Security Journey Announced Support for WCAG and SCIM
December 05, 2023

Security Journey announced support for WCAG, SCIM and continued compliance with SOC2 Type 2, which are leading industry standards.

The new capabilities mean large enterprises can now provide application security education to their development teams from a platform that meets security, global accessibility, and automated user provisioning requirements. These features ensure that in-depth training programs are provided to all learners including those who are sight and hearing-impaired, streamline user access and lifecycle management, and provide additional assurances on the rigorous security of the platform itself.

Specifically, the Security Journey platform now supports:

Web Content Accessibility Guidelines (WCAG), Section 508 (US) and EN 301 549 (EU)*

- These accessibility standards/guidelines focus on ensuring web content such as text, images, sounds, code or markup that defines structure and presentation can be understood by people with disabilities.

- Security Journey lessons now provide captions and “alt text” for images so that learners can see and hear content using assistive technologies.

- Learner interface and over 800 lessons have accessibility features.

- This is an industry first for an application security training provider.

System for Cross-Domain Identity Management (SCIM)

- SCIM is an open standard for automating user provisioning across domains, reducing the time and complexity typically associated with the process.

- It removes the need for manual user management and minimizes human error, meaning program admins can spend more time with learners.

System and Organization Controls (SOC) 2 Type 2

- SOC 2 is an international standard designed to help service organizations provide assurance about their security, availability, processing integrity, confidentiality, and privacy controls.

- Security Journey customers can be confident that their sensitive data will be handled in line with industry best practices.

*The technical requirements of the Section 508 procurement law in the US refer to WCAG for web content, documents and software. Similarly, EN 301 549 is the technical standard that allows the European Commission to enforce policies across Europe.

Security Journey CEO, Joe Ferrara, said, “I believe this marks a new maturity level in the market – making it appealing for large enterprises to move from less effective home-grown training to an in-depth progressive program built by AppSec experts.”

Share this

Industry News

April 17, 2025

GitLab announced the general availability of GitLab Duo with Amazon Q.

April 17, 2025

Perforce Software and Liquibase announced a strategic partnership to enhance secure and compliant database change management for DevOps teams.

April 17, 2025

Spacelift announced the launch of Saturnhead AI — an enterprise-grade AI assistant that slashes DevOps troubleshooting time by transforming complex infrastructure logs into clear, actionable explanations.

April 16, 2025

CodeSecure and FOSSA announced a strategic partnership and native product integration that enables organizations to eliminate security blindspots associated with both third party and open source code.

April 16, 2025

Bauplan, a Python-first serverless data platform that transforms complex infrastructure processes into a few lines of code over data lakes, announced its launch with $7.5 million in seed funding.

April 15, 2025

Perforce Software announced the launch of the Kafka Service Bundle, a new offering that provides enterprises with managed open source Apache Kafka at a fraction of the cost of traditional managed providers.

April 14, 2025

LambdaTest announced the launch of the HyperExecute MCP Server, an enhancement to its AI-native test orchestration platform, HyperExecute.

April 14, 2025

Cloudflare announced Workers VPC and Workers VPC Private Link, new solutions that enable developers to build secure, global cross-cloud applications on Cloudflare Workers.

April 14, 2025

Nutrient announced a significant expansion of its cloud-based services, as well as a series of updates to its SDK products, aimed at enhancing the developer experience by allowing developers to build, scale, and innovate with less friction.

April 10, 2025

Check Point® Software Technologies Ltd.(link is external) announced that its Infinity Platform has been named the top-ranked AI-powered cyber security platform in the 2025 Miercom Assessment.

April 10, 2025

Orca Security announced the Orca Bitbucket App, a cloud-native seamless integration for scanning Bitbucket Repositories.

April 10, 2025

The Live API for Gemini models is now in Preview, enabling developers to start building and testing more robust, scalable applications with significantly higher rate limits.

April 09, 2025

Backslash Security(link is external) announced significant adoption of the Backslash App Graph, the industry’s first dynamic digital twin for application code.

April 09, 2025

SmartBear launched API Hub for Test, a new capability within the company’s API Hub, powered by Swagger.

April 09, 2025

Akamai Technologies introduced App & API Protector Hybrid.