QA Pro AcademyCybersecurity A-Z
← Back to catalogue
CY-SENIOR-043Senior Level · Software Supply Chain Program

Software Supply Chain Security Program — The Provenance Funnel

A senior-level, program-scale course that runs software supply chain security as an org-wide program, not a single pipeline. Work the provenance funnel - eight stages: Scope, Inventory, Standards, Build Integrity, Dependencies, Verification, Vendors, and Assurance - proving provenance rather than assuming it across first-party, open-source, commercial, build-infrastructure, and AI-generated code, with real SBOM/VEX, SLSA, signing, admission, dependency-governance, and customer-assurance work. Four hands-on activities in every lesson.

16 hours8 chapters32 lessons225 activities8 labs

What you'll learn

  • Scope and charter an org-wide supply-chain program across every software category, grounded in a real threat model.
  • Build an org-wide component and build-system inventory with current SBOMs and VEX, and adopt SLSA/SSDF/Scorecard standards with a tiered minimum bar.
  • Harden build integrity with hermetic builds, isolated ephemeral runners, signed provenance, and admission control, and govern dependencies against malicious packages.
  • Enforce deploy-time verification, hold vendors to SBOM/VEX/patch-SLA requirements, and deliver honest SBOMs and maturity metrics to customers and regulators.

Price
৳6,000
৳10,000
Sign in to get access

Sign in to enrol — you can pay by bKash or Nagad, or apply a promo code.