Abstract
DevOps practices' emergence into software development has revolutionized efficiency and agility in the development lifecycle. However, as organizations adopt DevOps, there is growing acceptance of the imperative to integrate security practices into the DevOps workflow. Traditionally, security practices were often implemented as standalone processes, but integration across the entire pipeline is imperative in the fast-paced DevOps environment. This research proposes a methodology to integrate DevOps and security practices to embed security seamlessly throughout the DevOps lifecycle. Our approach focuses on selecting, assessing compatibility, and incorporating security practices. First, we identify two distinct categories of practices. The nineteen DevOps Security practices were drawn from the prior studies focused on developing a framework for implementing DevOps practices, and eighteen security practices were chosen from a previous study aimed at constructing a framework for successful DevSecOps operation in software development organizations. Moreover, we also integrated ten security practices distributed among the distinct phases of the DevOps lifecycle that are highly compatible with DevOps practices.
| Original language | English |
|---|---|
| Title of host publication | Proceedings of the 29th International Conference on Evaluation and Assessment in Software Engineering , EASE, 2025 edition, EASE Companion 2025 |
| Editors | Muhammad Ali Babar, Ayse Tosun, Stefan Wagner, Viktoria Stray |
| Publisher | Association for Computing Machinery, Inc |
| Pages | 22-27 |
| Number of pages | 6 |
| ISBN (Electronic) | 9798400718328 |
| DOIs | |
| State | Published - 23 Dec 2025 |
| Event | 29th International Conference on Evaluation and Assessment of Software Engineering, EASE 2025 - Istanbul, Turkey Duration: 17 Jun 2025 → 20 Jun 2025 |
Publication series
| Name | Proceedings of the 29th International Conference on Evaluation and Assessment in Software Engineering , EASE, 2025 edition, EASE Companion 2025 |
|---|
Conference
| Conference | 29th International Conference on Evaluation and Assessment of Software Engineering, EASE 2025 |
|---|---|
| Country/Territory | Turkey |
| City | Istanbul |
| Period | 17/06/25 → 20/06/25 |
Bibliographical note
Publisher Copyright:© 2025 Copyright held by the owner/author(s).
Keywords
- Challenges
- DevOps
- DevOps as a service
- Empirical Studies
- Mixed Methods
ASJC Scopus subject areas
- Software
Fingerprint
Dive into the research topics of 'Embedding Security Practices into Taxonomy of DevOps Practices'. Together they form a unique fingerprint.Cite this
- APA
- Author
- BIBTEX
- Harvard
- Standard
- RIS
- Vancouver