Secure Supply Chain Consumption Framework (S2C2F) is an intensive two-day, hands-on course. It gives working technology professionals a comprehensive introduction to the framework. Attendees leave with a clear understanding of S2C2F’s principal features, maturity levels, and use cases.
Day one opens with an S2C2F overview. It then turns to the common open source supply chain threats the framework is built to counter, from typosquatting to compromised dependencies. Students then get hands-on with ingesting and scanning software artifacts for known vulnerabilities. They also build a working inventory of artifacts flowing through their supply chain, the foundation for every later maturity level.
Day two focuses on operational practice: updating artifacts and managing their dependency lifecycles. It also covers auditing software provenance and CI/CD workflows, and enforcing supply chain security policy across the organization. The course closes with rebuilding artifacts from source and pushing fixes upstream, the highest S2C2F maturity practice. Students gain hands-on experience through a series of labs demonstrating each of the framework’s key requirements. Each leaves equipped with tools implementing the S2C2F model in their own environment.
Who Should Attend
IT and QA Staff, Developers, Technical Managers, SRE/DevOps/DevSecOps/PlatformOps and Build personnel
What Attendees Will Learn
Upon completing Secure Supply Chain Consumption Framework (S2C2F), attendees will be able to:
- Explain the S2C2F framework and its maturity levels
- Identify common open source supply chain threats
- Ingest and scan software artifacts for vulnerabilities
- Inventory software artifacts across the supply chain
- Update artifacts and manage dependency lifecycles
- Audit software provenance and CI/CD workflows
- Enforce supply chain security policy
- Rebuild artifacts and push upstream fixes
Upon completion, attendees will have the skills and knowledge necessary to dramatically improve their internal supply chain security using a threat-based risk-reduction approach to software consumption, with the added ability to measure efforts toward compliance with Executive Order standards in the Secure Software Development Framework (SSDF).
Prerequisites
Students should have basic software build and devops knowledge including some experience with Linux and Linux containers.