The Supply Chain Threat Model
Where software supply chains break, told through SolarWinds, Codecov, xz-utils and event-stream. And what SLSA was never designed to catch.
WRIGHTBRAINEDSECURITY
Book a call
SLSA (pronounced "salsa") is a framework for proving that software hasn't been tampered with between the developer's keyboard and your systems. This self-paced course teaches software teams how to meet it, and teaches buyers what to ask for.
Where software supply chains break, told through SolarWinds, Codecov, xz-utils and event-stream. And what SLSA was never designed to catch.
What a SLSA level actually claims, who is responsible for what, and how to question a vendor's level claim.
Read a real build record field by field, then take one apart yourself in the lab.
What an assessor will actually ask, what counts as proof, and where companies that thought they were ready come up short.
Ask about CMMC trainingNo. It's practical training from a practicing Lead CMMC Certified Assessor. It won't earn you a credential, but it will prepare you for the real thing.
Yes. Your whole team can take the online course, and I can be available for a live Q&A session with the group.
Yes. Everyone who finishes the course gets a certificate of completion.
Thirty minutes, no slide deck. Tell us what you're up against and we'll tell you honestly whether we can help.