YoVDO

Analyzing Google's SLSA Framework for Securing Software Supply Chains

Offered By: OWASP Foundation via YouTube

Tags

Software Supply Chain Security Courses Application Security Courses

Course Description

Overview

Save Big on Coursera Plus. 7,000+ courses at $160 off. Limited Time Only!
Explore Google's "Supply Chain Levels for Software Artifacts" (SLSA) framework in this 20-minute OWASP Foundation conference talk. Delve into the growing threat of software supply chain attacks and learn how SLSA aims to address this critical AppSec need. Examine the framework's approach, key areas of focus, and controls for attaining each level. Gain insights into additional aspects of software supply chain security not covered by SLSA. Understand the collapse of the SDLC into SCM and the implications for security. Analyze the framework's components, including Source, Build, Provenance, and Common elements, while identifying areas that fall outside the scope of SLSA.

Syllabus

Intro
2021 is the Year of the Software Supply Chain Attack
The SDLC has collapsed into SCMS
Google's SLSA Levels
Google's SLSA framework - Source
Source - Out of Scope
Google's SLSA framework - Build
Google's SLSA framework - Provenance con
Build & Provenance - Out of Scope
Google's SLSA framework - Common
Common - Out of Scope


Taught by

OWASP Foundation

Related Courses

Hardening Your Soft Software Supply Chain
Pluralsight
DevOps with GitHub and Azure: Implementing Software Supply Chain Security with GitHub
Pluralsight
Securing Your Software Supply Chain with Sigstore
Linux Foundation via edX
GitHub Supply Chain Security Using GitGat
Linux Foundation via edX
Kyverno - Deep Dive - Tech Talks
Mirantis via YouTube