Class Central is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

YouTube

Harnessing In-toto Attestations for Security and Compliance With Next-gen Policies

OpenSSF via YouTube

Overview

Coursera Spring Sale
40% Off Coursera Plus Annual!
Grab it
Learn how to leverage the in-toto framework for supply chain security and compliance in this 19-minute conference talk that addresses the growing need for authenticated supply chain metadata driven by U.S. executive orders 14028 and 14144. Discover the in-toto Attestation Framework as a standardized approach for describing supply chain data, including SBOMs and SLSA Build Provenance, and understand its central role in helping vendors meet regulatory requirements. Explore the challenges consumers and auditors face when defining intuitive policies to extract meaningful insights from existing attestations, and examine how previous in-toto policy versions proved incompatible with new attestation formats. Watch a demonstration of in-toto's redesigned policy framework that connects attestations in more powerful, flexible, and user-friendly ways while accommodating diverse real-world use cases in the rapidly evolving supply chain security ecosystem.

Syllabus

Harnessing In-toto Attestations for Security and Compliance W... Marcela Melara & Trishank Kuppusamy

Taught by

OpenSSF

Reviews

Start your review of Harnessing In-toto Attestations for Security and Compliance With Next-gen Policies

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.