The reference of CSU_SA0 is relevant to "Programming Debug Challenge/Response Value Register (DCVR/DRVR)" for secure boot. If you are not enabling Secure Boot, the AN is not relevant.
Please keep in mind AN5227 is for ARMS A7 core, LS1046 is Arm A8 core, the setting will be different.
It may be a bit confusing, "TrustZone/Secure World" and "Secure debug controller" (Debug Challenge and Response Value Registers) are complimentary but "independent" features.
Debug Challenge and Response Value Registers only control whether one can use the JTAG port or not. It does not modify or impact Central Security Unit.
You can think of "Debug Challenge Value Register" and "Debug Response Value Register" as the userid and password to access the JTAG interface.