Publication in conference proceedings Q2
Integration of security standards in DevOps pipelines: An industry case study
Fabiola Móyon (Móyon, F.); Rafael Soares (Soares, R.); Maria Pinto-Albuquerque (Pinto-Albuquerque, M.); Daniel Mendez Fernandez (Mendez, D.); Kristian Beckers (Beckers, K.);
Product-Focused Software Process Improvement. Lecture Notes in Computer Science
Year (definitive publication)
2020
Language
English
Country
Switzerland
More Information
Web of Science®

Times Cited: 17

(Last checked: 2026-03-15 09:26)

View record in Web of Science®

Scopus

Times Cited: 18

(Last checked: 2026-03-16 00:37)

View record in Scopus


: 2.3
Google Scholar

Times Cited: 45

(Last checked: 2026-03-14 13:15)

View record in Google Scholar

This publication is not indexed in Overton

Abstract
In the last decade, companies adopted DevOps as a fast path to deliver software products according to customer expectations, with well aligned teams and in continuous cycles. As a basic practice, DevOps relies on pipelines that simulate factory swim-lanes. The more automation in the pipeline, the shorter a lead time is supposed to be. However, applying DevOps is challenging, particularly for industrial control systems (ICS) that support critical infrastructures and that must obey to rigorous requirements from security regulations and standards. Current research on security compliant DevOps presents open gaps for this particular domain and in general for systematic application of security standards. In this paper, we present a systematic approach to integrate standard-based security activities into DevOps pipelines and highlight their automation potential. Our intention is to share our experiences and help practitioners to overcome the trade-off between adding security activities into the development process and keeping a short lead time. We conducted an evaluation of our approach at a large industrial company considering the IEC 62443-4-1 security standard that regulates ICS. The results strengthen our confidence in the usefulness of our approach and artefacts, and in that they can support practitioners to achieve security compliance while preserving agility including short lead times.
Acknowledgements
This work is partially funded by Portuguese national funds through FCT - Fundação para a Ciência e Tecnologia, I.P., under the project FCT UIDB/04466/2020. Furthermore, the third author thanks the Instituto Universitário de Lisboa and ISTAR-IUL, for their
Keywords
Secure software engineering,Security standards,Agile software engineering,DevOps pipeline,DevSecOps,Industrial control systems
  • Mathematics - Natural Sciences
  • Computer and Information Sciences - Natural Sciences
Funding Records
Funding Reference Funding Entity
UIDB/04466/2020 Fundação para a Ciência e a Tecnologia