Overview
Coursera Spring Sale
40% Off Coursera Plus Annual!
Grab it
Learn how to leverage the in-toto framework for supply chain security and compliance in this 19-minute conference talk that addresses the growing need for authenticated supply chain metadata driven by U.S. executive orders 14028 and 14144. Discover the in-toto Attestation Framework as a standardized approach for describing supply chain data, including SBOMs and SLSA Build Provenance, and understand its central role in helping vendors meet regulatory requirements. Explore the challenges consumers and auditors face when defining intuitive policies to extract meaningful insights from existing attestations, and examine how previous in-toto policy versions proved incompatible with new attestation formats. Watch a demonstration of in-toto's redesigned policy framework that connects attestations in more powerful, flexible, and user-friendly ways while accommodating diverse real-world use cases in the rapidly evolving supply chain security ecosystem.
Syllabus
Harnessing In-toto Attestations for Security and Compliance W... Marcela Melara & Trishank Kuppusamy
Taught by
OpenSSF