Software Composition Analysis (SCA) Glossary Definition

Term Software Composition Analysis (SCA)
Definition

Software Composition Analysis (SCA) identifies third-party components, open-source packages, licenses, and known vulnerabilities in software.

Software Composition Analysis (SCA) is a DevOps security concept that integrates security, compliance, and risk controls into software delivery and operational workflows.

Context & Usage

SCA supports software supply-chain risk management and helps maintain an accurate software bill of materials.

Security, development, and operations teams use this concept to make security checks continuous instead of treating them as a late-stage review.

Related concepts include DevOps, DevSecOps, Security Automation and Software Supply Chain.

Additional Resource: OWASP DevSecOps Guideline.

Related concepts include Dependency Management.

Categories Software Development and Programming, Web, Database, Cloud, and DevOps Technologies, Cybersecurity, Compliance, and Access Management