Secure DevSecOps Framework for Cloud Infrastructure Protection
The article is devoted to the development of a secure DevSecOps framework for cloud infrastructure protection. The purpose of the study is to substantiate the author's approach to building such a framework based on the integration of artificial intelligence-based cyber threat detection technologies and data leakage prevention mechanisms. The scientific research used general scientific methods of cognition, in particular analysis, synthesis, generalization, systematization and classification, as well as the Relative Importance Index to assess the priority of the author's development components. The results of the study show that cloud infrastructure protection covers at least six levels of architecture, each of which requires a separate set of control mechanisms, and the classes and models of cloud services form a different distribution of responsibility between the provider and the consumer. Modern security technologies are systematized, covering secure service networks, data categorization in transit, continuous integration pipeline certification, and AI-based vulnerability detection tools. Based on the analysis, a proprietary secure DevSecOps framework is proposed that combines behavioral anomaly assessment, automated SIEM event correlation, built-in secure development controls, project-based data leakage prevention, and cloud infrastructure hardening. An assessment of the framework components by the relative importance index showed that automated SIEM event correlation and behavioral anomaly assessment have the highest priority, while secure development controls, data leakage prevention, and infrastructure hardening play a supporting but necessary role. The practical significance of the research lies in the possibility of using the proposed framework by organizations implementing cloud services to build a holistic system for detecting and preventing cyber threats at all stages of the software development life cycle.