Home→Courses→Software Supply-Chain Risk Management Training Course
Risk Management
Software Supply-Chain Risk Management Training Course
Introduction
The modern software landscape is defined by its deep reliance on third-party components, particularly vast ecosystems of Open Source Software (OSS). This reliance, while enabling rapid innovation, has fundamentally expanded the attack surface, transforming the Software Supply Chain (SSC) into a primary target for sophisticated threat actors. High-profile incidents like SolarWinds and the XZ Utility Backdoor demonstrate that compromising a single, trusted link whether a third-party vendor, a build environment, or a popular open-source library can lead to catastrophic, cascading breaches across thousands of organizations. The current state demands a shift from reactive vulnerability patching to a proactive, security-by-design approach. Organizations are now struggling with a fundamental lack of visibility into their dependencies, a surge in malicious packages and typosquatting, and the imperative to comply with rapidly evolving mandates for transparency and integrity, notably the generation and consumption of the Software Bill of Materials (SBOM).
Software Supply-Chain Risk Management Training Course is critical for embedding cyber-resilience throughout the entire Software Development Life Cycle (SDLC). It moves beyond traditional perimeter defenses to focus on securing the very process of software creation, integration, and delivery. Participants will master essential security controls, including automated Software Composition Analysis (SCA), Artifact Verification, Code Integrity validation, and the implementation of robust CI/CD pipeline hardening techniques. By adopting a Zero Trust model applied to the supply chain and leveraging continuous Threat Modeling, students will gain the expertise to not only identify and mitigate current risks but also to establish a sustainable, auditable, and secure DevSecOps culture that meets regulatory requirements and safeguards against the inevitable future of AI-generated code vulnerabilities.
Programme Curriculum
Software Supply-Chain Risk Management Training Course
Introduction
The modern software landscape is defined by its deep reliance on third-party components, particularly vast ecosystems of Open Source Software (OSS). This reliance, while enabling rapid innovation, has fundamentally expanded the attack surface, transforming the Software Supply Chain (SSC) into a primary target for sophisticated threat actors. High-profile incidents like SolarWinds and the XZ Utility Backdoor demonstrate that compromising a single, trusted link whether a third-party vendor, a build environment, or a popular open-source library can lead to catastrophic, cascading breaches across thousands of organizations. The current state demands a shift from reactive vulnerability patching to a proactive, security-by-design approach. Organizations are now struggling with a fundamental lack of visibility into their dependencies, a surge in malicious packages and typosquatting, and the imperative to comply with rapidly evolving mandates for transparency and integrity, notably the generation and consumption of the Software Bill of Materials (SBOM).
Software Supply-Chain Risk Management Training Course is critical for embedding cyber-resilience throughout the entire Software Development Life Cycle (SDLC). It moves beyond traditional perimeter defenses to focus on securing the very process of software creation, integration, and delivery. Participants will master essential security controls, including automated Software Composition Analysis (SCA), Artifact Verification, Code Integrity validation, and the implementation of robust CI/CD pipeline hardening techniques. By adopting a Zero Trust model applied to the supply chain and leveraging continuous Threat Modeling, students will gain the expertise to not only identify and mitigate current risks but also to establish a sustainable, auditable, and secure DevSecOps culture that meets regulatory requirements and safeguards against the inevitable future of AI-generated code vulnerabilities.
Course Duration
5 days
Course Objectives
Upon completion of this course, participants will be able to:
Map and obtain deep Visibility into multi-tiered software supply chains, including all transitive dependencies.
Analyze, generate, and consume Software Bill of Materials in standard formats for Compliance and risk analysis.
Implement and enforce Code Integrity controls using digital signatures and secure artifact verification processes.
Apply Threat Modeling techniques specifically to the CI/CD Pipeline to identify and mitigate high-impact attack vectors.
Differentiate between and secure against various modern attacks: Dependency Confusion, Typosquatting, and Malicious Packages.
Harden Build Systems and Source Code Repositories using principles of Least Privilege and secure configuration management.
Integrate Software Composition Analysis (SCA) and Static Application Security Testing (SAST) tools early in the SDLC (Shift Left).
Design an effective Vulnerability Exploitability eXchange (VEX) program to manage and communicate vulnerability status efficiently.
Establish Continuous Monitoring and logging across the supply chain to detect anomalous and suspicious activity in real-time.
Implement a supply chain-focused Zero Trust architecture, specifically for developer and system access.
Interpret and ensure adherence to key regulatory frameworks, including NIST Secure Software Development Framework (SSDF) and Executive Order 14028.
Develop and practice a comprehensive Software Supply Chain Incident Response plan using real-world scenarios.
Evaluate and manage the security posture of Third-Party Vendors and outsourced development partners.
Target Audience
DevSecOps Engineers/Architects
Application Security (AppSec) Managers
Software Engineers/Developers
Cybersecurity Risk Analysts
CISO/CTO and Technology Leadership
Security Auditors and Compliance Officers
Supply Chain/Procurement Managers
Cloud Security Engineers
Course Modules
Module 1: Understanding the Software Supply Chain Threat Landscape
Upon successful completion of this training, participants will be issued with a globally- recognized certificate.
Tailor-Made Course
We also offer tailor-made courses based on your needs.
Key Notes
a. The participant must be conversant with English.
b. Upon completion of training the participant will be issued with an Authorized Training Certificate
c. Course duration is flexible and the contents can be modified to fit any number of days.
d. The course fee includes facilitation training materials, 2 coffee breaks, buffet lunch and A Certificate upon successful completion of Training.
e. One-year post-training support Consultation and Coaching provided after the course.
f. Payment should be done at least a week before commence of the training, to FINESKILL TRAINING CENTER account, as indicated in the invoice so as to enable us prepare better for you.