For the complete documentation index, see llms.txt. This page is also available as Markdown.

Application Security Testing - SCS

Learn Supply Chain Security through Harness University

Secure your SDLC and align them with industry-standard risk frameworks. Govern the use of open source with promotion and attestation policies.

Go to Harness University for the full catalogue of courses and certifications.

Self-Paced Training Instructor-Led Training Certifications

Self-Paced Training

Free self-paced courses that you can consume on your own time.

Instructor-Led Training

Intensive two-day courses are designed for engineers looking to deepen their understanding and expertise in Harness.

Certifications

Test and validate your knowledge of Harness by becoming a Harness Certified Expert.

Supply Chain Security - Developer

Supply Chain Security - Developer badge

Product version: Harness SCS Paid Plans

Assesses the fundamental skills to manage your applications with SCS projects.

Review Study Guide

Topic
Material

1. Introduction to Supply Chain Security with Harness

Understand SCS Overview and Key Concepts

Explore Onboarding Steps and Getting Started Guide

Review Supported Tools and Integrations

2. Repository and CI/CD Security Posture Management

Assess Repository Security Posture

Assess CI/CD Pipeline Security Posture

Use Insights to Prioritize Security Improvements

3. Managing Risk and Compliance

Understand Compliance Posture and Framework Mapping

Define and Apply Security Standards and Rules

Monitor Risk through Dashboards and Reports

4. Software Bill of Materials (SBOM) Generation and Ingestion

Generate SBOMs using Harness and GitHub Actions

Ingest SBOMs from External Tools (Aqua Trivy, Snyk, Blackduck)

Automate SBOM Drift Detection for GitHub Repositories

5. SBOM Policy Management

Create and Customize SBOM Policies

Write and Maintain Policy Definitions

Enforce and Verify Policies via GitHub Actions

6. Artifact Signing and Verification

Sign Artifacts to Ensure Integrity

Verify Signed Artifacts Before Promotion or Deployment

7. SLSA Provenance Compliance

Generate SLSA Provenance with or without GitHub Actions

Verify Provenance to Maintain SLSA Compliance

Understand SLSA Levels and How to Progress Across Them

8. Remediation and Reporting

Create and Use Remediation Trackers for Vulnerability Management

View and Interpret License and Pipeline Execution Reports

Label Components from Images for Better Tracking

9. Access and Integration Management

Manage Role-Based Access Control (RBAC) and Permissions

Configure and Use Third-Party Integrations (SCM, CI/CD tools, scanners)

Register for Exam

Exam Details

The Supply Chain Security Developer exam tests your knowledge and skills of the Harness Supply Chain Security module.

Prerequisites

  • Basic terminal skills

  • Basic understanding of cloud security

Exam Details

Exam Duration: 90 minutes

Question Type: Multiple choice

Covered Domain
Percentage

Introduction to Supply Chain Security with Harness

10%

Repository and CI/CD Security Posture Management

15%

Managing Risk and Compliance

10%

Software Bill of Materials (SBOM) Generation and Ingestion

15%

SBOM Policy Management

20%

Artifact Signing and Verification

10%

SLSA Provenance Compliance

10%

Remediation and Reporting

5%

Access and Integration Management

5%

Exam Objectives

List of Objectives

The following is a detailed list of exam objectives:

#
Objectives

1

Introduction to Supply Chain Security with Harness

1.1

Understand SCS Overview and Key Concepts

1.2

Explore Onboarding Steps and Getting Started Guide

1.3

Review Supported Tools and Integrations

2

Repository and CI/CD Security Posture Management

2.1

Assess Repository Security Posture

2.2

Assess CI/CD Pipeline Security Posture

2.3

Use Insights to Prioritize Security Improvements

3

Managing Risk and Compliance

3.1

Understand Compliance Posture and Framework Mapping

3.2

Define and Apply Security Standards and Rules

3.3

Monitor Risk through Dashboards and Reports

4

Software Bill of Materials (SBOM) Generation and Ingestion

4.1

Generate SBOMs using Harness and GitHub Actions

4.2

Ingest SBOMs from External Tools (Aqua Trivy, Snyk, Blackduck)

4.3

Automate SBOM Drift Detection for GitHub Repositories

5

SBOM Policy Management

5.1

Create and Customize SBOM Policies

5.2

Write and Maintain Policy Definitions

5.3

Enforce and Verify Policies via GitHub Actions

6

Artifact Signing and Verification

6.1

Sign Artifacts to Ensure Integrity

6.2

Verify Signed Artifacts Before Promotion or Deployment

7

SLSA Provenance Compliance

7.1

Generate SLSA Provenance with or without GitHub Actions

7.2

Verify Provenance to Maintain SLSA Compliance

7.3

Understand SLSA Levels and How to Progress Across Them

8

Remediation and Reporting

8.1

Create and Use Remediation Trackers for Vulnerability Management

8.2

View and Interpret License and Pipeline Execution Reports

8.3

Label Components from Images for Better Tracking

9

Access and Integration Management

9.1

Manage Role-Based Access Control (RBAC) and Permissions

9.2

Configure and Use Third-Party Integrations (SCM, CI/CD tools, scanners)

Next Steps

The Supply Chain Security Developer exam can start immediately after registering. Please allow up to 90 mins for the exam.

  1. Create an account in Harness University

  2. Register for an exam

  3. Take the exam

Register for Exam

Supply Chain Security - Administrator (BETA COMING SOON)

Supply Chain Security - Administrator (BETA COMING SOON) badge

Product version: Harness SCS Paid Plans

Coming soon

This certification is in beta and not yet open for registration.

Assesses the fundamental skills to deploy and maintain SCS projects and the overall Harness Platform.

Supply Chain Security - Architect (BETA COMING SOON)

Supply Chain Security - Architect (BETA COMING SOON) badge

Product version: Harness SCS Paid Plans

Coming soon

This certification is in beta and not yet open for registration.

Assess key technical job functions and advanced skills in design, implementation and management of SCS.

Last updated

Was this helpful?