> For the complete documentation index, see [llms.txt](https://developer.harness.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://developer.harness.io/university/readme/scs.md).

# Application Security Testing - SCS

Learn Supply Chain Security through Harness University

Secure your SDLC and align them with industry-standard risk frameworks. Govern the use of open source with promotion and attestation policies.

Go to [Harness University](/university/readme.md) for the full catalogue of courses and certifications.

## Self-Paced Training

Free self-paced courses that you can consume on your own time.

<table data-view="cards"><thead><tr><th></th><th></th><th data-hidden data-card-target data-type="content-ref"></th></tr></thead><tbody><tr><td><img src="https://2307127582-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Feh03Q8VHpO02MFM5nUSL%2Fuploads%2Fgit-blob-8d9330b11e4adb2c19a6b64b4a75262530fb0ef8%2Fplatform.svg?alt=media" alt="" data-size="line"> <strong>Harness Platform Fundamentals</strong></td><td>Self-paced video course introducing the Harness Platform.<br><em>Product version: Free Plans of any module</em></td><td><a href="https://university-registration.harness.io/self-paced-training-platform-fundamentals">https://university-registration.harness.io/self-paced-training-platform-fundamentals</a></td></tr><tr><td><img src="https://2307127582-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Feh03Q8VHpO02MFM5nUSL%2Fuploads%2Fgit-blob-8d9330b11e4adb2c19a6b64b4a75262530fb0ef8%2Fplatform.svg?alt=media" alt="" data-size="line"> <strong>Introduction to AI Agents</strong></td><td>Self-paced tidbit introducing the Custom AI Agents.<br><em>Product version: Paid Plans of any module</em></td><td><a href="https://university-registration.harness.io/self-paced-training-tidbit-custom-ai-agents">https://university-registration.harness.io/self-paced-training-tidbit-custom-ai-agents</a></td></tr><tr><td><img src="https://2307127582-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Feh03Q8VHpO02MFM5nUSL%2Fuploads%2Fgit-blob-bc1cffb572f010dfceb4e1f240c00186de90fda0%2Fsupply-chain.svg?alt=media" alt="" data-size="line"> <strong>Application Security Testing - SCS</strong></td><td>Self-paced video course introducing Harness Application Security Testing focusing on SCS.<br><em>Product version: Harness Application Security Testing Paid Plans</em></td><td><a href="https://university-registration.harness.io/self-paced-training-harness-supply-chain-security">https://university-registration.harness.io/self-paced-training-harness-supply-chain-security</a></td></tr></tbody></table>

## Instructor-Led Training

Intensive two-day courses are designed for engineers looking to deepen their understanding and expertise in Harness.

<table data-view="cards"><thead><tr><th></th><th></th><th data-hidden data-card-target data-type="content-ref"></th></tr></thead><tbody><tr><td><img src="https://2307127582-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Feh03Q8VHpO02MFM5nUSL%2Fuploads%2Fgit-blob-8d9330b11e4adb2c19a6b64b4a75262530fb0ef8%2Fplatform.svg?alt=media" alt="" data-size="line"> <strong>Introduction to the Harness Platform</strong></td><td>Self-paced hands-on, prerequisite course to all module-specific ILT courses.<br><em>Product version: Paid Plans of any module</em></td><td><a href="https://university-registration.harness.io/introduction-to-the-harness-platform">https://university-registration.harness.io/introduction-to-the-harness-platform</a></td></tr><tr><td><img src="https://2307127582-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Feh03Q8VHpO02MFM5nUSL%2Fuploads%2Fgit-blob-bc1cffb572f010dfceb4e1f240c00186de90fda0%2Fsupply-chain.svg?alt=media" alt="" data-size="line"> <strong>Application Security Testing - SCS</strong></td><td>Deep dive into supply chain security and concepts.<br><em>Product version: Harness Application Security Testing Paid Plans</em></td><td><a href="https://university-registration.harness.io/ilt-harness-supply-chain-security">https://university-registration.harness.io/ilt-harness-supply-chain-security</a></td></tr></tbody></table>

## Certifications

Test and validate your knowledge of Harness by becoming a Harness Certified Expert.

{% tabs %}
{% tab title="For Developer" %}

### Supply Chain Security - Developer

![Supply Chain Security - Developer badge](https://2307127582-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Feh03Q8VHpO02MFM5nUSL%2Fuploads%2Fgit-blob-32f85359fdb2e26623fb3056c6619643578853fb%2Fcert-dev-scs-badge.svg?alt=media)

**Product version:** Harness SCS Paid Plans

Assesses the fundamental skills to manage your applications with SCS projects.

#### Review Study Guide

| Topic                                                                   | Material                                                                                                                                                    |
| ----------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **1. Introduction to Supply Chain Security with Harness**               |                                                                                                                                                             |
| Understand SCS Overview and Key Concepts                                | [SCS Overview and Key Concepts](https://developer.harness.io/docs/software-supply-chain-assurance/get-started/overview)                                     |
| Explore Onboarding Steps and Getting Started Guide                      | [Onboarding Guide](https://developer.harness.io/docs/software-supply-chain-assurance/get-started/onboarding-guide)                                          |
| Review Supported Tools and Integrations                                 | [Supported Tools and Integrations](https://developer.harness.io/docs/software-supply-chain-assurance/ssca-supported)                                        |
| **2. Repository and CI/CD Security Posture Management**                 |                                                                                                                                                             |
| Assess Repository Security Posture                                      | [Repository Security Posture](https://developer.harness.io/docs/software-supply-chain-assurance/repository-security-posture-management-rspm)                |
| Assess CI/CD Pipeline Security Posture                                  | [CI/CD Security Posture](https://developer.harness.io/docs/software-supply-chain-assurance/cicd-security-posture-management-cicdspm)                        |
| Use Insights to Prioritize Security Improvements                        | [Prioritize Security Improvements](https://developer.harness.io/docs/software-supply-chain-assurance/manage-risk-and-compliance/manage-compliance-posture)  |
| **3. Managing Risk and Compliance**                                     |                                                                                                                                                             |
| Understand Compliance Posture and Framework Mapping                     | [Compliance Posture](https://developer.harness.io/docs/software-supply-chain-assurance/manage-risk-and-compliance/manage-compliance-posture)                |
| Define and Apply Security Standards and Rules                           | [Security Standards and Rules](https://developer.harness.io/docs/software-supply-chain-assurance/manage-risk-and-compliance/standards-and-rule-definitions) |
| Monitor Risk through Dashboards and Reports                             | [Dashboards and Reports](https://developer.harness.io/docs/software-supply-chain-assurance/manage-risk-and-compliance/manage-compliance-posture)            |
| **4. Software Bill of Materials (SBOM) Generation and Ingestion**       |                                                                                                                                                             |
| Generate SBOMs using Harness and GitHub Actions                         | [Generate SBOMs](https://developer.harness.io/docs/software-supply-chain-assurance/sbom/overview)                                                           |
| Ingest SBOMs from External Tools (Aqua Trivy, Snyk, Blackduck)          | [Ingest SBOMs](https://developer.harness.io/docs/software-supply-chain-assurance/sbom/ingest-sbom-data)                                                     |
| Automate SBOM Drift Detection for GitHub Repositories                   | [SBOM Drift Detection](https://developer.harness.io/docs/software-supply-chain-assurance/sbom/automate-sbom-drift-detection)                                |
| **5. SBOM Policy Management**                                           |                                                                                                                                                             |
| Create and Customize SBOM Policies                                      | [Create SBOM Policies](https://developer.harness.io/docs/software-supply-chain-assurance/sbom-policies/create-sbom-policies)                                |
| Write and Maintain Policy Definitions                                   | [Policy Definitions](https://developer.harness.io/docs/software-supply-chain-assurance/sbom-policies/define-sbom-policies)                                  |
| Enforce and Verify Policies via GitHub Actions                          | [Enforce SBOM Policies](https://developer.harness.io/docs/software-supply-chain-assurance/sbom-policies/enforce-sbom-policies-with-github-actions)          |
| **6. Artifact Signing and Verification**                                |                                                                                                                                                             |
| Sign Artifacts to Ensure Integrity                                      | [Sign Artifacts](https://developer.harness.io/docs/category/sign-and-verify-artifacts)                                                                      |
| Verify Signed Artifacts Before Promotion or Deployment                  | [Verify Signed Artifacts](https://developer.harness.io/docs/software-supply-chain-assurance/artifact/verify-signed-artifacts)                               |
| **7. SLSA Provenance Compliance**                                       |                                                                                                                                                             |
| Generate SLSA Provenance with or without GitHub Actions                 | [Generate SLSA Provenance](https://developer.harness.io/docs/software-supply-chain-assurance/slsa/generate-slsa)                                            |
| Verify Provenance to Maintain SLSA Compliance                           | [Verify SLSA Provenance](https://developer.harness.io/docs/software-supply-chain-assurance/slsa/verify-slsa)                                                |
| Understand SLSA Levels and How to Progress Across Them                  | [SLSA Overview](https://developer.harness.io/docs/software-supply-chain-assurance/slsa/overview)                                                            |
| **8. Remediation and Reporting**                                        |                                                                                                                                                             |
| Create and Use Remediation Trackers for Vulnerability Management        | [Remediation Trackers](https://developer.harness.io/docs/software-supply-chain-assurance/remediation-tracker/overview)                                      |
| View and Interpret License and Pipeline Execution Reports               | [Execution Reports](https://developer.harness.io/docs/software-supply-chain-assurance/ssca-view-results)                                                    |
| Label Components from Images for Better Tracking                        | [Label Components](https://developer.harness.io/docs/software-supply-chain-assurance/label-components-from-image)                                           |
| **9. Access and Integration Management**                                |                                                                                                                                                             |
| Manage Role-Based Access Control (RBAC) and Permissions                 | [RBAC](https://developer.harness.io/docs/software-supply-chain-assurance/ssca-access-control)                                                               |
| Configure and Use Third-Party Integrations (SCM, CI/CD tools, scanners) | [Third-Party Integrations](https://developer.harness.io/docs/software-supply-chain-assurance/integrations-and-permissions)                                  |

[**Register for Exam**](https://university-registration.harness.io/supply-chain-security-developer)

#### Exam Details

The Supply Chain Security Developer exam tests your knowledge and skills of the Harness Supply Chain Security module.

**Prerequisites**

* Basic terminal skills
* Basic understanding of cloud security

**Exam Details**

Exam Duration: 90 minutes

Question Type: Multiple choice

| Covered Domain                                             | Percentage |
| ---------------------------------------------------------- | ---------- |
| Introduction to Supply Chain Security with Harness         | 10%        |
| Repository and CI/CD Security Posture Management           | 15%        |
| Managing Risk and Compliance                               | 10%        |
| Software Bill of Materials (SBOM) Generation and Ingestion | 15%        |
| SBOM Policy Management                                     | 20%        |
| Artifact Signing and Verification                          | 10%        |
| SLSA Provenance Compliance                                 | 10%        |
| Remediation and Reporting                                  | 5%         |
| Access and Integration Management                          | 5%         |

**Exam Objectives**

<details>

<summary>List of Objectives</summary>

The following is a detailed list of exam objectives:

| #   | Objectives                                                              |
| --- | ----------------------------------------------------------------------- |
| 1   | **Introduction to Supply Chain Security with Harness**                  |
| 1.1 | Understand SCS Overview and Key Concepts                                |
| 1.2 | Explore Onboarding Steps and Getting Started Guide                      |
| 1.3 | Review Supported Tools and Integrations                                 |
| 2   | **Repository and CI/CD Security Posture Management**                    |
| 2.1 | Assess Repository Security Posture                                      |
| 2.2 | Assess CI/CD Pipeline Security Posture                                  |
| 2.3 | Use Insights to Prioritize Security Improvements                        |
| 3   | **Managing Risk and Compliance**                                        |
| 3.1 | Understand Compliance Posture and Framework Mapping                     |
| 3.2 | Define and Apply Security Standards and Rules                           |
| 3.3 | Monitor Risk through Dashboards and Reports                             |
| 4   | **Software Bill of Materials (SBOM) Generation and Ingestion**          |
| 4.1 | Generate SBOMs using Harness and GitHub Actions                         |
| 4.2 | Ingest SBOMs from External Tools (Aqua Trivy, Snyk, Blackduck)          |
| 4.3 | Automate SBOM Drift Detection for GitHub Repositories                   |
| 5   | **SBOM Policy Management**                                              |
| 5.1 | Create and Customize SBOM Policies                                      |
| 5.2 | Write and Maintain Policy Definitions                                   |
| 5.3 | Enforce and Verify Policies via GitHub Actions                          |
| 6   | **Artifact Signing and Verification**                                   |
| 6.1 | Sign Artifacts to Ensure Integrity                                      |
| 6.2 | Verify Signed Artifacts Before Promotion or Deployment                  |
| 7   | **SLSA Provenance Compliance**                                          |
| 7.1 | Generate SLSA Provenance with or without GitHub Actions                 |
| 7.2 | Verify Provenance to Maintain SLSA Compliance                           |
| 7.3 | Understand SLSA Levels and How to Progress Across Them                  |
| 8   | **Remediation and Reporting**                                           |
| 8.1 | Create and Use Remediation Trackers for Vulnerability Management        |
| 8.2 | View and Interpret License and Pipeline Execution Reports               |
| 8.3 | Label Components from Images for Better Tracking                        |
| 9   | **Access and Integration Management**                                   |
| 9.1 | Manage Role-Based Access Control (RBAC) and Permissions                 |
| 9.2 | Configure and Use Third-Party Integrations (SCM, CI/CD tools, scanners) |

</details>

**Next Steps**

The Supply Chain Security Developer exam can start immediately after registering. Please allow up to 90 mins for the exam.

1. Create an account in Harness University
2. Register for an exam
3. Take the exam

[**Register for Exam**](https://university-registration.harness.io/supply-chain-security-developer)
{% endtab %}

{% tab title="For Administrator" %}

### Supply Chain Security - Administrator (BETA COMING SOON)

![Supply Chain Security - Administrator (BETA COMING SOON) badge](https://2307127582-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Feh03Q8VHpO02MFM5nUSL%2Fuploads%2Fgit-blob-0e4bfb603b3bd275d49a3d5e7bab6b23c17ef795%2Fcert-adm-scs-badge.svg?alt=media)

**Product version:** Harness SCS Paid Plans

{% hint style="info" %}
**Coming soon**

This certification is in beta and not yet open for registration.
{% endhint %}

Assesses the fundamental skills to deploy and maintain SCS projects and the overall Harness Platform.
{% endtab %}

{% tab title="For Architect" %}

### Supply Chain Security - Architect (BETA COMING SOON)

![Supply Chain Security - Architect (BETA COMING SOON) badge](https://2307127582-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Feh03Q8VHpO02MFM5nUSL%2Fuploads%2Fgit-blob-d372046d21f7936b0c52052e59e95a5ad1ab788e%2Fcert-arc-scs-badge.svg?alt=media)

**Product version:** Harness SCS Paid Plans

{% hint style="info" %}
**Coming soon**

This certification is in beta and not yet open for registration.
{% endhint %}

Assess key technical job functions and advanced skills in design, implementation and management of SCS.
{% endtab %}
{% endtabs %}
