The expert evaluation suggests that integrating security, quality assurance, and user experience within a unified lifecycle model may improve the consistency of software validation processes, reduce fragmentation across DevSecOps practices, and enhance user trust in security mechanisms.
Abstract
The increasing complexity of modern software systems and the growing demand for continuous software delivery have accelerated the adoption of DevOps practices. However, existing approaches remain largely fragmented, providing limited integration of security, quality assurance (QA), and user experience (UX), thereby creating challenges related to software security, quality, and user acceptance. This study proposes DevSecOpsUX, a reference framework that integrates security, quality assurance, and user experience into a unified model for continuous software delivery. The research follows a mixed-method approach, combining a systematic mapping study of 118 publications with the conceptual design and expert validation of the proposed framework. The framework is structured around four interconnected pillars—SecUX, SecDev, SecQA, and SecOps—and defines thirteen security milestones embedded throughout the software lifecycle that support continuous validation, traceability, and cross-functional integration. The framework was evaluated by thirteen cybersecurity professionals, achieving agreement levels exceeding 90% across the assessed dimensions of relevance, clarity, conceptual coherence, and applicability. The expert evaluation suggests that integrating security, quality assurance, and user experience within a unified lifecycle model may improve the consistency of software validation processes, reduce fragmentation across DevSecOps practices, and enhance user trust in security mechanisms. These findings should be interpreted as an exploratory assessment based on expert judgment rather than evidence of effectiveness in industrial environments. The proposed framework provides an adaptable and measurable reference model for secure and user-centered software delivery while offering practical guidance for organizations seeking to integrate security, quality assurance, and user experience throughout continuous software delivery lifecycles. Future research should focus on empirical validation through industrial case studies and real-world DevSecOps implementations.
The implementation of DevSecOps has emerged as an essential strategy for incorporating security from the early stages of software development. Its adoption allows for reducing vulnerabilities, streamlining threat detection, and complying with security regulations. Using a Systematic Literature Review, the study retrieved thirty research articles that met the requirements for inclusion in the review. The objective is to provide an overview of the current state of existing empirical studies on DevSecOps practices, which can help define strengths and areas of opportunity, and allow for planning future studies. Finally, studies reveal several advantages to adopting the DevSecOps approach, such as creating more secure and resilient software, improving cybersecurity defenses, and fostering a safe and open culture through communication and collaboration among development teams. However, the literature highlighted specific challenges or barriers to adopting this approach, such as organizational resistance, cultural transformations, and the complexity of implementing new security tools and procedures.
Spanish-language metadata / Metadatos en españolTítulo en español:
DevSecOps para el desarrollo seguro de software: una revisión sistemática de la literatura sobre prácticas, beneficios y barreras de adopciónResumen:
La implementación de DevSecOps se ha consolidado como una estrategia esencial para incorporar la seguridad desde las primeras etapas del desarrollo de software. Su adopción permite reducir vulnerabilidades, agilizar la detección de amenazas y cumplir con las normativas de seguridad. Mediante una revisión sistemática de la literatura, el estudio recuperó treinta artículos de investigación que cumplieron los criterios de inclusión establecidos. El objetivo es ofrecer una visión general del estado actual de los estudios empíricos existentes sobre las prácticas de DevSecOps, con el fin de identificar sus fortalezas y áreas de oportunidad, así como facilitar la planificación de futuras investigaciones. Finalmente, los estudios revelan varias ventajas asociadas con la adopción del enfoque DevSecOps, entre ellas el desarrollo de software más seguro y resiliente, la mejora de las defensas de ciberseguridad y el fomento de una cultura segura y abierta mediante la comunicación y la colaboración entre los equipos de desarrollo. Sin embargo, la literatura también destaca desafíos o barreras específicas para la adopción de este enfoque, como la resistencia organizacional, las transformaciones culturales y la complejidad de implementar nuevas herramientas y procedimientos de seguridad.
Palabras Claves:
DevSecOps; desarrollo seguro de software; ciclo de vida del desarrollo de software; revisión sistemática de la literatura; seguridad por diseño; seguridad continua; prácticas de seguridad del software; resiliencia de ciberseguridad; detección de amenazas; barreras para la adopción de DevSecOps; cultura organizacional; automatización de la seguridad.
Smart citations:
https://scite.ai/reports/10.61467/2007.1558.2026.v17i4.1299Dimensions.Open Alex.
Patricia Martínez-Moreno, J. A. Vergara-Camacho, Víctor Adrián Lueváno-Mondragon et al.· International Journal of Com...· 0 citations
An integrated reference architecture is proposed that combines TDD's fine-grained unit-level feedback loop with BDD's stakeholder-readable acceptance criteria inside a single continuous integration and continuous delivery (CI/CD) pipeline.
Urvish Gajjar· International Journal of Sci...· 0 citations
This paper presents a realistic case study showing how the implementation of DevOps principles in cross-functional teams, with the help of the standardized pipelines and integrated automation, facilitates cooperation, reduces cycle times, enhances quality assurance and accelerates delivery outcomes.
Karthik Allam· International Journal of Eme...· 0 citations
It is shown that the enhanced Zynerator framework reduces development effort, strengthens security posture, and accelerates DevSecOps adoption, indicating that DevSecOps-aware model-driven engineering offers a viable pathway toward secure, auto-mated software delivery.
Younes Zouani, Mohamed Lachgar, Youssef Harrati et al.· International Journal of Adv...· 0 citations
Today, IT organizations, in particular, have to provide quick, reliable and high-quality software solutions for meeting
the changing market requirements. While the development process has been structured by traditional software engineering
paradigms (Waterfall, Agile and Spiral Models), traditional workflows often involve operational bottlenecks. In particular, the
lack of communication and coordination between development and operations can lead to delivery delays. DevOps has come
about as a transformative approach that fuses software design and IT operations into a single, streamlined and automated
process that aims to overcome these systemic inefficiencies. DevOps is used to streamline the software delivery pipeline, when
paired with Cloud Computing infrastructure, including SaaS, PaaS, and IaaS solutions from AWS, Azure, and GCP. In this
project, one will be working on building a Continuous Integration and Continuous Deployment (CI/CD) pipeline using
Microsoft Azure to automate software delivery and improve overall efficiency
Ashwani Kumar, Geetanjali Amarawat· International Journal for Re...· 0 citations
Test automation in regulated financial contexts goes beyond operational efficiency; it constitutes a risk governance mechanism that must be embedded in quality architectures from system inception.
Ricardo Polanski Alves· Journal of Interdisciplinary...· 0 citations