Software Supply Chain Security: Prevent Attacks & Master CSSE Certification 2025
From Code to Cloud, Secure Every Step of Your Software Supply Chain Recent attacks like SolarWinds, Codecov, and the XZ backdoor exposed just how fragile modern software supply chains are. The Certified Software Supply Chain Security Expertโข (CSSE) course by Practical DevSecOps teaches you how to identify, exploit, and defend every layer of the supply chainโfrom Git to CI/CD, containers, Kubernetes, and cloud infrastructure. With 70% hands-on labs, SBOM generation, artifact signing, and CI/CD pipeline defenses, this course is a must-have for modern security professionals. Join 5,000+ certified professionals who now lead secure SDLCs at the worldโs top companies. ๐ What Youโll Learn - Defend against dependency confusion, typosquatting, pre-commit hook exploitation, and repo jacking - Secure GitHub Actions, GitLab CI/CD, and cloud-native CI pipelines against poisoning and credential theft - Detect insecure Docker images, open registries, and cloud misconfigurations in AWS, Azure, GCP - Use SBOM tools like Syft, Tern, and Bomber to track components across your SDLC - Implement and automate NIST SSDF, SLSA, and OWASP SCVS standards - Secure Kubernetes clusters with RBAC, image scanning, admission controls, and Helm security - Use tools like Trivy, GuardDog, Kubescape, YaraHunter, and DefectDojo to continuously monitor and respond to supply chain threats ๐ง Course Format & Perks - 3 Years of Access to Course Content + Checklists - 60 Days of Browser-Based Labs - 6-Hour Hands-On Practical Exam - 24/7 Instructor Support + Lifetime Access to Community - AI-Powered โExplain to Meโ Command Assistant - Beginner-Friendly: Just Linux, Git, and basic security knowledge required ๐ค Who This Is For DevSecOps professionals, AppSec engineers, security architects, cloud engineers, red teamers, and anyone managing modern development pipelines or third-party code. ๐งช Course Modules Include - Intro to Software Supply Chain Threats - Code & App Layer Attacks (Repo Jacking, Dependency Confusion) - Container Attacks (Malicious Images, Daemon Abuse) - Kubernetes Supply Chain Attacks (Helm, RBAC, Admission Webhooks) - Cloud Supply Chain Threats (S3, GCS, Azure Blob, IAM Abuse) - Supply Chain Defense with SBOMs, Signing, SCVS, SLSA - Managing a Secure Supply Chain Program at Scale ๐ฌ What Learners Say "Every CI/CD and cloud risk we worried aboutโcovered and hands-on!" โ Jason Lutz, AWS "Malicious images, Git hooks, cloud metadataโlearned it all and passed the practical!" โ Tuomas Tiensuu, CISO "The most relevant and actionable course for securing SDLCs. Period." โ Marcin Falkowski, OSCP ๐ Ready to Become a Software Supply Chain Security Expert? ๐ Enroll in the CSSE Course ๐ Watch the Full Overview ABOUT PRACTICAL DEVSECOPS Practical DevSecOps is a global cybersecurity education company specializing in hands-on DevSecOps, AI Security, and Application Security training and certifications. Listed on the NICCS/CISA National Initiative for Cybersecurity Careers and Studies platform, Practical DevSecOps has trained over 12,500 security professionals across 108+ countries and is trusted by organizations including Roche, Accenture, IBM, PWC, and Booz Allen Hamilton. ๐ช๐ต๐ฎ๐ ๐ช๐ฒ ๐ข๐ณ๐ณ๐ฒ๐ฟ Our certification programs are built for practitioners, not theory. Every course is delivered through browser-based labs where learners attack and defend real systems, with no downloads or installations required. Current certifications include: CDP โ Certified DevSecOps Professional CDE โ Certified DevSecOps Expert CAISP โ Certified AI Security Professional CMCPSE โ Certified MCP Security Expert CCSE โ Certified Container Security Expert CCNSE โ Certified Cloud Native Security Expert CTMP โ Certified Threat Modeling Professional CASP โ Certified API Security Professional CSSE โ Certified Software Supply Chain Security Expert CSC โ Certified Security Champion ๐ช๐ต๐ผ ๐ช๐ฒ ๐ง๐ฟ๐ฎ๐ถ๐ป Security engineers, DevSecOps engineers, AppSec professionals, Red Teamers, and Security Leaders at Fortune 500 companies, Defense Agencies, and Government Organizations worldwide. ๐๐ฒ๐ฎ๐ฑ๐พ๐๐ฎ๐ฟ๐๐ฒ๐ฟ๐: San Francisco, USA ๐๐ผ๐๐ป๐ฑ๐ฒ๐ฑ: 2018 ๐ช๐ฒ๐ฏ๐๐ถ๐๐ฒ: practical-devsecops.com
Download
1 formatsVideo Formats
Right-click 'Download' and select 'Save Link As' if the file opens in a new tab.