Skip to main content
Image coming soon

Deeper command of the SLSA framework for secure software supply chains

$199.00
Adding to cart… The item has been added

A tailored course, built for your situation

Deeper command of the SLSA framework for secure software supply chains

Master the framework defining modern software integrity verification

$199 one-time
24-hour access provisioning 30-day money-back guarantee Hand-built implementation playbook
12 modules. 12 chapters per module. 144 chapters total.
12 modules, each with 12 chapters (144 chapters total), text-based, plus downloadable templates and a hand-built implementation playbook delivered alongside course access.
Frustrated by fragmented tooling and unclear SLSA implementation paths?

The situation this course is for

Most engineers approach SLSA through piecemeal tool integration without grasping the full control hierarchy. This leads to partial adoption, audit gaps, and rework when security reviews intensify.

Who this is for

Senior software engineer or platform specialist implementing supply chain security in product-first organizations

Who this is not for

Engineers focused only on runtime security, application pentesting, or network-layer controls without ownership of build pipelines or artifact provenance

What you walk away with

  • Full command of SLSA’s four integrity levels and their technical thresholds
  • Ability to design tier-appropriate build environments with reproducible outputs
  • Confidence mapping third-party SBOMs to internal SLSA compliance benchmarks
  • Mastery of signed attestations using Sigstore and Fulcio integration patterns
  • Clarity on how SLSA integrates with internal tooling without requiring Jira or Atlassian-specific extensions

The 12 modules (with all 144 chapters)

Module 1. SLSA framework fundamentals and evolving adoption
Understand the core motivations behind SLSA, its relationship to NIST SSDF and SBOMs, and how it is being implemented across product-led engineering organizations today.
12 chapters in this module
  1. Origins of SLSA
  2. Key stakeholders in adoption
  3. SLSA vs SPDX vs CycloneDX
  4. Integration with CI CD
  5. Build vs release integrity
  6. Attestation basics
  7. Sigstore overview
  8. Tier 1 requirements
  9. Tier 2 thresholds
  10. Tier 3 objectives
  11. Tier 4 goals
  12. Framework versioning
Module 2. Artifact provenance and provenance signing
Learn how to generate verifiable metadata for software components and implement cryptographic signing to establish trust in origin and build process.
12 chapters in this module
  1. Provenance definition
  2. Envelope formats
  3. DSSE standard
  4. Signing with Cosign
  5. Keyless signing flow
  6. Fulcio certificate authority
  7. OIDC identity
  8. Rekor transparency log
  9. Verification workflow
  10. Provenance schema
  11. Provenance storage
  12. Provenance access
Module 3. Build integrity and reproducible outputs
Master techniques for ensuring builds are hermetic and deterministic, reducing drift and increasing confidence in artifact consistency across environments.
12 chapters in this module
  1. Hermetic builds
  2. Deterministic compilation
  3. Source capture
  4. Environment isolation
  5. Dependency pinning
  6. Container base security
  7. Build config signing
  8. Reproducibility testing
  9. Diff systems
  10. Build reproducibility score
  11. Toolchain trust
  12. Layered verification
Module 4. SLSA Level 1 implementation
Implement basic SLSA compliance with version-controlled source and authenticated controls over build triggers and artifact publication.
12 chapters in this module
  1. Source control gating
  2. Authenticated triggers
  3. Build service identity
  4. Artifact naming
  5. Provenance generation
  6. Initial signing
  7. Verification script
  8. Pipeline logging
  9. Access controls
  10. Deployment guardrails
  11. Review automation
  12. Compliance dashboard
Module 5. SLSA Level 2 implementation
Upgrade to intermediate integrity with build platform isolation and signed provenance, reducing risks from shared build environments.
12 chapters in this module
  1. Dedicated build platform
  2. Isolated workspace
  3. VM vs container isolation
  4. Build worker identity
  5. Signed provenance
  6. Provenance schema compliance
  7. Provenance signing
  8. Verification pipeline
  9. Audit trail completeness
  10. Dependency verification
  11. Artifact immutability
  12. Retention policy
Module 6. SLSA Level 3 implementation
Achieve high assurance through reproducible builds and two-person review requirements, enabling audit-grade confidence in production artifacts.
12 chapters in this module
  1. Reproducible build design
  2. Two person review rule
  3. Source diff verification
  4. Build config locking
  5. Binary diff analysis
  6. Rebuild on demand
  7. Provenance completeness
  8. Provenance signing policy
  9. Verification automation
  10. Attestation bundling
  11. Artifact indexing
  12. Trust domain mapping
Module 7. SLSA Level 4 implementation
Design fault-tolerant, fully reproducible build systems with adversarial resistance, suitable for critical infrastructure and regulated environments.
12 chapters in this module
  1. High availability builds
  2. Distributed rebuilds
  3. Threshold signing
  4. Build redundancy
  5. Adversarial testing
  6. Tamper proof logging
  7. Zero trust build pipeline
  8. Independent rebuild verification
  9. Cross org validation
  10. Signed release tags
  11. Threshold attestation
  12. Incident readiness
Module 8. SBOM integration with SLSA attestations
Combine software bills of materials with SLSA provenance to create rich, verifiable dependency disclosures for internal and external stakeholders.
12 chapters in this module
  1. SBOM formats
  2. SPDX generation
  3. CycloneDX export
  4. Dependency graph capture
  5. Transitive risk tracking
  6. Vulnerability mapping
  7. Attestation bundling
  8. Provenance inclusion
  9. SBOM signing
  10. SBOM verification
  11. Third party validation
  12. Regulator readiness
Module 9. CI/CD pipeline integration patterns
Adapt existing pipelines to meet SLSA requirements without disrupting developer velocity or requiring proprietary tooling.
12 chapters in this module
  1. Pipeline architecture
  2. Trigger security
  3. Build isolation
  4. Provenance injection
  5. Signing steps
  6. Verification gates
  7. Failure handling
  8. Developer feedback
  9. Pipeline hardening
  10. Identity binding
  11. Access audit
  12. Pipeline compliance
Module 10. Internal governance and framework adoption
Lead adoption across engineering teams by building internal standards, playbooks, and audit processes that scale with organizational maturity.
12 chapters in this module
  1. Adoption roadmap
  2. Tiered rollout
  3. Team enablement
  4. Training materials
  5. Internal benchmarks
  6. Audit preparation
  7. Compliance reporting
  8. Framework updates
  9. Policy enforcement
  10. Tooling standards
  11. Feedback loops
  12. Maturity tracking
Module 11. Third-party verification and vendor assessment
Evaluate external vendors and open-source projects using SLSA criteria to reduce supply chain risk and inform procurement decisions.
12 chapters in this module
  1. Vendor attestation review
  2. Tier compliance check
  3. Provenance validation
  4. Attestation verification
  5. SBOM completeness
  6. Build transparency
  7. Source availability
  8. Security posture
  9. Risk scoring
  10. Due diligence
  11. Escalation path
  12. Remediation guidance
Module 12. Audit readiness and external validation
Prepare for regulatory scrutiny and third-party audits with comprehensive documentation, verification tooling, and clear attestation trails.
12 chapters in this module
  1. Audit package composition
  2. Attestation bundles
  3. Provenance archives
  4. Verification tooling
  5. Log completeness
  6. Policy documentation
  7. Control mapping
  8. Evidence collection
  9. Response preparation
  10. Regulator engagement
  11. Findings resolution
  12. Improvement roadmap

How this maps to your situation

  • When starting SLSA implementation
  • Upgrading from Tier 1 to Tier 2
  • Preparing for external audit
  • Evaluating third-party software

Before vs. after

Before
SLSA guidance feels fragmented, with unclear paths from documentation to implementation.
After
You own a structured, repeatable approach to SLSA adoption across teams and pipelines.

What's included with your purchase

  • 12 modules with 12 chapters each (144 chapters)
  • Downloadable templates and worked examples for every module
  • Hand-built implementation playbook delivered alongside course access
  • 30-day money-back guarantee

Delivery and format

  • Course and learning environment access provisioned within 24 hours of purchase
  • Hand-built implementation playbook delivered alongside course access

Format: Text-based modules and chapters in the Art of Service learning environment, plus downloadable templates and worked examples for every chapter, plus the hand-built implementation playbook delivered alongside course access.

Time investment: 6-8 hours total, self-paced with downloadable references.

If nothing changes
Without clear command of SLSA, teams risk incomplete implementations, audit findings, and increased scrutiny during security reviews.

How this compares to the alternatives

Unlike vendor-specific certifications or general security courses, this program focuses exclusively on practical, implementation-grade SLSA mastery with no fluff or abstract theory.

Frequently asked

Who is this course for?
Senior software engineers, platform engineers, and security specialists implementing supply chain integrity in product-first engineering environments.
How is the course structured?
12 modules, each containing 12 chapters (144 chapters total).
Does this course cover Atlassian tools?
No. The course focuses on SLSA framework implementation using open standards and cloud-agnostic tooling, avoiding any reference to Atlassian products.
$199 one-time. 6-8 hours total, self-paced with downloadable references..

Within 24 hours your account in the learning environment is provisioned and the tailored implementation playbook is delivered alongside it.

30-day money-back guarantee· 144 chapters· Hand-built playbook included· Account access within 24 hours