CY-SENIOR-043Senior Level · Software Supply Chain Program
Software Supply Chain Security Program — The Provenance Funnel
A senior-level, program-scale course that runs software supply chain security as an org-wide program, not a single pipeline. Work the provenance funnel - eight stages: Scope, Inventory, Standards, Build Integrity, Dependencies, Verification, Vendors, and Assurance - proving provenance rather than assuming it across first-party, open-source, commercial, build-infrastructure, and AI-generated code, with real SBOM/VEX, SLSA, signing, admission, dependency-governance, and customer-assurance work. Four hands-on activities in every lesson.
16 hours8 chapters32 lessons225 activities8 labs
What you'll learn
- Scope and charter an org-wide supply-chain program across every software category, grounded in a real threat model.
- Build an org-wide component and build-system inventory with current SBOMs and VEX, and adopt SLSA/SSDF/Scorecard standards with a tiered minimum bar.
- Harden build integrity with hermetic builds, isolated ephemeral runners, signed provenance, and admission control, and govern dependencies against malicious packages.
- Enforce deploy-time verification, hold vendors to SBOM/VEX/patch-SLA requirements, and deliver honest SBOMs and maturity metrics to customers and regulators.
Sign in to enrol — you can pay by bKash or Nagad, or apply a promo code.