A handy script and step-by-step instructions on how to create a chroot jail. Additional programs can be added to the jailed account by copying over the executables plus all the libraries those executables use (as determined by ldd <executable>).
Upd: To let WinSCP work with a chrooted account, in some distros (e.g., FC>6) you need to disable the requiretty setting in /etc/sudoers