期刊论文详细信息
Cardiometry
Effective DevSecOps Implementation: A Systematic Literature Review
article
Dhaval Anjaria1  Mugdha Kulkarni1 
[1] Symbiosis Centre for Information Technology, Symbiosis International ,(Deemed University) Pune
关键词: DevOps;    DevSecOps;    Security;    SecDevOps;    Continuous Integration;    Continuous Delivery;   
DOI  :  10.18137/cardiometry.2022.24.410417
学科分类:环境科学(综合)
来源: Russian New University
PDF
【 摘 要 】

Adopting DevOps means increased collaboration between development and operations teams and faster release cycles through a shift to automation. Using Dev Ops brings with it several advantages in the development of software. Security, however, is often neglected in DevOps due to the fast release cycle. Therefore Dev Sec Ops has emerged as an extension to DevOps that attempts to integrate security with Dev Ops practices, which is not without its challenges. DevOps, and by extension Dev Sec Ops, represents a significant change in the culture, tooling, and processes used in software development. Therefore, when implementing DevSecOps, teams and their organizations need to be aware of the challenges it brings and how to address those challenges for a DevSecOps implementation to be effective. Literature on DevSecOps exists that outlines practices and principles to do this. This paper uses a grounded theory approach to do a systematic literature review of academic literature to find the factors that contribute to an effective DevSecOps implementation. It attempts to reconcile the challenges of DevSecOps with ways of mitigating them and the advantages that a DevSecOps implementation can bring. The paper thus outlines methods of effectively implementing DevSecOps as described in academic literature.

【 授权许可】

CC BY   

【 预 览 】
附件列表
Files Size Format View
RO202307120003335ZK.pdf 204KB PDF download
  文献评价指标  
  下载次数:1次 浏览次数:0次