership
- Legal team alignment
- Security team collaboration
- Developer onboarding plan
- Audit team support
- Vendor communication playbook
- Incident response integration
- Training for non-technical roles
- Metrics for progress tracking
- Roadmap presentation
- FAQ for internal rollout
- Centralized policy enforcement
- Template-based adoption
- Automated onboarding flow
- Cross-team governance model
- Standardized tooling
- Version control strategy
- Monitoring compliance at scale
- Feedback loops for improvement
- Documentation standards
- Change management process
- Leadership alignment
- Success measurement
- Sigstore keyless signing
- Fulcio identity integration
- Rekor transparency log use
- Cosign for attestations
- Bazel and SLSA
- Reproducible Java builds
- Go build determinism
- Python packaging challenges
- Container rebuild verification
- Binary diffing for validation
- Automated compliance bots
- Policy as code frameworks
- SLSA maturity model
- Self-assessment tool
- Gap analysis method
- Prioritization framework
- Roadmap planning
- Emerging standards overlap
- DORA metrics correlation
- Vendor ecosystem trends
- OpenSSF collaboration
- Contribution opportunities
- Training program design
- Long-term sustainability
How this maps to your situation
- After first audit findings on build provenance
- When onboarding regulated clients
- Before scaling CI/CD pipeline usage
- During vendor security assessments
Before vs. after
What's included with your purchase
- 12 modules with 12 chapters each (144 chapters total)
- Downloadable templates and worked examples for every module
- Hand-built implementation playbook delivered alongside course access
- 30-day money-back guarantee
Delivery and format
- Course and learning environment access provisioned within 24 hours of purchase
- Hand-built implementation playbook delivered alongside course access
Format: Text-based modules and chapters in the Art of Service learning environment, plus downloadable templates and worked examples for every chapter, plus the hand-built implementation playbook delivered alongside course access.
Time investment: Approximately 3 hours per module, with self-paced access and lifetime updates.
How this compares to the alternatives
Unlike generic DevSecOps courses, this program delivers SLSA-specific implementation patterns used by leading tech firms, with direct applicability to regulated software delivery.
Frequently asked
Within 24 hours your account in the learning environment is provisioned and the tailored implementation playbook is delivered alongside it.