Jul 2026· International Journal of Innovative Science and Research Technology· 0 citations· 15 references
TL;DR
The Adaptive Risk-Driven DevSecOps Framework (ARDDSF) is proposed, a layered framework for securing multi-cloud enterprise systems in the era of agentic artificial intelligence that bridges DevSecOps automation, AI-assisted security analysis, Zero Trust policy enforcement, and multi-cloud governance.
Abstract
The rapid adoption of cloud-native architectures, microservices, and continuous delivery pipelines has
transformed enterprise software engineering by enabling faster deployment cycles, independent service evolution, and
scalable digital delivery. However, these advantages also expand the cybersecurity attack surface across source code
repositories, CI/CD pipelines, software supply chains, cloud identities, infrastructure-as-code templates, runtime
workloads, and distributed multi-cloud environments. Prior research shows that DevSecOps improves software security
by embedding security practices into development and operations workflows, yet organizations continue to face challenges
related to toolchain fragmentation, inconsistent risk prioritization, limited automation, and weak integration between
security findings and deployment decisions. This paper proposes the Adaptive Risk-Driven DevSecOps Framework (ARDDSF), a layered framework for securing multi-cloud enterprise systems in the era of agentic artificial intelligence. ARDDSF integrates real-time risk scoring, AI-assisted threat modeling, secure CI/CD orchestration, policy-as-code
enforcement, Zero Trust-aligned access control, and continuous feedback loops across the software development lifecycle.
Unlike static DevSecOps pipelines that treat security findings as isolated scan outputs, ARD-DSF prioritizes vulnerabilities
using contextual risk factors such as asset criticality, exploitability, deployment stage, identity exposure, cloud
configuration posture, regulatory relevance, and runtime telemetry. The primary contribution of this work is a unified,
adaptive, and risk-aware DevSecOps architecture that bridges DevSecOps automation, AI-assisted security analysis, Zero
Trust policy enforcement, and multi-cloud governance. The paper provides a formal risk scoring model, implementation
workflow, experimental protocol, results templates, and architecture to support future validation in enterprise-scale
software delivery environments.
The proposed maturity model comprising Fragmented, Instrumented, Correlated, Automated, Automated, and Adaptive stages provides organizations with a practical roadmap for assessing current capabilities and systematically advancing toward intelligent, self-optimizing security operations.
Lakshmi Kiran Meesala· International Journal of Art...· 0 citations
The growing dependence of governments, financial institutions, healthcare organizations, energy providers, transportation networks, and communication systems on “cloud-native” platforms has made it more important than ever that these digital services be delivered continuously and securely. Cloud-native architectures offer scalability, flexibility, and quick deployment using microservices, containers, orchestration, and DevSecOps practices, but they also present complex cybersecurity, operational, and supply chain threats to the country’s critical infrastructure and economic well-being. The existing research focuses on cloud resilience, artificial intelligence for IT operations (AIOps), cybersecurity or governance individually, causing approaches to be disjointed and suboptimal for critical service continuity during large-scale cyber incidents. In this research, the authors introduce the AI-powered Integrated Cyber-Economic Resilience (AICER) Framework, which is a conceptual framework that integrates cloud-native infrastructure, cybersecurity intelligence, AI-assisted operational analytics, secure software delivery, economic impact assessment, and governance into a comprehensive decision-support architecture. The framework is formulated on the basis of Design Science Research Methodology (DSRM) and supported by an integrative literature review encompassing the most recent literature, international cybersecurity standards, and cloud computing best practices. The proposed framework does not introduce new performance metrics but rather builds on existing metrics, such as Service Level Objectives (SLOs), availability and reliability metrics, Mean Time Between Failures (MTBF), Mean Time to Recovery (MTTR), DORA software delivery metrics, Common Vulnerability Scoring System (CVSS), Exploit Prediction Scoring System (EPSS), Software Levels for Supply Chain Security (SLSA), and NIST Cybersecurity Framework (CSF 2.0) and NIST AI Risk Management Framework (AI RMF). The framework also takes economic impact into account to inform decisions on recovery for nationally significant services. The proposed architecture provides a vision for a policy-aware and AI-driven approach to enhancing cyber resilience, bolstering critical infrastructure, and fortifying continuity of essential digital services. The study provides a strong foundation for further prototype implementation, experimental validation, and deployment in public and private critical sectors.
Unknown authors· American Journal of Innovati...· 0 citations
The rapid evolution of enterprise systems toward cloud-native environments has introduced significant improvements in scalability and flexibility, while also increasing architectural complexity. Traditional solution architectures struggle to handle dynamic workloads, heterogeneous infrastructures, and real-time decision-making requirements. This paper proposes an AI-driven enterprise solution architecture designed to enhance scalability, resilience, and intelligent orchestration in cloud-native systems. The framework integrates artificial intelligence across multiple layers, including resource provisioning, service orchestration, anomaly detection, and adaptive scaling. Unlike conventional rule-based approaches, the architecture leverages data-driven intelligence to optimize system performance and resource utilization while maintaining reliability. Key components include microservices-based design, container orchestration, event-driven communication, and AI-enabled control mechanisms. The architecture emphasizes modularity, interoperability, and continuous learning to ensure adaptability across diverse enterprise applications. Security and governance are incorporated following DevSecOps practices. The proposed solution effectively addresses operational inefficiencies, latency issues, and scalability bottlenecks, providing a robust foundation for next-generation intelligent enterprise systems.
Shandilya Avadhanam, Venkat Krishna Sastry Vice, Dr Pasuluri Bindu et al.· 2026 6th International Confe...· 0 citations
Cloud-based academic environments such as Learning Management Systems (LMS), Open Journal Systems (OJS), institutional repositories, and web applications face increasing cybersecurity challenges due to heterogeneous users, distributed services, and extensive exposure to public networks. Existing security approaches remain fragmented, where machine learning focuses on threat detection, Zero Trust Architecture (ZTA) emphasizes access control, and blockchain is primarily used for secure logging. The lack of integration among these components limits the ability of security systems to adapt dynamically to evolving cyber threats. This study proposes an Adaptive Cybersecurity Framework (ACF) that integrates unsupervised machine learning-based anomaly detection, a risk-based Zero Trust Policy Engine, and blockchain-based immutable audit logging within a continuous adaptive feedback loop. The framework was evaluated using 450,000 anonymized HTTP and Web Application Firewall (WAF) events collected from a multi-domain academic cloud environment consisting of LMS, OJS, repositories, and supporting web applications. The analysis revealed structured and repetitive attack behaviors dominated by automated endpoint probing and cross-domain propagation patterns, indicating ecosystem-level security threats. The proposed risk assessment mechanism demonstrated effective alignment between anomaly detection and policy-based decision making. Experimental results achieved an AUROC of 0.7296 for risk-based threat detection while maintaining an average decision latency of approximately 11 ms, indicating suitability for real-time deployment. Blockchain integration further provided verifiable, tamper-resistant audit trails for mitigation actions and policy enforcement activities. This study contributes an ecosystem-aware adaptive cybersecurity paradigm that bridges threat detection, policy enforcement, and auditability through a unified security architecture for Academic Cloud Environments.
Danang, Corresponding Author, Teguh Wahyono et al.· Journal of Intelligent Decis...· 0 citations
Enterprise platform engineering has emerged as a response to the operational complexity created by cloud-native applications, microservices, Kubernetes, and expanding software delivery toolchains. Yet many enterprises continue to rely on fragmented developer tools, manually coordinated infrastructure processes, inconsistent configurations, and reactive operational practices that increase cognitive load and delay service delivery. This study develops an AI-enabled enterprise platform engineering framework for scalable developer platforms, intelligent infrastructure automation, and operational excellence. Following a design-science approach, the study synthesizes evidence from 35 peer-reviewed publications and translates identified capabilities into an integrated architectural artifact. The framework combines an internal developer portal, reusable service templates, infrastructure as code, CI/CD and GitOps orchestration, cloud-native runtime services, policy-as-code controls, unified observability, and an AI intelligence layer for configuration assistance, anomaly detection, capacity forecasting, root-cause analysis, and remediation recommendations. Human approval gates, explainability controls, audit trails, and rollback mechanisms are incorporated to constrain high-risk automated actions. The framework is evaluated through criterion-based architectural analysis and comparative operational scenarios covering service onboarding, infrastructure provisioning, deployment, workload scaling, policy violations, and incident recovery. The evaluation indicates that combining self-service workflows with governed AI assistance can improve process consistency, reduce operational handoffs, strengthen continuous compliance, and support earlier detection and resolution of infrastructure failures. The study contributes a unified, measurable model that connects platform engineering with AIOps, DevSecOps, developer experience, and cloud governance. Practically, it provides enterprise technology leaders and platform teams with a phased basis for moving from fragmented DevOps tooling towards secure, observable, and progressively autonomous platform operations.
Bhanu Kiran Kumar Muggalla· International Journal of Int...· 0 citations
Large financial institutions operate under continuous compliance, security, and vendor risk obligations distributed across hundreds of teams, systems, and jurisdictions. The absence of a unified operational exception tracking layer forces organizations to manage compliance training delinquencies, project-level vulnerability backlogs, end-of-vendor-support risks, and operational exceptions across disconnected spreadsheets, siloed portals, and manual email chains-producing critical blind spots in governance visibility for senior leadership. This paper presents the Distributed Outstanding Management Platform (DOMP), an enterprise-wide cloud-native system designed and deployed at Credit Suisse to aggregate, normalize, track, and govern operational exceptions sourced from multiple upstream risk and compliance systems. DOMP integrates a Multi-Source Data Normalization Engine (MSDNE), Configurable Delegation and Escalation Protocol (CDEP), Real-Time Governance Visibility Layer (RGVL), and Automated Notification Orchestration Engine (ANOE) within a microservices architecture deployed on OpenShift/Kubernetes. Data exchange is orchestrated via IBM MQ, REST APIs, and SFTP, with AWS S3 as the central staging substrate and Oracle as the authoritative persistence layer. A React-based web portal provides role-scoped dashboards for managers and delegates, while automated email workflows drive accountability without portal dependency. Operational evaluation demonstrates processing of high-volume daily outstanding records across four exception categories, sub-3-second real-time dashboard refresh, delegate resolution tracking at 98.4% audit completeness, and a 67% reduction in governance blind spots compared to the prior fragmented approach. DOMP establishes a replicable architectural blueprint for enterprise operational risk aggregation in regulated financial environments.
Arun Meesala· International Journal of Art...· 0 citations