Certified SCA Architect (CSCAA) Syllabus

You can download the CSCAA syllabus from: https://securecodealliance.com/content/sca-architect.pdf
About The CSCAA
CSCAA's are expected to: (1) Define the security architecture(s) the organization will follow for application development processes. (2) Define application development considerations for the organization’s risk management practices across the entire Software/System Development Life Cycle (SDLC). (3) Publish rules for the organization’s application development processes for development, testing, staging, and production environments. (4) Develop conformity assessment practices for the organization to follow in order to demonstrate alignment with stated Secure Software Development Practices. (5) Ensure that information security and privacy principles are an integral part of Secure Software Development Practices (SSDP) across the entire SDLC. (6) Ensure security & privacy-related measures are included in the requirements for new systems or enhancements to existing systems. (7) Ensure application development practices (internal and external) adhere to industry-recognized secure coding practices. (8) Develop Software Bill of Materials (SBOM) documentation for application development projects. (9) Oversee changes to Applications, Services and Processes (ASP) across the SDLC using formal change control procedures. (10) Oversee application security testing practices. (11) Implement the SSDP concepts and techniques for all High-Value Assets (HVA): - New Systems; - Dedicated or Special-Purpose Systems; - System of Systems; - System Modifications; - System Evolution; and - System Retirement.
Certified SCA Architect (CSCAA) Course Curriculum
-
1
Secure Code Alliance (SCA) Overview
-
(Included in full purchase)
What Is The SCA?
-
(Included in full purchase)
What Is The Developing Security & Privacy by Design (DSPD) Initiative?
-
(Included in full purchase)
-
2
Certified SCA Architect (CSCAA) Overview
-
(Included in full purchase)
CSCAA Expectations
-
(Included in full purchase)
Baselining The Concept of Compliant vs Secure
-
(Included in full purchase)
Key Learning Objectives
-
(Included in full purchase)
End Of Chapter Review
-
(Included in full purchase)
-
3
Executive Order (EO) 14028
-
(Included in full purchase)
EO 14028 Overview
-
(Included in full purchase)
CISA Secure Software Development Attestation Form
-
(Included in full purchase)
End Of Chapter Review
-
(Included in full purchase)
-
4
NIST SP 800-218 - Secure Software Development Framework (SSDF)
-
(Included in full purchase)
NIST SP 800-218 Overview
-
(Included in full purchase)
SSDF Organization & Practices
-
(Included in full purchase)
SSDF Applicability
-
(Included in full purchase)
End Of Chapter Review
-
(Included in full purchase)
-
5
NIST SP 800-218A - SSDP for Generative AI and Dual-Use Foundation Models
-
(Included in full purchase)
NIST SP 800-218A Overview
-
(Included in full purchase)
End Of Chapter Review
-
(Included in full purchase)
-
6
NIST SP 800-160 - Secure Engineering & Resiliency
-
(Included in full purchase)
NIST SP 800-160 Overview
-
(Included in full purchase)
NIST SP 800-160 Vol. 1 - Engineering Trustworthy Secure Systems
-
(Included in full purchase)
NIST SP 800-160 Vol. 2 - Developing Cyber-Resilient Systems
-
(Included in full purchase)
Secure Development Lifecycle (SDL)
-
(Included in full purchase)
Microsoft Operational Security Practices
-
(Included in full purchase)
End Of Chapter Review
-
(Included in full purchase)
-
7
OWASP Top 10
-
(Included in full purchase)
OWASP Top 10 Overview
-
(Included in full purchase)
End Of Chapter Review
-
(Included in full purchase)
-
8
Software Bill of Materials (SBOM)
-
(Included in full purchase)
SBOM Best Practices
-
(Included in full purchase)
SBOM Benefits
-
(Included in full purchase)
Current State of SBOMs
-
(Included in full purchase)
-
9
Secure Development Practice (SDP)-Related Compliance Requirements
-
(Included in full purchase)
SDP Requirements Overview
-
(Included in full purchase)
Executive Order (EO) 14028 - Application Security Controls
-
(Included in full purchase)
NIST SP 800-171 - Application Security Controls
-
(Included in full purchase)
NIST SP 800-53 - Application Security Controls
-
(Included in full purchase)
Payment Card Industry Data Security Standard (PCI DSS) v4.0 - Application Security Controls
-
(Included in full purchase)
Center for Internet Security Critical Security Controls (CIS CSC)
-
(Included in full purchase)
ISO 27002:2022 - Application Security Controls
-
(Included in full purchase)
CISA - SBOM Guidance
-
(Included in full purchase)
Digital Millennium Copyright Act (DCMA)
-
(Included in full purchase)
-
10
CSCAA Exam
-
(Included in full purchase)
SCA Architect Knowledge Exam
-
(Included in full purchase)