Certified SCA Architect (CSCAA) Syllabus

SCA Architect Syllabus

You can download the CSCAA syllabus from: https://securecodealliance.com/content/sca-architect.pdf

About The CSCAA

CSCAA's are expected to: (1) Define the security architecture(s) the organization will follow for application development processes. (2) Define application development considerations for the organization’s risk management practices across the entire Software/System Development Life Cycle (SDLC). (3) Publish rules for the organization’s application development processes for development, testing, staging, and production environments. (4) Develop conformity assessment practices for the organization to follow in order to demonstrate alignment with stated Secure Software Development Practices. (5) Ensure that information security and privacy principles are an integral part of Secure Software Development Practices (SSDP) across the entire SDLC. (6) Ensure security & privacy-related measures are included in the requirements for new systems or enhancements to existing systems. (7) Ensure application development practices (internal and external) adhere to industry-recognized secure coding practices. (8) Develop Software Bill of Materials (SBOM) documentation for application development projects. (9) Oversee changes to Applications, Services and Processes (ASP) across the SDLC using formal change control procedures. (10) Oversee application security testing practices. (11) Implement the SSDP concepts and techniques for all High-Value Assets (HVA):  - New Systems;  - Dedicated or Special-Purpose Systems;  - System of Systems;  - System Modifications;  - System Evolution; and  - System Retirement.

Certified SCA Architect (CSCAA) Course Curriculum

  1. 1

    Secure Code Alliance (SCA) Overview

    1. (Included in full purchase)
    2. (Included in full purchase)
  2. 2

    Certified SCA Architect (CSCAA) Overview

    1. (Included in full purchase)
    2. (Included in full purchase)
    3. (Included in full purchase)
    4. (Included in full purchase)
  3. 3

    Executive Order (EO) 14028

    1. (Included in full purchase)
    2. (Included in full purchase)
    3. (Included in full purchase)
  4. 4

    NIST SP 800-218 - Secure Software Development Framework (SSDF)

    1. (Included in full purchase)
    2. (Included in full purchase)
    3. (Included in full purchase)
    4. (Included in full purchase)
  5. 5

    NIST SP 800-218A - SSDP for Generative AI and Dual-Use Foundation Models

    1. (Included in full purchase)
    2. (Included in full purchase)
  6. 6

    NIST SP 800-160 - Secure Engineering & Resiliency

    1. (Included in full purchase)
    2. (Included in full purchase)
    3. (Included in full purchase)
    4. (Included in full purchase)
    5. (Included in full purchase)
    6. (Included in full purchase)
  7. 7

    OWASP Top 10

    1. (Included in full purchase)
    2. (Included in full purchase)
  8. 8

    Software Bill of Materials (SBOM)

    1. (Included in full purchase)
    2. (Included in full purchase)
    3. (Included in full purchase)
  9. 9

    Secure Development Practice (SDP)-Related Compliance Requirements

    1. (Included in full purchase)
    2. (Included in full purchase)
    3. (Included in full purchase)
    4. (Included in full purchase)
    5. (Included in full purchase)
    6. (Included in full purchase)
    7. (Included in full purchase)
    8. (Included in full purchase)
    9. (Included in full purchase)
  10. 10

    CSCAA Exam

    1. (Included in full purchase)