Application Security Testing - SCS
Learn Supply Chain Security through Harness University
Secure your SDLC and align them with industry-standard risk frameworks. Govern the use of open source with promotion and attestation policies.
Go to Harness University for the full catalogue of courses and certifications.
Self-Paced Training
Free self-paced courses that you can consume on your own time.
Instructor-Led Training
Intensive two-day courses are designed for engineers looking to deepen their understanding and expertise in Harness.
Certifications
Test and validate your knowledge of Harness by becoming a Harness Certified Expert.
Supply Chain Security - Developer
Product version: Harness SCS Paid Plans
Assesses the fundamental skills to manage your applications with SCS projects.
Review Study Guide
1. Introduction to Supply Chain Security with Harness
Understand SCS Overview and Key Concepts
Explore Onboarding Steps and Getting Started Guide
Review Supported Tools and Integrations
2. Repository and CI/CD Security Posture Management
Assess Repository Security Posture
Assess CI/CD Pipeline Security Posture
Use Insights to Prioritize Security Improvements
3. Managing Risk and Compliance
Understand Compliance Posture and Framework Mapping
Define and Apply Security Standards and Rules
Monitor Risk through Dashboards and Reports
4. Software Bill of Materials (SBOM) Generation and Ingestion
Generate SBOMs using Harness and GitHub Actions
Ingest SBOMs from External Tools (Aqua Trivy, Snyk, Blackduck)
Automate SBOM Drift Detection for GitHub Repositories
5. SBOM Policy Management
Create and Customize SBOM Policies
Write and Maintain Policy Definitions
Enforce and Verify Policies via GitHub Actions
6. Artifact Signing and Verification
Sign Artifacts to Ensure Integrity
Verify Signed Artifacts Before Promotion or Deployment
7. SLSA Provenance Compliance
Generate SLSA Provenance with or without GitHub Actions
Verify Provenance to Maintain SLSA Compliance
Understand SLSA Levels and How to Progress Across Them
8. Remediation and Reporting
Create and Use Remediation Trackers for Vulnerability Management
View and Interpret License and Pipeline Execution Reports
Label Components from Images for Better Tracking
9. Access and Integration Management
Manage Role-Based Access Control (RBAC) and Permissions
Configure and Use Third-Party Integrations (SCM, CI/CD tools, scanners)
Exam Details
The Supply Chain Security Developer exam tests your knowledge and skills of the Harness Supply Chain Security module.
Prerequisites
Basic terminal skills
Basic understanding of cloud security
Exam Details
Exam Duration: 90 minutes
Question Type: Multiple choice
Introduction to Supply Chain Security with Harness
10%
Repository and CI/CD Security Posture Management
15%
Managing Risk and Compliance
10%
Software Bill of Materials (SBOM) Generation and Ingestion
15%
SBOM Policy Management
20%
Artifact Signing and Verification
10%
SLSA Provenance Compliance
10%
Remediation and Reporting
5%
Access and Integration Management
5%
Exam Objectives
Next Steps
The Supply Chain Security Developer exam can start immediately after registering. Please allow up to 90 mins for the exam.
Create an account in Harness University
Register for an exam
Take the exam
Last updated
Was this helpful?