Skip to main content
Image coming soon

Deeper command of the SLSA framework from implementation to enforcement

$199.00
Adding to cart… The item has been added

A tailored course, built for your situation

Deeper command of the SLSA framework from implementation to enforcement

Build verifiable software supply chain integrity with precision and confidence

$199 one-time
24-hour access provisioning 30-day money-back guarantee Hand-built implementation playbook
12 modules. 12 chapters per module. 144 chapters total.
12 modules, each with 12 chapters (144 chapters total), text-based, plus downloadable templates and a hand-built implementation playbook delivered alongside course access.
Frustration with inconsistent provenance data across vendor builds

The situation this course is for

Teams are expected to validate software origin, but tooling generates fragmented, incomplete provenance. Without command of SLSA levels and attestation policies, audits become reactive and trust remains unverifiable.

Who this is for

Senior compliance or security engineer working in a product-driven tech environment with exposure to third-party code, CI/CD pipelines, and audit demands for software provenance

Who this is not for

Junior developers new to DevOps, or executives seeking only high-level summaries of software supply chain risk

What you walk away with

  • Generate complete SLSA Level 3 artefacts for internal and external builds
  • Enforce attestation policies across CI/CD stages with confidence
  • Automate provenance collection with verifiable signatures and traceable metadata
  • Respond to vendor review requests with auditable, standard-aligned outputs
  • Own the technical narrative in software integrity discussions across security and engineering teams

The 12 modules (with all 144 chapters)

Module 1. Understanding SLSA fundamentals
Define the SLSA framework, its purpose in modern software supply chains, and alignment with zero-trust principles. Learn how each SLSA level raises assurance and what that means for development and audit workflows.
12 chapters in this module
  1. What SLSA solves in software provenance
  2. SLSA vs SBOM vs in-toto: distinct roles
  3. Overview of SLSA levels 0 to 4
  4. The role of metadata in trusted builds
  5. SLSA and NIST SSDF alignment
  6. Key components: provenance, integrity, verifiability
  7. The meaning of 'software attestations'
  8. Source repository security as a baseline
  9. Build platform trust requirements
  10. Provenance format specifications
  11. SLSA as a compliance enabler
  12. How SLSA reduces audit effort
Module 2. Sourcing and securing origin
Establish secure source control practices that meet SLSA Level 1-2 requirements. Implement branch protection, access controls, and logging to ensure reproducibility and traceability from code commit to build trigger.
12 chapters in this module
  1. Secure source repository setup
  2. Branch protection rules
  3. Access control policies
  4. Code ownership sign-offs
  5. Immutable commit history
  6. Timestamping source snapshots
  7. Detecting unauthorized changes
  8. Integration with identity providers
  9. Logging source actions
  10. Guardrails for pull requests
  11. Source transparency for vendors
  12. Auditing source integrity
Module 3. Designing tamper-resistant build systems
Architect build environments that resist compromise and support reproducible builds. Implement separation of duties, secure dependencies, and hardened execution contexts for SLSA Level 2+ compliance.
12 chapters in this module
  1. Build environment isolation
  2. Dedicated build service accounts
  3. Immutable build images
  4. Dependency pinning
  5. Reproducibility requirements
  6. Build timestamp sync
  7. Secure credential handling
  8. Network restrictions
  9. Build metadata capture
  10. Enforcing clean build states
  11. Signed build configuration
  12. Monitoring for drift
Module 4. Generating SLSA provenance
Produce complete, signed provenance documents that comply with SLSA specifications. Learn to structure provenance for verification, including attestations, dependencies, and materials used in the build.
12 chapters in this module
  1. Provenance JSON structure
  2. Signing with trusted keys
  3. Attestation formats
  4. Recording input materials
  5. Environment metadata
  6. Output artefact references
  7. Timestamps and integrity checks
  8. Integrating with build tools
  9. Automating provenance generation
  10. Handling multi-stage builds
  11. Provenance verification steps
  12. Fixing incomplete provenance
Module 5. Implementing attestations
Apply granular attestations to verify build steps, code reviews, and policy checks. Use in-toto attestations to strengthen provenance and demonstrate compliance with internal and external standards.
12 chapters in this module
  1. Attestation vs provenance
  2. Signing build steps
  3. Code review attestations
  4. Policy check verification
  5. Vulnerability scan attestations
  6. Generating SLSA attestations
  7. Chaining attestations
  8. Using Fulcio for signing
  9. Integration with Sigstore
  10. Attestation storage
  11. Verification workflows
  12. Attestation expiry
Module 6. Enforcing SLSA levels
Map organizational needs to SLSA Level 1 through 4. Implement controls and verification processes that ensure builds meet defined thresholds for integrity and trust.
12 chapters in this module
  1. Defining level thresholds
  2. Level 1: basic provenance
  3. Level 2: tamper resistance
  4. Level 3: reproducibility
  5. Level 4: two-person reviews
  6. Auditing against levels
  7. Gap assessment process
  8. Vendor SLSA compliance
  9. Internal certification process
  10. Reporting for audits
  11. Continuous monitoring
  12. Roadmap to higher levels
Module 7. Validating external builds
Verify third-party and open-source software using SLSA. Use provenance and attestations to assess trustworthiness, reduce supply chain risk, and streamline vendor onboarding.
12 chapters in this module
  1. Assessing vendor SLSA support
  2. Provenance verification
  3. Checking attestation signatures
  4. Validating build integrity
  5. Trusted repository integration
  6. Handling unsigned builds
  7. Vendor questionnaires
  8. Automated validation scripts
  9. Scoring vendor maturity
  10. Escalation paths
  11. Documentation for compliance
  12. Reporting to security teams
Module 8. CI/CD integration
Embed SLSA generation and verification into CI/CD pipelines. Automate provenance signing, attestation checks, and policy enforcement without slowing development velocity.
12 chapters in this module
  1. CI/CD pipeline stages
  2. Automated provenance signing
  3. Attestation gates
  4. Policy enforcement points
  5. Failure handling
  6. Logging for audits
  7. Integration with GitHub Actions
  8. GitLab CI compatibility
  9. Jenkins plugin setup
  10. Monitoring pipeline health
  11. Re-triggering builds
  12. Secure key management
Module 9. Policy as code for SLSA
Define and enforce software supply chain policies using code. Implement checks for provenance, attestations, and build integrity in automated workflows.
12 chapters in this module
  1. Defining policy rules
  2. Using Rego with OPA
  3. Provenance format validation
  4. Signature verification rules
  5. Attestation checks
  6. Build environment policies
  7. Automated policy evaluation
  8. Generating policy reports
  9. Remediation workflows
  10. Policy versioning
  11. Integration with CI/CD
  12. Audit log integration
Module 10. Auditing with SLSA
Use SLSA artefacts to streamline internal and external audits. Provide verifiable, standardized evidence of build integrity and compliance with minimal manual effort.
12 chapters in this module
  1. Audit preparation checklist
  2. Provenance as evidence
  3. Attestation review process
  4. Generating audit reports
  5. Responding to auditor questions
  6. Internal compliance dashboards
  7. Cross-team reporting
  8. Evidence retention
  9. Version comparisons
  10. Remediation tracking
  11. Audit feedback loop
  12. Continuous compliance
Module 11. SLSA in multi-cloud environments
Apply SLSA consistently across AWS, GCP, and Azure build systems. Adapt provenance generation and verification to different cloud-native toolchains and identity models.
12 chapters in this module
  1. AWS CodeBuild integration
  2. Google Cloud Build provenance
  3. Azure Pipeline support
  4. Cloud key management
  5. Federated identity setup
  6. Cross-cloud provenance format
  7. Monitoring consistency
  8. Vendor-specific tooling
  9. Standardizing outputs
  10. Handling regional builds
  11. Multi-cloud audit readiness
  12. Unified logging approach
Module 12. Leading SLSA adoption
Drive organizational adoption of SLSA by aligning engineering, security, and compliance teams. Build playbooks, training, and governance structures that scale assurance across products and teams.
12 chapters in this module
  1. Identifying pilot teams
  2. Stakeholder alignment
  3. Training development
  4. Internal documentation
  5. Feedback collection
  6. Scaling to new products
  7. Governance committee setup
  8. Metrics for success
  9. Roadmap development
  10. External benchmarking
  11. Sharing best practices
  12. Maintaining momentum

How this maps to your situation

  • Starting first internal SLSA implementation
  • Responding to vendor software with incomplete provenance
  • Preparing for audit with new software integrity requirements
  • Leading cross-functional software supply chain initiative

Before vs. after

Before
Manual collection of build provenance, inconsistent vendor compliance, reactive audit responses
After
Automated SLSA artefact generation, verified attestations, and audit-ready outputs across builds

What's included with your purchase

  • 12 modules with 12 chapters each (144 chapters)
  • Downloadable templates and worked examples for every module
  • Hand-built implementation playbook delivered alongside course access
  • 30-day money-back guarantee

Delivery and format

  • Course and learning environment access provisioned within 24 hours of purchase
  • Hand-built implementation playbook delivered alongside course access

Format: Text-based modules and chapters in the Art of Service learning environment, plus downloadable templates and worked examples for every chapter, plus the hand-built implementation playbook delivered alongside course access.

Time investment: Approximately 3-4 hours per module, designed for completion over 6-8 weeks with hands-on application.

If nothing changes
Without structured SLSA implementation, software provenance remains fragmented, increasing audit burden and weakening trust in internal and third-party builds during security reviews.

How this compares to the alternatives

Unlike generic security courses, this program delivers precise SLSA implementation guidance with real-world templates and enforcement strategies tailored to engineering and compliance teams.

Frequently asked

Is this course only for engineers?
No, it’s designed for both engineers and compliance practitioners who need to implement or verify SLSA in production environments.
How is the course structured?
12 modules, each containing 12 chapters (144 chapters total).
Does it cover SBOM integration?
Yes, SLSA provenance feeds into SBOMs, and we cover how to synchronize both for maximum compliance leverage.
$199 one-time. Approximately 3-4 hours per module, designed for completion over 6-8 weeks with hands-on application..

Within 24 hours your account in the learning environment is provisioned and the tailored implementation playbook is delivered alongside it.

30-day money-back guarantee· 144 chapters· Hand-built playbook included· Account access within 24 hours