Aug 2026· International Journal of Combinatorial Optimization Problems and Informatics· 0 citations· 1 references
Abstract
The implementation of DevSecOps has emerged as an essential strategy for incorporating security from the early stages of software development. Its adoption allows for reducing vulnerabilities, streamlining threat detection, and complying with security regulations. Using a Systematic Literature Review, the study retrieved thirty research articles that met the requirements for inclusion in the review. The objective is to provide an overview of the current state of existing empirical studies on DevSecOps practices, which can help define strengths and areas of opportunity, and allow for planning future studies. Finally, studies reveal several advantages to adopting the DevSecOps approach, such as creating more secure and resilient software, improving cybersecurity defenses, and fostering a safe and open culture through communication and collaboration among development teams. However, the literature highlighted specific challenges or barriers to adopting this approach, such as organizational resistance, cultural transformations, and the complexity of implementing new security tools and procedures.
Spanish-language metadata / Metadatos en españolTítulo en español:
DevSecOps para el desarrollo seguro de software: una revisión sistemática de la literatura sobre prácticas, beneficios y barreras de adopciónResumen:
La implementación de DevSecOps se ha consolidado como una estrategia esencial para incorporar la seguridad desde las primeras etapas del desarrollo de software. Su adopción permite reducir vulnerabilidades, agilizar la detección de amenazas y cumplir con las normativas de seguridad. Mediante una revisión sistemática de la literatura, el estudio recuperó treinta artículos de investigación que cumplieron los criterios de inclusión establecidos. El objetivo es ofrecer una visión general del estado actual de los estudios empíricos existentes sobre las prácticas de DevSecOps, con el fin de identificar sus fortalezas y áreas de oportunidad, así como facilitar la planificación de futuras investigaciones. Finalmente, los estudios revelan varias ventajas asociadas con la adopción del enfoque DevSecOps, entre ellas el desarrollo de software más seguro y resiliente, la mejora de las defensas de ciberseguridad y el fomento de una cultura segura y abierta mediante la comunicación y la colaboración entre los equipos de desarrollo. Sin embargo, la literatura también destaca desafíos o barreras específicas para la adopción de este enfoque, como la resistencia organizacional, las transformaciones culturales y la complejidad de implementar nuevas herramientas y procedimientos de seguridad.
Palabras Claves:
DevSecOps; desarrollo seguro de software; ciclo de vida del desarrollo de software; revisión sistemática de la literatura; seguridad por diseño; seguridad continua; prácticas de seguridad del software; resiliencia de ciberseguridad; detección de amenazas; barreras para la adopción de DevSecOps; cultura organizacional; automatización de la seguridad.
Smart citations:
https://scite.ai/reports/10.61467/2007.1558.2026.v17i4.1299Dimensions.Open Alex.
The expert evaluation suggests that integrating security, quality assurance, and user experience within a unified lifecycle model may improve the consistency of software validation processes, reduce fragmentation across DevSecOps practices, and enhance user trust in security mechanisms.
Jonathan Alejandro López Acevedo, G. M. Ramírez, C. Huidobro· IEEE Access· 0 citations
The results of this study indicate that successful implementation of the ISMM will require a balance of architectural approach, between structural standardization and context flexibility, which contributes to the development of more sophisticated ISMMs and supports trailblazing studies on AI-driven security maturity models.
Siti Zaleha Abd Goni, Muhamad Khairulnizam Zaini, Qamarul Nazrin Harun et al.· Information & Computer S...· 0 citations
A guide that facilitates the step-by-step adoption of five practices: version control, change requests controlled with manual code inspection, continuous integration, static code analysis, and implementing an automated pipeline for continuous integration is proposed.
M. Pastrana, Hugo-Armando Ordoñez-Erazo, C. Cobos-Lozada et al.· 0 citations
Over the last decade, the number of organizations adopting GSD to access a wide range of international talent and reduce their development costs is increasing.. Although, the geographical distance, time-zone, and cultural differences associated with GSD have introduced a number of risks for globally distributed software development teams, continuing to cause a high rate of project failures. To build a more holistic approach and address these challenges, we conducted a Systematic Literature Review (SLR) based on the PRISMA 2020 guidelines. We systematically analyzed a highly filtered set of 19 top-tier, high-impact primary studies published between 2015 and 2025. The objective of this research paper is to perform a formal requirements elicitation, identifying Critical Success Factors (CSFs) to form the architectural foundation of a future GSD project management ecosystem. Our synthesis of the literature reveals seven major CSFs that drive success in globally distributed projects. Crucially, these dimensions were not identified solely based on their frequency of occurrence in the selected studies (appearing in over 50% of the papers), but because the primary sources consistently assigned them high weights and priority rankings using advanced decision-making models. These core dimensions are: Communication and Coordination (100%), Human Resources and Skills (95%), Technology and Infrastructure (74%), Knowledge Management (63%), Management Support and Leadership (58%), Requirements Engineering (58%), and Cost and Time Efficiency (58%).These findings highlight a major paradigm shift within the software industry: socio-technical skills and reliable technology now carry significantly more weight than strict, traditional processes. By integrating these highly validated factors through this requirements elicitation, we outline the fundamental architectural parameters necessary to build a future GSD management ecosystem capable of overcoming the complexities arising from geographical distance.
Chellal Mostafa, Mohammed Saber, M. Belkasmi· EPJ Web of Conferences· 0 citations
A conceptual model and methodological framework are proposed for embedding data from vulnerability databases into ISMS processes in alignment with ISO/IEC 27001/27002 and NIST recommendations, and provides methodological and architectural foundations for implementing integrated vulnerability management and enhancing cyber resilience in critical infrastructure environments.
V. Yashchuk, A. Ivanusa, N. Maslova et al.· International Joint Conferen...· 1 citation
This study presents a PRISMA-ScR-guided scoping review to systematically map the current landscape of LLM applications in cybersecurity, addressing their roles as both threat enablers and defensive tools while identifying key governance challenges and future research directions.