DevSecOps for Secure Software Development: A Systematic Literature Review of Practices, Benefits, and Adoption Barriers

Authors

DOI:

https://doi.org/10.61467/2007.1558.2026.v17i4.1299

Keywords:

DevSecOps, secure software development, software development life cycle, systematic literature review, desarrollo seguro de software, ciclo de vida del desarrollo de software, revisión sistemática de la literatura

Abstract

The implementation of DevSecOps has emerged as an essential strategy for incorporating security from the early stages of software development. Its adoption allows for reducing vulnerabilities, streamlining threat detection, and complying with security regulations. Using a Systematic Literature Review, the study retrieved thirty research articles that met the requirements for inclusion in the review. The objective is to provide an overview of the current state of existing empirical studies on DevSecOps practices, which can help define strengths and areas of opportunity, and allow for planning future studies. Finally, studies reveal several advantages to adopting the DevSecOps approach, such as creating more secure and resilient software, improving cybersecurity defenses, and fostering a safe and open culture through communication and collaboration among development teams. However, the literature highlighted specific challenges or barriers to adopting this approach, such as organizational resistance, cultural transformations, and the complexity of implementing new security tools and procedures.

 

Spanish-language metadata / Metadatos en español
Título en español:

DevSecOps para el desarrollo seguro de software: una revisión sistemática de la literatura sobre prácticas, beneficios y barreras de adopción
Resumen:

La implementación de DevSecOps se ha consolidado como una estrategia esencial para incorporar la seguridad desde las primeras etapas del desarrollo de software. Su adopción permite reducir vulnerabilidades, agilizar la detección de amenazas y cumplir con las normativas de seguridad. Mediante una revisión sistemática de la literatura, el estudio recuperó treinta artículos de investigación que cumplieron los criterios de inclusión establecidos. El objetivo es ofrecer una visión general del estado actual de los estudios empíricos existentes sobre las prácticas de DevSecOps, con el fin de identificar sus fortalezas y áreas de oportunidad, así como facilitar la planificación de futuras investigaciones. Finalmente, los estudios revelan varias ventajas asociadas con la adopción del enfoque DevSecOps, entre ellas el desarrollo de software más seguro y resiliente, la mejora de las defensas de ciberseguridad y el fomento de una cultura segura y abierta mediante la comunicación y la colaboración entre los equipos de desarrollo. Sin embargo, la literatura también destaca desafíos o barreras específicas para la adopción de este enfoque, como la resistencia organizacional, las transformaciones culturales y la complejidad de implementar nuevas herramientas y procedimientos de seguridad.

Palabras Claves:

DevSecOps; desarrollo seguro de software; ciclo de vida del desarrollo de software; revisión sistemática de la literatura; seguridad por diseño; seguridad continua; prácticas de seguridad del software; resiliencia de ciberseguridad; detección de amenazas; barreras para la adopción de DevSecOps; cultura organizacional; automatización de la seguridad.

 


Smart citations:

https://scite.ai/reports/10.61467/2007.1558.2026.v17i4.1299
Dimensions.
Open Alex.

Author Biographies

Patricia Martínez-Moreno, Universidad Veracruzana

Full-time professor in the software engineering department

José Antonio Vergara-Camacho, Universidad Veracruzana

Full-time professor in the software engineering department

Víctor Adrián Lueváno-Mondragon, Universidad Veracruzana

Software engineering department

Karla Alejandra Jiménez-Martínez

Department of Computer Systems Engineering

References

Akbar, M. A., Khan, A. A., Mahmood, S., & Hyrynsalmi, S. (2025). Management of DevSecOps process: An empirical investigation. Software: Practice and Experience, 55(7), 1234–1255. https://doi.org/10.1002/spe.3419

Akbar, M. A., Rafi, S., Hyrynsalmi, S., & Khan, A. A. (2024). Towards people maturity for secure development and operations: A vision. In Proceedings of the 28th International Conference on Evaluation and Assessment in Software Engineering (pp. 528–533). Association for Computing Machinery. https://doi.org/10.1145/3661167.3661238

Alawneh, M., & Abbadi, I. M. (2022). Expanding DevSecOps practices and clarifying the concepts within Kubernetes ecosystem. In 2022 Ninth International Conference on Software Defined Systems (SDS) (pp. 1–7). IEEE. https://doi.org/10.1109/SDS57574.2022.10062874

Ashenden, D., & Ollis, G. (2020). Putting the Sec in DevSecOps: Using social practice theory to improve secure software development. In Proceedings of the New Security Paradigms Workshop 2020 (pp. 34–44). Association for Computing Machinery. https://doi.org/10.1145/3442167.3442178

Azad, N., & Hyrynsalmi, S. (2024). Multivocal literature review on DevOps critical success factors. In Proceedings of the 28th International Conference on Evaluation and Assessment in Software Engineering (pp. 520–527). Association for Computing Machinery. https://doi.org/10.1145/3661167.3661236

Barrak, A., Ksontini, E., Atike, R., & Jaafar, F. (2025). FaaSGuard: Secure CI/CD for serverless applications—An OpenFaaS case study [Preprint]. arXiv. https://doi.org/10.48550/arXiv.2509.04328

Billawa, P., Tukaram, A. B., Díaz Ferreyra, N. E., Steghöfer, J.-P., Scandariato, R., & Simhandl, G. (2022). SoK: Security of microservice applications: A practitioners’ perspective on challenges and best practices. In Proceedings of the 17th International Conference on Availability, Reliability and Security (pp. 1–10). Association for Computing Machinery. https://doi.org/10.1145/3538969.3538986

Burkard, E. C. (2020). Usability testing within a DevSecOps environment. In 2020 Integrated Communications Navigation and Surveillance Conference (ICNS) (pp. 1C1-1–1C1-7). IEEE. https://doi.org/10.1109/ICNS50378.2020.9222919

Cankar, M., Petrović, N., Pita Costa, J., Černivec, A., Antić, J., Martinčič, T., & Štepec, D. (2023). Security in DevSecOps: Applying tools and machine learning to verification and monitoring steps. In Companion of the 2023 ACM/SPEC International Conference on Performance Engineering (pp. 201–205). Association for Computing Machinery. https://doi.org/10.1145/3578245.3584943

Cheenepalli, J., Hastings, J. D., Ahmed, K. M., & Fenner, C. R. (2025). Advancing DevSecOps in SMEs: Challenges and best practices for secure CI/CD pipelines. In 2025 13th International Symposium on Digital Forensics and Security (ISDFS) (pp. 1–6). IEEE. https://doi.org/10.1109/ISDFS65363.2025.11011960

Chen, M., Liang, B., & Lu, X. (2024). The practice and application of a novel DevSecOps platform on security. In 2024 5th International Seminar on Artificial Intelligence, Networking and Information Technology (AINIT) (pp. 558–562). IEEE. https://doi.org/10.1109/AINIT61980.2024.10581700

Chen, T., & Suo, H. (2022). Design and practice of security architecture via DevSecOps technology. In 2022 IEEE 13th International Conference on Software Engineering and Service Science (ICSESS) (pp. 310–313). IEEE. https://doi.org/10.1109/ICSESS54813.2022.9930212

Díaz, J., Pérez, J. E., Lopez-Peña, M. A., Mena, G. A., & Yagüe, A. (2019). Self-service cybersecurity monitoring as enabler for DevSecOps. IEEE Access, 7, 100283–100295. https://doi.org/10.1109/ACCESS.2019.2930000

Feio, C., Santos, N., Escravana, N., & Pacheco, B. (2024). An empirical study of DevSecOps focused on continuous security testing. In 2024 IEEE European Symposium on Security and Privacy Workshops (EuroS&PW) (pp. 610–617). IEEE. https://doi.org/10.1109/EuroSPW61312.2024.00074

Grigorieva, N. M., Petrenko, A. S., & Petrenko, S. A. (2024). Development of secure software based on the new DevSecOps technology. In 2024 Conference of Young Researchers in Electrical and Electronic Engineering (ElCon) (pp. 158–161). IEEE. https://doi.org/10.1109/ElCon61730.2024.10468425

Haverinen, H., Janhunen, T., Päivärinta, T., Lempinen, S., Kaartinen, S., & Merilä, S. (2024). Automating cybersecurity compliance in DevSecOps with open information model for security as code. In Proceedings of the 4th Eclipse Security, AI, Architecture and Modelling Conference on Data Space (pp. 93–102). Association for Computing Machinery. https://doi.org/10.1145/3685651.3686700

Hermann, K., Peldszus, S., Steghöfer, J.-P., & Berger, T. (2025). An exploratory study on the engineering of security features. In 2025 IEEE/ACM 47th International Conference on Software Engineering (ICSE) (pp. 2470–2482). IEEE. https://doi.org/10.1109/ICSE55347.2025.00184

Kitchenham, B., & Charters, S. (2007). Guidelines for performing systematic literature reviews in software engineering (EBSE Technical Report EBSE-2007-01). Keele University.

Kwon, S., Son, W., & Lee, J.-H. (2025). Anomaly detection in containerized tactical systems using temporal graph neural networks. In MILCOM 2025—IEEE Military Communications Conference (pp. 1566–1571). IEEE. https://doi.org/10.1109/MILCOM64451.2025.11310523

Lazarus, J. I., Truett, L., Fischer, B., & Kershner, C. (2024). DevSecOps process assessment collaboration tool: A novel method to inject R&M into Agile development. In 2024 Annual Reliability and Maintainability Symposium (RAMS) (pp. 1–5). IEEE. https://doi.org/10.1109/RAMS51492.2024.10457824

Le-Thanh, P., Le-Anh, T., & Le-Trung, Q. (2023). Research and development of a smart solution for runtime web application self-protection. In Proceedings of the 12th International Symposium on Information and Communication Technology (pp. 304–311). Association for Computing Machinery. https://doi.org/10.1145/3628797.3628901

Mahboob, J., & Coffman, J. (2021). A Kubernetes CI/CD pipeline with Asylo as a trusted execution environment abstraction framework. In 2021 IEEE 11th Annual Computing and Communication Workshop and Conference (CCWC) (pp. 529–535). IEEE. https://doi.org/10.1109/CCWC51732.2021.9376148

Marandi, M., Bertia, A., & Silas, S. (2023). Implementing and automating security scanning to a DevSecOps CI/CD pipeline. In 2023 World Conference on Communication & Computing (WCONF) (pp. 1–6). IEEE. https://doi.org/10.1109/WCONF58270.2023.10235015

Morales, J. A., & Yasar, H. (2023). Experiences with secure pipelines in highly regulated environments. In Proceedings of the 18th International Conference on Availability, Reliability and Security (Article 57, pp. 1–9). Association for Computing Machinery. https://doi.org/10.1145/3600160.3605466

Morales, J. A., Scanlon, T. P., Volkmann, A., Yankel, J., & Yasar, H. (2020). Security impacts of sub-optimal DevSecOps implementations in a highly regulated environment. In Proceedings of the 15th International Conference on Availability, Reliability and Security (Article 63, pp. 1–8). Association for Computing Machinery. https://doi.org/10.1145/3407023.3409186

Moyón, F., Angermeir, F., & Mendez, D. (2024). Industrial challenges in secure continuous development. In Proceedings of the 46th IEEE/ACM International Conference on Software Engineering: Software Engineering in Practice (pp. 309–311). Association for Computing Machinery. https://doi.org/10.1145/3639477.3639736

Nadgowda, S., & Luan, L. (2021). Tapiserí: Blueprint to modernize DevSecOps for real world. In Proceedings of the Seventh International Workshop on Container Technologies and Container Clouds (pp. 13–18). Association for Computing Machinery. https://doi.org/10.1145/3493649.3493655

Nagasundari, S., Manja, P., Mathur, P., & Honnavalli, P. B. (2025). Extensive review of threat models for DevSecOps. IEEE Access, 13, 45252–45271. https://doi.org/10.1109/ACCESS.2025.3547932

Nugraha, A. D. P., & Irsan, M. (2025). Integrating self-protection into DevSecOps framework for defense against threat. In 2025 International Conference on Software Engineering and Computer Systems (ICSECS) (pp. 287–291). IEEE. https://doi.org/10.1109/ICSECS65227.2025.11279258

Orosz, M., Spear, G., Duffy, B., & Charlton, C. (2022). Merging Agile/DevSecOps into the US DoD space acquisition environment—A multiple case study. INSIGHT, 25(4), 96–99. https://doi.org/10.1002/inst.12420

Patel, A., Laudya, R., Ragothaman, H., Udayakumar, S. K., Pandey, P., & Sheth, A. (2025). Dynamic secret injection for microservices in the cloud. In 2025 8th International Conference on Information and Computer Technologies (ICICT) (pp. 72–79). IEEE. https://doi.org/10.1109/ICICT64582.2025.00018

Pecka, N., Ben Othmane, L., & Valani, A. (2022). Privilege escalation attack scenarios on the DevOps pipeline within a Kubernetes environment. In Proceedings of the International Conference on Software and System Processes and International Conference on Global Software Engineering (pp. 45–49). Association for Computing Machinery. https://doi.org/10.1145/3529320.3529325

Petersen, K., Vakkalanka, S., & Kuzniarz, L. (2015). Guidelines for conducting systematic mapping studies in software engineering: An update. Information and Software Technology, 64, 1–18. https://doi.org/10.1016/j.infsof.2015.03.007

Pressman, R. S., & Maxim, B. R. (2021). Ingeniería del software: Un enfoque práctico (9.ª ed.). McGraw Hill.

Putra, A. M., & Kabetta, H. (2022). Implementation of DevSecOps by integrating static and dynamic security testing in CI/CD pipelines. In 2022 IEEE International Conference of Computer Science and Information Technology (ICOSNIKOM) (pp. 1–6). IEEE. https://doi.org/10.1109/ICOSNIKOM56551.2022.10034883

Rajapakse, R. N., Zahedi, M., & Babar, M. A. (2021). An empirical analysis of practitioners’ perspectives on security tool integration into DevOps. In Proceedings of the 15th ACM/IEEE International Symposium on Empirical Software Engineering and Measurement (pp. 1–12). Association for Computing Machinery. https://doi.org/10.1145/3475716.3475776

Scanlon, T., & Morales, J. (2022). Revelations from an Agile and DevSecOps transformation in a large organization: An experiential case study. In Proceedings of the International Conference on Software and System Processes and International Conference on Global Software Engineering (pp. 77–81). Association for Computing Machinery. https://doi.org/10.1145/3529320.3529329

Sermpezis, E., Karapiperis, D., & Tjortjis, C. (2024). Integration of security in the DevOps methodology. In 2024 15th International Conference on Information, Intelligence, Systems and Applications (IISA) (pp. 1–6). IEEE. https://doi.org/10.1109/IISA62523.2024.10786669

Sinan, M., Shahin, M., & Gondal, I. (2025). Integrating security controls in DevSecOps: Challenges, solutions, and future research directions. Journal of Software: Evolution and Process, 37(6), Article e70029. https://doi.org/10.1002/smr.70029

Solaimalai, G. (2025). AI-augmented DevSecOps for cloud-native security automation. In 2025 International Conference on Recent Innovation in Science Engineering and Technology (ICRISET) (pp. 1–8). IEEE. https://doi.org/10.1109/ICRISET64803.2025.11252281

Sommerville, I. (2011). Software engineering (9th ed.). Pearson.

Turner, R. (2021). Systems engineering and DevSecOps: Reviewing the principles. INSIGHT, 24(2), 38–43. https://doi.org/10.1002/inst.12339

Varela Gutiérrez, B. (2021). Desarrollo seguro de software bajo la metodología DevSecOps. Universitat Oberta de Catalunya. https://hdl.handle.net/10609/138449

Verderame, L., Caviglione, L., Carbone, R., & Merlo, A. (2023). SecCo: Automated services to secure containers in the DevOps paradigm. In Proceedings of the 2023 International Conference on Research in Adaptive and Convergent Systems (Article 10, pp. 1–6). Association for Computing Machinery. https://doi.org/10.1145/3599957.3606222

Wang, Z., Guo, G., Liu, C., & Zhu, W. (2022). Research on railway DevSecOps system construction based on “people-process-technology”. In 2022 2nd International Signal Processing, Communications and Engineering Management Conference (ISPCEM) (pp. 19–23). IEEE. https://doi.org/10.1109/ISPCEM57418.2022.00010

Yasar, H., & Teplov, S. E. (2022). DevSecOps in embedded systems: An empirical study of past literature. In Proceedings of the 17th International Conference on Availability, Reliability and Security (Article 155, pp. 1–6). Association for Computing Machinery. https://doi.org/10.1145/3538969.3544451

Yasar, H., Morales, J., Antunes, L., Earl, P., Edman, R., Hamed, J., Reynolds, D., Maffey, K. R., & Yankel, J. (2024). Insights on implementing a metrics baseline for post-deployment AI container monitoring. In Proceedings of the 2024 International Conference on Software and Systems Processes (pp. 46–55). Association for Computing Machinery. https://doi.org/10.1145/3666015.3666018

Yu, W., Qian, J., Xu, R., Jin, C., Fang, H., & Shi, X. (2024). Improving substation network security with DevSecOps and AIOps. In 2024 IEEE 10th Conference on Big Data Security on Cloud (BigDataSecurity) (pp. 113–118). IEEE. https://doi.org/10.1109/BigDataSecurity62737.2024.00027

Yulianto, S., & Ngo, G. N. C. (2024). Enhancing DevSecOps pipelines with AI-driven threat detection and response. In 2024 International Conference on ICT for Smart Society (ICISS) (pp. 1–8). IEEE. https://doi.org/10.1109/ICISS62896.2024.10751269

Zhang, H., Babar, M. A., & Tell, P. (2011). Identifying relevant studies in software engineering. Information and Software Technology, 53(6), 625–637. https://doi.org/10.1016/j.infsof.2010.12.010

Zhou, X., Mao, R., Zhang, H., Dai, Q., Huang, H., Shen, H., Li, J., & Rong, G. (2023). Revisit security in the era of DevOps: An evidence-based inquiry into DevSecOps industry. IET Software, 17(4), 435–454. https://doi.org/10.1049/sfw2.12132

Downloads

Published

2026-08-02

How to Cite

Martínez-Moreno, P., Vergara-Camacho, J. A., Lueváno-Mondragon, V. A., & Jiménez-Martínez, K. A. (2026). DevSecOps for Secure Software Development: A Systematic Literature Review of Practices, Benefits, and Adoption Barriers. International Journal of Combinatorial Optimization Problems and Informatics, 17(4), 25–40. https://doi.org/10.61467/2007.1558.2026.v17i4.1299

Issue

Section

SMaDE 2025