Secure Controls Framework
SCA Body of Knowledge

The foundation of SCA certification.

The SCA-BoK is a summarized version of industry-recognized secure practices that provides expectations for knowledge / competency associated with the Certified SCA Practitioner (CSCAP) and Certified SCA Architect (CSCAA) roles.

✓ Freely Available
✓ Voluntary Consensus Standards
✓ Foundation for CSCAP & CSCAA
What is the SCA-BoK

A summarized reference of secure practices.

The SCA-BoK is a summarized version of these industry-recognized secure practices that provides expectations for knowledge / competency associated with the Certified SCA Practitioner (CSCAP) and Certified SCA Architect (CSCAA) roles.

For industry-recognized secure practices, the SCA's intent is to leverage freely-available content that are available at no cost to the public.

The SCA references numerous leading frameworks and standards for Secure Software Development Practices (SSDP) in an effort to provide “industry-recognized secure practices” references. These voluntary consensus standards, most publicly available at no cost, are referenced by the SCA's Body of Knowledge.

The global nature of software development also means that the English language is often not the native language for developers. Given this understanding of the global workforce and how collaboration efforts exist in software development, the practice of being able to openly reference content should be seen as an industry norm.

Referenced Frameworks & Standards

Built on voluntary consensus standards.

The SCA-BoK summarizes and references the following industry-recognized frameworks. Most are publicly available at no cost.

NIST SP 800-218 (SSDF)
NIST SP 800-53
NIST SP 800-160
NIST SP 800-161
NIST SP 800-171
EO 14028
CISA SSDAF
PCI DSS v4
CIS v8
CMMC
ISO 27002
OWASP Top Ten
OWASP ASVS
FREE
Open access by design
The SCA's intent is to leverage freely-available content available at no cost to the public — making the body of knowledge accessible to the global developer community.
SUMMARIZED
A practical synthesis
Rather than asking practitioners to read every framework end-to-end, the BoK distills the most relevant SSDP expectations into one reference.
GLOBAL
Global developer audience
The practice of being able to openly reference content is treated as an industry norm — recognizing that English isn't the native language for many developers.
Who the BoK Serves

Expectations for two roles.

The BoK defines knowledge and competency expectations for the two SCA individual certifications.

CSCAP

Practitioner expectations

Knowledge and competency expectations for the Certified SCA Practitioner — the developer-facing certification grounded in Secure Development Lifecycle (SDL) processes.

View CSCAP scope
CSCAA

Architect expectations

Knowledge and competency expectations for the Certified SCA Architect — covering cyber-resiliency constructs, design principles, and lifecycle processes.

View CSCAA scope

Read the SCA-BoK.

The full Body of Knowledge document is available as a free PDF. Use it to prepare for the CSCAP or CSCAA exam, or to align your team's secure development practices with industry standards.