A tailored course, built for your situation
Deeper command of the SLSA framework for secure software supply chains
Master the framework defining modern software integrity verification
The situation this course is for
Most engineers approach SLSA through piecemeal tool integration without grasping the full control hierarchy. This leads to partial adoption, audit gaps, and rework when security reviews intensify.
Who this is for
Senior software engineer or platform specialist implementing supply chain security in product-first organizations
Who this is not for
Engineers focused only on runtime security, application pentesting, or network-layer controls without ownership of build pipelines or artifact provenance
What you walk away with
- Full command of SLSA’s four integrity levels and their technical thresholds
- Ability to design tier-appropriate build environments with reproducible outputs
- Confidence mapping third-party SBOMs to internal SLSA compliance benchmarks
- Mastery of signed attestations using Sigstore and Fulcio integration patterns
- Clarity on how SLSA integrates with internal tooling without requiring Jira or Atlassian-specific extensions
The 12 modules (with all 144 chapters)
- Origins of SLSA
- Key stakeholders in adoption
- SLSA vs SPDX vs CycloneDX
- Integration with CI CD
- Build vs release integrity
- Attestation basics
- Sigstore overview
- Tier 1 requirements
- Tier 2 thresholds
- Tier 3 objectives
- Tier 4 goals
- Framework versioning
- Provenance definition
- Envelope formats
- DSSE standard
- Signing with Cosign
- Keyless signing flow
- Fulcio certificate authority
- OIDC identity
- Rekor transparency log
- Verification workflow
- Provenance schema
- Provenance storage
- Provenance access
- Hermetic builds
- Deterministic compilation
- Source capture
- Environment isolation
- Dependency pinning
- Container base security
- Build config signing
- Reproducibility testing
- Diff systems
- Build reproducibility score
- Toolchain trust
- Layered verification
- Source control gating
- Authenticated triggers
- Build service identity
- Artifact naming
- Provenance generation
- Initial signing
- Verification script
- Pipeline logging
- Access controls
- Deployment guardrails
- Review automation
- Compliance dashboard
- Dedicated build platform
- Isolated workspace
- VM vs container isolation
- Build worker identity
- Signed provenance
- Provenance schema compliance
- Provenance signing
- Verification pipeline
- Audit trail completeness
- Dependency verification
- Artifact immutability
- Retention policy
- Reproducible build design
- Two person review rule
- Source diff verification
- Build config locking
- Binary diff analysis
- Rebuild on demand
- Provenance completeness
- Provenance signing policy
- Verification automation
- Attestation bundling
- Artifact indexing
- Trust domain mapping
- High availability builds
- Distributed rebuilds
- Threshold signing
- Build redundancy
- Adversarial testing
- Tamper proof logging
- Zero trust build pipeline
- Independent rebuild verification
- Cross org validation
- Signed release tags
- Threshold attestation
- Incident readiness
- SBOM formats
- SPDX generation
- CycloneDX export
- Dependency graph capture
- Transitive risk tracking
- Vulnerability mapping
- Attestation bundling
- Provenance inclusion
- SBOM signing
- SBOM verification
- Third party validation
- Regulator readiness
- Pipeline architecture
- Trigger security
- Build isolation
- Provenance injection
- Signing steps
- Verification gates
- Failure handling
- Developer feedback
- Pipeline hardening
- Identity binding
- Access audit
- Pipeline compliance
- Adoption roadmap
- Tiered rollout
- Team enablement
- Training materials
- Internal benchmarks
- Audit preparation
- Compliance reporting
- Framework updates
- Policy enforcement
- Tooling standards
- Feedback loops
- Maturity tracking
- Vendor attestation review
- Tier compliance check
- Provenance validation
- Attestation verification
- SBOM completeness
- Build transparency
- Source availability
- Security posture
- Risk scoring
- Due diligence
- Escalation path
- Remediation guidance
- Audit package composition
- Attestation bundles
- Provenance archives
- Verification tooling
- Log completeness
- Policy documentation
- Control mapping
- Evidence collection
- Response preparation
- Regulator engagement
- Findings resolution
- Improvement roadmap
How this maps to your situation
- When starting SLSA implementation
- Upgrading from Tier 1 to Tier 2
- Preparing for external audit
- Evaluating third-party software
Before vs. after
What's included with your purchase
- 12 modules with 12 chapters each (144 chapters)
- Downloadable templates and worked examples for every module
- Hand-built implementation playbook delivered alongside course access
- 30-day money-back guarantee
Delivery and format
- Course and learning environment access provisioned within 24 hours of purchase
- Hand-built implementation playbook delivered alongside course access
Format: Text-based modules and chapters in the Art of Service learning environment, plus downloadable templates and worked examples for every chapter, plus the hand-built implementation playbook delivered alongside course access.
Time investment: 6-8 hours total, self-paced with downloadable references.
How this compares to the alternatives
Unlike vendor-specific certifications or general security courses, this program focuses exclusively on practical, implementation-grade SLSA mastery with no fluff or abstract theory.
Frequently asked
Within 24 hours your account in the learning environment is provisioned and the tailored implementation playbook is delivered alongside it.