Skip to main content
Image coming soon

SLSA Software Supply Chain Integrity Evidence & Implementation Kit

$249.00
Adding to cart… The item has been added
SLSA Software Supply Chain Integrity · Software supply chain integrity, made adopt-ready · Evidence & Implementation Kit
Meet the SLSA framework, without decoding the framework yourself.
Every requirement handed to you as an adopt-ready control, source and hosted builds through signed provenance and dependency integrity to verification and policy enforcement, with the evidence an assessor examines.
Ready in a weekend, not a quarter.

Here is the honest situation. SLSA, Supply-chain Levels for Software Artifacts, is a framework of progressive levels for build and provenance integrity. It covers version-controlled and reviewed source, scripted hosted builds, signed and authenticated provenance, hardened and isolated builds, dependency tracking and pinning, publishing artifacts with provenance, and verifying provenance against policy before use. A team building software without provenance or verification is exactly where organizations fall short in the supply chain.

This Kit removes the guesswork. It is the SLSA framework written as adopt-ready controls you personalize in a weekend, with the evidence an assessor examines.

What you get, the moment you buy

18
Requirements as adopt-ready controls. Every requirement, written so you personalize and apply it.
18
Evidence-they-examine checklists. For each control, exactly what an assessor examines, plus where organizations fall short, so you close the gap first.
1
Control Matrix, pre-built. Every requirement in a working spreadsheet, ready to record status, owner and evidence location.
1
Gap & Readiness Assessment. Score each requirement and the workbook returns your readiness as a single percentage, and exactly what to fix next.

Grounded in the SLSA framework. Editable Word and Excel files.

A build without provenance is unverifiable
If you cannot prove how an artifact was built, you cannot trust it. This Kit turns SLSA into adopt-ready controls with signed provenance and the evidence an assessor asks for.

What one control looks like

This is the opening control, where the program begins. All 18 are built to this depth.

SLSA-1 Adopt the SLSA framework SCOPE
Put this control in place

Adopt Supply-chain Levels for Software Artifacts as [your organization name]'s framework for build and supply chain integrity, and identify the artifacts and build systems in scope, and document it, so integrity is structured and the organization can evidence its adoption.

Requirement note.

SLSA (Supply-chain Levels for Software Artifacts) is a framework of levels for build and provenance integrity of software artifacts.

Evidence an assessor examines
  • SLSA adopted as the framework
  • Artifacts and build systems in scope
  • Records of the adoption
Common finding they raise: Software build integrity is not measured against a framework.

Why this is not another template pack

  • The evidence is the point. A requirement you cannot evidence is a gap waiting to be found. This tells you what an assessor examines and where organizations fall short, for every requirement.
  • The specifics built in. The requirement's distinctive requirements are written into the controls, not left generic.
  • Built on a mapped compliance corpus, not one person's opinion, from a graph of thousands of controls across standards.
  • It compounds. This work shares its shape with related security and safety frameworks, so it feeds your wider program.

Who buys this

Platform, build and application security teams securing the software supply chain. Whether it is a first integrity baseline or a provenance uplift, you save weeks and walk in with your source, build, provenance, dependency and verification controls structured.

By the end of the weekend you will have
✓  An adopt-ready control for all 18 requirements
✓  A completed control matrix
✓  The evidence an assessor examines
✓  Your core controls in place
✓  A readiness percentage and a fix list
✓  The highest-risk gaps closed

Common questions

Is it really editable? Yes. Word and Excel files you own and adapt. No portal, no subscription.

Is SLSA just about signing? No. It covers source, build, provenance, dependencies and verification. This Kit operationalises the whole framework.

Does it cover verifying provenance? Yes. Verifying provenance against policy and blocking untrusted artifacts are built as controls.

What if it is not for me? A 30-day money-back guarantee.

Do not face an assessor with requirements you cannot show.
Every requirement is fast to adopt with the Kit. It is instant, and it is guaranteed.
Add it to your cart and be ready this weekend.

Instant digital download · 30-day money-back guarantee · The Art of Service Pty Ltd, GPO Box 2673, Brisbane QLD 4001 · support@theartofservice.com