Artigo em revista científica Q1
DevSecOps practices and tools
Luís Prates (Prates, L.); Rúben Pereira (Pereira, R.);
Título Revista
International Journal of Information Security
Ano (publicação definitiva)
2025
Língua
Inglês
País
Reino Unido
Mais Informação
Web of Science®

N.º de citações: 0

(Última verificação: 2024-11-28 18:50)

Ver o registo na Web of Science®

Scopus

N.º de citações: 0

(Última verificação: 2024-11-26 20:37)

Ver o registo na Scopus

Google Scholar

N.º de citações: 0

(Última verificação: 2024-11-27 18:27)

Ver o registo no Google Scholar

Abstract/Resumo
Nowadays, software development happens at a fast pace. At the same time, Information Technology organizations face higher demands and competition while struggling with external threats such as cyberattacks. Therefore, many organizations adopt DevOps as a working culture to improve their Software Development Lifecycle (SDL). However, the success of DevOps adoption remains inconsistent, and recently, IEEE introduced a DevOps standard that might help improve DevOps adoption. The standard mentions DevSecOps as the security aspect of DevOps, adding security practices to the SDL from inception, but what are these practices or capabilities? Which tools can be used to implement these practices? Therefore, a Multivocal Literature Review was performed to identify DevSecOps practices and their definitions, and which tools can be used to implement them.
Agradecimentos/Acknowledgements
--
Palavras-chave
DevSecOps,SecDevOps,Practices,Capabilities,Secure software development,Security tools
  • Ciências da Computação e da Informação - Ciências Naturais
  • Engenharia Civil - Engenharia e Tecnologia