2026· International Joint Conference on Rough Sets· pp. 47-59· 1 citation· 32 references
Computer Science
TL;DR
A conceptual model and methodological framework are proposed for embedding data from vulnerability databases into ISMS processes in alignment with ISO/IEC 27001/27002 and NIST recommendations, and provides methodological and architectural foundations for implementing integrated vulnerability management and enhancing cyber resilience in critical infrastructure environments.
The proposed maturity model comprising Fragmented, Instrumented, Correlated, Automated, Automated, and Adaptive stages provides organizations with a practical roadmap for assessing current capabilities and systematically advancing toward intelligent, self-optimizing security operations.
Lakshmi Kiran Meesala· International Journal of Art...· 0 citations
The methodology addresses log correlation, alert triage, incident classification and cross-functional escalation protocols and produces measurable improvements in mean time to detect (MTTD) and mean time to respond (MTTR) while reducing alert fatigue and redundant infrastructure costs.
Oladele Adekunle Awonusi· Computer Science & IT Re...· 0 citations
The implementation of DevSecOps has emerged as an essential strategy for incorporating security from the early stages of software development. Its adoption allows for reducing vulnerabilities, streamlining threat detection, and complying with security regulations. Using a Systematic Literature Review, the study retrieved thirty research articles that met the requirements for inclusion in the review. The objective is to provide an overview of the current state of existing empirical studies on DevSecOps practices, which can help define strengths and areas of opportunity, and allow for planning future studies. Finally, studies reveal several advantages to adopting the DevSecOps approach, such as creating more secure and resilient software, improving cybersecurity defenses, and fostering a safe and open culture through communication and collaboration among development teams. However, the literature highlighted specific challenges or barriers to adopting this approach, such as organizational resistance, cultural transformations, and the complexity of implementing new security tools and procedures.
Spanish-language metadata / Metadatos en españolTítulo en español:
DevSecOps para el desarrollo seguro de software: una revisión sistemática de la literatura sobre prácticas, beneficios y barreras de adopciónResumen:
La implementación de DevSecOps se ha consolidado como una estrategia esencial para incorporar la seguridad desde las primeras etapas del desarrollo de software. Su adopción permite reducir vulnerabilidades, agilizar la detección de amenazas y cumplir con las normativas de seguridad. Mediante una revisión sistemática de la literatura, el estudio recuperó treinta artículos de investigación que cumplieron los criterios de inclusión establecidos. El objetivo es ofrecer una visión general del estado actual de los estudios empíricos existentes sobre las prácticas de DevSecOps, con el fin de identificar sus fortalezas y áreas de oportunidad, así como facilitar la planificación de futuras investigaciones. Finalmente, los estudios revelan varias ventajas asociadas con la adopción del enfoque DevSecOps, entre ellas el desarrollo de software más seguro y resiliente, la mejora de las defensas de ciberseguridad y el fomento de una cultura segura y abierta mediante la comunicación y la colaboración entre los equipos de desarrollo. Sin embargo, la literatura también destaca desafíos o barreras específicas para la adopción de este enfoque, como la resistencia organizacional, las transformaciones culturales y la complejidad de implementar nuevas herramientas y procedimientos de seguridad.
Palabras Claves:
DevSecOps; desarrollo seguro de software; ciclo de vida del desarrollo de software; revisión sistemática de la literatura; seguridad por diseño; seguridad continua; prácticas de seguridad del software; resiliencia de ciberseguridad; detección de amenazas; barreras para la adopción de DevSecOps; cultura organizacional; automatización de la seguridad.
Smart citations:
https://scite.ai/reports/10.61467/2007.1558.2026.v17i4.1299Dimensions.Open Alex.
Patricia Martínez-Moreno, J. A. Vergara-Camacho, Víctor Adrián Lueváno-Mondragon et al.· International Journal of Com...· 0 citations
This study evaluates the comparative effectiveness of two widely adopted cybersecurity frameworks, the OWASP Top Ten (2021) and the OWASP Web Security Testing Guide (WSTG), in the context of web application security auditing. While the OWASP Top Ten is a standard for risk awareness, it lacks the technical granularity required for comprehensive testing, creating a gap between high-level risk identification and practical verification. To bridge this gap, this study proposes a structured integration through comparative mapping and empirical validation using real-world mitigation data. A procedural analysis combined with granularity evaluation was employed to map the ten OWASP risk categories to 102 technical verification units in the WSTG. The results reveal a 920% increase in testing granularity compared to the baseline Top Ten framework. Empirical validation conducted on a government subdomain (Instansi X) demonstrated that this integrated approach identified critical vulnerabilities, including Broken Access Control and Cryptographic Failures, which are often overlooked in high-level assessments. By implementing specific WSTG-based mitigation procedures, such as middleware authorization and secure communication protocols, identified risks were successfully remediated without disrupting production stability. This study contributes a validated framework that bridges the gap between conceptual risk and actionable technical verification. The findings indicate that while the OWASP Top Ten serves as a strategic reference, the WSTG is superior as a primary technical auditing framework. This integration enhances audit consistency, precision, and efficiency in evaluating modern web environments.
The authors analyze the limitations of existing approaches when applied in isolation, noting the insufficient specification of the FSTEC methodology, the lack of prioritization mechanisms in the MITRE ATT&CK knowledge base, and the subjectivity of the quantitative assessments of the DREAD model. As a solution, they propose a comprehensive methodology based on the mathematical formalization of the integration of these three frameworks. The developed approach includes an algorithm for mapping threats from the FSTEC database to MITRE ATT&CK attack techniques and uses adapted DREAD metrics to rank risks based on existing protective measures. The practical significance of the study lies in the presentation of a step-by-step implementation algorithm, including asset inventory, security audit, and security budget optimization, making the tool applicable to organizations of all sizes.
E. G. Balenko, M. Mitrofanov, N. N. Kramskoy et al.· SOFT MEASUREMENTS AND COMPUT...· 0 citations