Secure Supply Chain Consumption Framework (S2C2F)

}
2 Days

Available On-Site

Available Virtually

Contact Us for Open Enrollment
f

Customizable

Secure Supply Chain Consumption Framework (S2C2F) is an intensive two-day, hands-on course. It gives working technology professionals a comprehensive introduction to the framework. Attendees leave with a clear understanding of S2C2F’s principal features, maturity levels, and use cases.

Day one opens with an S2C2F overview. It then turns to the common open source supply chain threats the framework is built to counter, from typosquatting to compromised dependencies. Students then get hands-on with ingesting and scanning software artifacts for known vulnerabilities. They also build a working inventory of artifacts flowing through their supply chain, the foundation for every later maturity level.

Day two focuses on operational practice: updating artifacts and managing their dependency lifecycles. It also covers auditing software provenance and CI/CD workflows, and enforcing supply chain security policy across the organization. The course closes with rebuilding artifacts from source and pushing fixes upstream, the highest S2C2F maturity practice. Students gain hands-on experience through a series of labs demonstrating each of the framework’s key requirements. Each leaves equipped with tools implementing the S2C2F model in their own environment.

Who Should Attend

IT and QA Staff, Developers, Technical Managers, SRE/DevOps/DevSecOps/PlatformOps and Build personnel

What Attendees Will Learn

Upon completing Secure Supply Chain Consumption Framework (S2C2F), attendees will be able to:

  • Explain the S2C2F framework and its maturity levels
  • Identify common open source supply chain threats
  • Ingest and scan software artifacts for vulnerabilities
  • Inventory software artifacts across the supply chain
  • Update artifacts and manage dependency lifecycles
  • Audit software provenance and CI/CD workflows
  • Enforce supply chain security policy
  • Rebuild artifacts and push upstream fixes

Upon completion, attendees will have the skills and knowledge necessary to dramatically improve their internal supply chain security using a threat-based risk-reduction approach to software consumption, with the added ability to measure efforts toward compliance with Executive Order standards in the Secure Software Development Framework (SSDF).

Prerequisites

Students should have basic software build and devops knowledge including some experience with Linux and Linux containers.

Delivery

Available for Instructor-Led (ILT) in-person/onsite training or Virtual Instructor-Led training (VILT) delivery.

Each attendee will require the ability to ssh into a cloud hosted virtual machine (provided with the course). In environments where SSH is not possible, local lab VMs or browser accessible lab systems can be provided. For web-based delivery, participants require an Internet-connected computer capable of teleconferencing.

Related Instructor-Led (ILT & VILT) Training Courses

If you are interested in other Cloud Native, AI, programming, or other courses, check out the full course list or search our entire catalog:

Secret Link