SCA
Software Composition Analysis
Software Composition Analysis identifies open-source and third-party components in a codebase and checks them against vulnerability databases. SCA tools track dependency trees, flag outdated libraries, verify license compliance, and alert teams when new CVEs affect their software supply chain.
Cómo se usa en ciberseguridad
Security engineers integrate SCA into CI/CD pipelines to block builds that include vulnerable dependencies. GRC analysts review SCA reports to confirm third-party component risk stays within acceptable thresholds. Security architects select and standardize SCA tools across development teams to ensure consistent supply chain visibility.
Término relacionado en el glosario: sca
Las definiciones son explicaciones originales escritas con fines de desarrollo profesional. Para definiciones técnicas autorizadas, consulta NIST, ISO o el organismo de normalización correspondiente.