A tailored course, built for your situation
Deeper command of the SLSA framework from implementation to enforcement
Build verifiable software supply chain integrity with precision and confidence
The situation this course is for
Teams are expected to validate software origin, but tooling generates fragmented, incomplete provenance. Without command of SLSA levels and attestation policies, audits become reactive and trust remains unverifiable.
Who this is for
Senior compliance or security engineer working in a product-driven tech environment with exposure to third-party code, CI/CD pipelines, and audit demands for software provenance
Who this is not for
Junior developers new to DevOps, or executives seeking only high-level summaries of software supply chain risk
What you walk away with
- Generate complete SLSA Level 3 artefacts for internal and external builds
- Enforce attestation policies across CI/CD stages with confidence
- Automate provenance collection with verifiable signatures and traceable metadata
- Respond to vendor review requests with auditable, standard-aligned outputs
- Own the technical narrative in software integrity discussions across security and engineering teams
The 12 modules (with all 144 chapters)
- What SLSA solves in software provenance
- SLSA vs SBOM vs in-toto: distinct roles
- Overview of SLSA levels 0 to 4
- The role of metadata in trusted builds
- SLSA and NIST SSDF alignment
- Key components: provenance, integrity, verifiability
- The meaning of 'software attestations'
- Source repository security as a baseline
- Build platform trust requirements
- Provenance format specifications
- SLSA as a compliance enabler
- How SLSA reduces audit effort
- Secure source repository setup
- Branch protection rules
- Access control policies
- Code ownership sign-offs
- Immutable commit history
- Timestamping source snapshots
- Detecting unauthorized changes
- Integration with identity providers
- Logging source actions
- Guardrails for pull requests
- Source transparency for vendors
- Auditing source integrity
- Build environment isolation
- Dedicated build service accounts
- Immutable build images
- Dependency pinning
- Reproducibility requirements
- Build timestamp sync
- Secure credential handling
- Network restrictions
- Build metadata capture
- Enforcing clean build states
- Signed build configuration
- Monitoring for drift
- Provenance JSON structure
- Signing with trusted keys
- Attestation formats
- Recording input materials
- Environment metadata
- Output artefact references
- Timestamps and integrity checks
- Integrating with build tools
- Automating provenance generation
- Handling multi-stage builds
- Provenance verification steps
- Fixing incomplete provenance
- Attestation vs provenance
- Signing build steps
- Code review attestations
- Policy check verification
- Vulnerability scan attestations
- Generating SLSA attestations
- Chaining attestations
- Using Fulcio for signing
- Integration with Sigstore
- Attestation storage
- Verification workflows
- Attestation expiry
- Defining level thresholds
- Level 1: basic provenance
- Level 2: tamper resistance
- Level 3: reproducibility
- Level 4: two-person reviews
- Auditing against levels
- Gap assessment process
- Vendor SLSA compliance
- Internal certification process
- Reporting for audits
- Continuous monitoring
- Roadmap to higher levels
- Assessing vendor SLSA support
- Provenance verification
- Checking attestation signatures
- Validating build integrity
- Trusted repository integration
- Handling unsigned builds
- Vendor questionnaires
- Automated validation scripts
- Scoring vendor maturity
- Escalation paths
- Documentation for compliance
- Reporting to security teams
- CI/CD pipeline stages
- Automated provenance signing
- Attestation gates
- Policy enforcement points
- Failure handling
- Logging for audits
- Integration with GitHub Actions
- GitLab CI compatibility
- Jenkins plugin setup
- Monitoring pipeline health
- Re-triggering builds
- Secure key management
- Defining policy rules
- Using Rego with OPA
- Provenance format validation
- Signature verification rules
- Attestation checks
- Build environment policies
- Automated policy evaluation
- Generating policy reports
- Remediation workflows
- Policy versioning
- Integration with CI/CD
- Audit log integration
- Audit preparation checklist
- Provenance as evidence
- Attestation review process
- Generating audit reports
- Responding to auditor questions
- Internal compliance dashboards
- Cross-team reporting
- Evidence retention
- Version comparisons
- Remediation tracking
- Audit feedback loop
- Continuous compliance
- AWS CodeBuild integration
- Google Cloud Build provenance
- Azure Pipeline support
- Cloud key management
- Federated identity setup
- Cross-cloud provenance format
- Monitoring consistency
- Vendor-specific tooling
- Standardizing outputs
- Handling regional builds
- Multi-cloud audit readiness
- Unified logging approach
- Identifying pilot teams
- Stakeholder alignment
- Training development
- Internal documentation
- Feedback collection
- Scaling to new products
- Governance committee setup
- Metrics for success
- Roadmap development
- External benchmarking
- Sharing best practices
- Maintaining momentum
How this maps to your situation
- Starting first internal SLSA implementation
- Responding to vendor software with incomplete provenance
- Preparing for audit with new software integrity requirements
- Leading cross-functional software supply chain initiative
Before vs. after
What's included with your purchase
- 12 modules with 12 chapters each (144 chapters)
- Downloadable templates and worked examples for every module
- Hand-built implementation playbook delivered alongside course access
- 30-day money-back guarantee
Delivery and format
- Course and learning environment access provisioned within 24 hours of purchase
- Hand-built implementation playbook delivered alongside course access
Format: Text-based modules and chapters in the Art of Service learning environment, plus downloadable templates and worked examples for every chapter, plus the hand-built implementation playbook delivered alongside course access.
Time investment: Approximately 3-4 hours per module, designed for completion over 6-8 weeks with hands-on application.
How this compares to the alternatives
Unlike generic security courses, this program delivers precise SLSA implementation guidance with real-world templates and enforcement strategies tailored to engineering and compliance teams.
Frequently asked
Within 24 hours your account in the learning environment is provisioned and the tailored implementation playbook is delivered alongside it.