Skip to content
Open access

Secure Programming and Secure Design in DevSecOps: A Literature-Based Conceptual Synthesis

Sep 2026 · Network · 0 citations · 22 references

Abstract

Secure programming and secure design are often managed as separate activities, leaving a gap between architectural intent and the implementation that reaches production. This paper presents a structured conceptual synthesis of twenty core publications, supplemented by standards and recent work on AI-assisted development. It makes three contributions. First, it frames secure programming as the implementation-facing realization of secure design within a closed feedback loop. Second, it uses an explicit 0–5 rubric to produce an illustrative comparison of Waterfall, Iterative, Spiral, and Agile with DevSecOps across six security-integration dimensions. These profiles are structured author judgments, not empirical measurements of security effectiveness. Third, it proposes an operational Secure SDLC–DevSecOps framework that links six stages through named artifacts, accountable roles, traceability rules, release gates, exceptions, and outcome measures. A comparison with NIST SSDF, OWASP SAMM, Microsoft SDL, ISO/IEC 27034, and OWASP implementation guidance shows that the individual practices are established; the framework’s intended contribution is the project-level control loop that connects design decisions to pipeline evidence and production feedback. The illustrative profiles place Spiral and Agile with DevSecOps close together under the baseline weights, while sensitivity scenarios show that their ordering depends on whether design-time risk analysis or delivery-time verification is emphasized. The synthesis therefore supports contextual tailoring rather than a universal ranking.

Read PDF

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.