Certified SCA Practitioner (CSCAP) Syllabus

You can download the CSCAP syllabus from: https://securecodealliance.com/content/sca-practitioner.pdf
About The CSCAP
CSCAPs are expected to: (1) Understand and operationalize the organization’s security architecture that must be followed for application development processes for development, testing, staging, and production environments. (2) Incorporate the organization’s risk management practices throughout application development processes across the entire Software/System Development Life Cycle (SDLC). (3) Develop software applications in accordance with industry-recognized secure coding practices. (4) Incorporate security and privacy measures throughout the SDLC. (5) Control changes to applications, systems, and processes across the SDLC using formal change control procedures. (6) Review custom code through a formal change management and approval process prior to release to production. (7) Remove custom application accounts, user IDs and passwords before applications become active or are released to customers. (8) Confidently review Software Bill of Materials (SBOM) documentation for security and privacy-related implications. (9) Perform software conformity assessments.
Certified SCA Practitioner (CSCAP) Course Curriculum
-
1
Secure Code Alliance (SCA) Overview
-
(Included in full purchase)
What Is The SCA?
-
(Included in full purchase)
What Is The Developing Security & Privacy by Design (DSPD) Initiative?
-
(Included in full purchase)
-
2
Certified SCA Practitioner (CSCAP) Overview
-
(Included in full purchase)
CSCAP Expectations
-
(Included in full purchase)
Baselining The Concept of Compliant vs Secure
-
(Included in full purchase)
Key Learning Objectives
-
(Included in full purchase)
End Of Chapter Review
-
(Included in full purchase)
-
3
Executive Order (EO) 14028
-
(Included in full purchase)
EO 14028 Overview
-
(Included in full purchase)
CISA Secure Software Development Attestation Form
-
(Included in full purchase)
End Of Chapter Review
-
(Included in full purchase)
-
4
NIST SP 800-218 - Secure Software Development Framework (SSDF)
-
(Included in full purchase)
NIST SP 800-218 Overview
-
(Included in full purchase)
SSDF Organization & Practices
-
(Included in full purchase)
SSDF Applicability
-
(Included in full purchase)
End Of Chapter Review
-
(Included in full purchase)
-
5
NIST SP 800-218A - SSDP for Generative AI and Dual-Use Foundation Models
-
(Included in full purchase)
NIST SP 800-218A Overview
-
(Included in full purchase)
End Of Chapter Review
-
(Included in full purchase)
-
6
NIST SP 800-160 - Secure Engineering & Resiliency
-
(Included in full purchase)
NIST SP 800-160 Overview
-
(Included in full purchase)
NIST SP 800-160 Vol. 1 - Engineering Trustworthy Secure Systems
-
(Included in full purchase)
NIST SP 800-160 Vol. 2 - Developing Cyber-Resilient Systems
-
(Included in full purchase)
End Of Chapter Review
-
(Included in full purchase)
-
7
OWASP Top 10
-
(Included in full purchase)
OWASP Top 10 Overview
-
(Included in full purchase)
End Of Chapter Review
-
(Included in full purchase)
-
8
Software Bill of Materials (SBOM)
-
(Included in full purchase)
SBOM Best Practices
-
(Included in full purchase)
SBOM Benefits
-
(Included in full purchase)
Current State of SBOMs
-
(Included in full purchase)
-
9
SDP-Related Compliance Requirements
-
(Included in full purchase)
SDP Requirements Overview
-
(Included in full purchase)
Executive Order (EO) 14028 - Application Security Controls
-
(Included in full purchase)
NIST SP 800-171 - Application Security Controls
-
(Included in full purchase)
NIST SP 800-53 - Application Security Controls
-
(Included in full purchase)
Payment Card Industry Data Security Standard (PCI DSS) v4.0 - Application Security Controls
-
(Included in full purchase)
Center for Internet Security Critical Security Controls (CIS CSC)
-
(Included in full purchase)
ISO 27002:2022 - Application Security Controls
-
(Included in full purchase)
CISA - SBOM Guidance
-
(Included in full purchase)
Digital Millennium Copyright Act (DCMA)
-
(Included in full purchase)
-
10
CSCAP Knowledge Exam
-
(Included in full purchase)
SCA Practitioner Knowledge Exam
-
(Included in full purchase)