# Software Supply Chain Security: SSDF, Attestations and SBOMs Course (Self-Paced)

Canonical URL: <https://www.graduateschool.edu/courses/software-supply-chain-security-course-self-paced>

## Overview

The SolarWinds Orion compromise showed how one trusted software update can reach thousands of organizations. This foundational course explains the software supply chain security pieces set in motion by Executive Order 14028, with no technical background required.

Learners study the NIST Secure Software Development Framework, the self-attestations that software producers provide to agencies, and software bills of materials. The focus is on what attestations and SBOMs do and do not guarantee, so learners can evaluate vendor submissions with confidence.

## What you'll learn

- Identify the components that make up a typical software supply chain.
- Explain why a compromise in an upstream software component can affect every agency that uses it.
- Describe what Executive Order 14028 directed federal agencies and software producers to do.
- Identify the four practice groups in the NIST Secure Software Development Framework.
- Explain why the SSDF describes outcomes rather than prescribing specific tools or techniques.
- Explain what a software producer's self-attestation requires them to certify.
- Identify who is expected to sign a self-attestation on behalf of a software producer.
- Describe what an agency does with a self-attestation once it is received.
- Recognize when an attestation alone is not enough and supporting artifacts are required.
- Identify the core elements typically found in a software bill of materials.
- Read a simple SBOM to locate a specific software component and its version.
- Explain why having an SBOM helps an agency respond faster to a newly disclosed vulnerability.
- Identify a limitation of relying on an SBOM alone.

## Curriculum

#### Module 1: Why Software Supply Chain Security Became a Federal Priority

- Lessons: 
  - What a Software Supply Chain Actually Includes
  - How a Compromise Upstream Becomes an Agency's Problem
  - Executive Order 14028 and the Federal Response

- Applied activity: Learners review a short, described scenario in which a widely used software update is later found to contain malicious code and trace which of the agency's own systems would be affected and why.

#### Module 2: The Secure Software Development Framework (SSDF)

- Lessons: 
  - What the SSDF Is and Who It Is For
  - The Four SSDF Practice Groups
  - How the SSDF Differs From a Compliance Checklist
  - Reading an SSDF Practice: An Example Walkthrough

- Applied activity: Learners review a short, described SSDF practice statement and identify what a software producer would need to do, and what evidence they might produce, to demonstrate they follow it.

#### Module 3: Self-Attestation: What Agencies Require From Software Producers

- Lessons: 
  - The Self-Attestation Requirement, and What It Actually Asks For
  - Who Signs an Attestation, and What They Are Certifying
  - What an Agency Does With an Attestation Once Received
  - When an Attestation Is Not Enough: Artifacts and Extensions

- Applied activity: Learners review a short, described attestation submission and identify whether it meets the basic requirements, then decide what an agency's next step should be if it does not.

#### Module 4: Software Bills of Materials (SBOMs): What They Are and How Agencies Use Them

- Lessons: 
  - What an SBOM Actually Contains
  - Reading a Simple SBOM Example
  - Why Agencies Ask for SBOMs
  - Common SBOM Formats and Limitations

- Applied activity: Learners review a simplified, described SBOM listing several components and identify which one would need immediate attention if a newly disclosed vulnerability affected a specific component and version.

## Pricing

**Tuition:** $799
