Skip to main navigation Skip to search Skip to main content

Embedding Security Practices into Taxonomy of DevOps Practices

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

DevOps practices' emergence into software development has revolutionized efficiency and agility in the development lifecycle. However, as organizations adopt DevOps, there is growing acceptance of the imperative to integrate security practices into the DevOps workflow. Traditionally, security practices were often implemented as standalone processes, but integration across the entire pipeline is imperative in the fast-paced DevOps environment. This research proposes a methodology to integrate DevOps and security practices to embed security seamlessly throughout the DevOps lifecycle. Our approach focuses on selecting, assessing compatibility, and incorporating security practices. First, we identify two distinct categories of practices. The nineteen DevOps Security practices were drawn from the prior studies focused on developing a framework for implementing DevOps practices, and eighteen security practices were chosen from a previous study aimed at constructing a framework for successful DevSecOps operation in software development organizations. Moreover, we also integrated ten security practices distributed among the distinct phases of the DevOps lifecycle that are highly compatible with DevOps practices.

Original languageEnglish
Title of host publicationProceedings of the 29th International Conference on Evaluation and Assessment in Software Engineering , EASE, 2025 edition, EASE Companion 2025
EditorsMuhammad Ali Babar, Ayse Tosun, Stefan Wagner, Viktoria Stray
PublisherAssociation for Computing Machinery, Inc
Pages22-27
Number of pages6
ISBN (Electronic)9798400718328
DOIs
StatePublished - 23 Dec 2025
Event29th International Conference on Evaluation and Assessment of Software Engineering, EASE 2025 - Istanbul, Turkey
Duration: 17 Jun 202520 Jun 2025

Publication series

NameProceedings of the 29th International Conference on Evaluation and Assessment in Software Engineering , EASE, 2025 edition, EASE Companion 2025

Conference

Conference29th International Conference on Evaluation and Assessment of Software Engineering, EASE 2025
Country/TerritoryTurkey
CityIstanbul
Period17/06/2520/06/25

Bibliographical note

Publisher Copyright:
© 2025 Copyright held by the owner/author(s).

Keywords

  • Challenges
  • DevOps
  • DevOps as a service
  • Empirical Studies
  • Mixed Methods

ASJC Scopus subject areas

  • Software

Fingerprint

Dive into the research topics of 'Embedding Security Practices into Taxonomy of DevOps Practices'. Together they form a unique fingerprint.

Cite this