DEVSECOPS: A Systematic Literature Review on Security Integration in Development and Operations

Authors

DOI:

https://doi.org/10.33003/fjs-2026-1018-5733

Keywords:

DevSecOps, Security Integration, Continuous Integration and Continuous Deployment (CI/CD), Shift-Left Security, Threat Modeling, Systematic Literature Review (SLR)

Abstract

In a world in which organizations are continually trying to deliver their software as quickly as possible. Keeping security strong throughout the development process is becoming a pressing challenge. Usually, security is put in at the end of the development process, typically resulting in high and extensive cost in order to rectify security loopholes in the software. DevSecOps changes that by weaving security into every level of the DevOps workflows and developing closer collaborations between the developers, operations, and security teams. This translates to software that is designed and developed security-first. This paper is a systematic literature review to examine the integration of security in the DevOps procedures, the demands for successful DevSecOps implementations, and the hurdles that institutions face when implementing it. Automated security testing, infrastructure as code, threat modeling and container security are used in DevSecOps practices to ensure the security of every level of the devops operations, as evidenced by an in-depth analysis of 22 scientific peer-reviewed articles published between 2020 and 2025. However, the review also uncovered some persistent challenges so as some of the solutions to these problems. Lack of existing literature is a gap with calls to develop more standardized frameworks and tools that can be used in the DevSecOps implementations to make them more readily adopted by organizations. Through investigating this area of growing interest in DevOps, it becomes possible to contribute to the knowledge of incorporating security more proactively into DevOps channels with the aim of creating more secure software systems.

Author Biographies

  • Ridwan Kolapo, Nile University of Nigeria

    Information Technology
    Senior Lecturer

  • Temitope Olufunmi Atoyebi, Nile University of Nigeria

    Information Technology

References

Abiona, O. O., Oladapo, O. J., Modupe, O. T., Oyeniran, C., Adewusi, A. O., & Komolafe, A. M. (2024). The emergence and importance of DevSecOps: Integrating and reviewing security practices within the DevOps pipeline.

Akbar, M. A., Smolander, K., Mahmood, S., & Alsanad, A. (2022). Toward successful DevSecOps in software development organizations: A decision-making framework. Information and Software Technology, 147, Article 106894. https://doi.org/10.1016/j.infsof.2022.106894

Anjaria, D., & Kulkarni, M. (2021). Effective DevSecOps implementation: A systematic literature review. Revista Gestão Inovação e Tecnologias, 11(4), 4931–4945. https://doi.org/10.47059/revistageintec.v11i4.2514

Ashenden, D., & Ollis, G. (2020). Putting the sec in DevSecOps: Using social practice theory to improve secure software development. In Proceedings of the ACM International Conference Proceeding Series (pp. 34–44). https://doi.org/10.1145/3442167.3442178

Athmakuri, N. (2024). Integrating security into the DevOps pipeline. International Journal for Research in Applied Science and Engineering Technology, 12(6), 1861–1866. https://doi.org/10.22214/ijraset.2024.63411

Azeem, M., Smolander, K., Mahmood, S., & Alsanad, A. (2022). Toward successful DevSecOps in software development organizations: A decision-making framework. Information and Software Technology, 147, Article 106894. https://doi.org/10.1016/j.infsof.2022.106894

Casola, V., De Benedictis, A., Mazzocca, C., & Orbinato, V. (2024). Secure software development and testing: A model-based methodology. Computers & Security, 137, Article 103639. https://doi.org/10.1016/j.cose.2023.103639

Chittibala, D. R. (2023). DevSecOps: Integrating security into the DevOps pipeline. 12(12), 2074–2078.

Isa, S. A., Atoyebi, T. O., Kolapo, R., Kirubakaran, P., Nathaniel, E. A., & Ahiaba, S. (2026). SYSTEMATIC REVIEW ON THE IMPACTS OF DIGITAL TRANSFORMATION ON CORPORATE INNOVATION PERFORMANCE. FUDMA Journal of Sciences, 10(1), 52-56. https://doi.org/10.33003/fjs-2026-1001-4176

Kumar, R., & Goyal, R. (2020). Modeling continuous security: A conceptual model for automated DevSecOps using open-source software over cloud (ADOC). Computers & Security, 97, Article 101967. https://doi.org/10.1016/j.cose.2020.101967

Lokiny, N., & Nandanampati, R. (2020). DevSecOps: Integrating security into DevOps with AI in cloud. 7(10), 239–242.

Lumpatki, S. S., Patwardhan, S., & Kulkarni, M. (2022). Implementing ‘DevSecOps as a culture.’ International Journal of Multidisciplinary Research (IJFMR), 4(1), 1–5.

Makani, S. T. (2024). DevOps security tools: Evaluating effectiveness in detecting and fixing vulnerabilities (Vol. 1).

Parashar, A., Dwivedi, A., Kumar, A., & Ahmad Khan, A. (2020). DevSecOps: A case study on a sample implementation of DevSecOps. International Journal of Engineering and Applied Sciences Technology, 5(2), 156–158. https://doi.org/10.33564/ijeast.2020.v05i02.022

Prates, L., & Pereira, R. (2025). DevSecOps practices and tools. International Journal of Information Security, 24(1), 1–25. https://doi.org/10.1007/s10207-024-00914-z

Putra, A. M., Siber, P., Kabetta, H., & Siber, P. (2022). Implementation of DevSecOps by integrating static and dynamic security testing in CI/CD pipelines. https://doi.org/10.1109/ICOSNIKOM56551.2022.10034883

Rajapakse, R. N., Zahedi, M., Babar, M. A., & Shen, H. (2022). Challenges and solutions when adopting DevSecOps: A systematic review. Information and Software Technology, 141, Article 106700. https://doi.org/10.1016/j.infsof.2021.106700

Rangnau, T., Buijtenen, R. V., Fransen, F., & Turkmen, F. (2020). Continuous security testing: A case study on integrating dynamic security testing tools in CI/CD pipelines. In Proceedings of the 2020 IEEE 24th International Enterprise Distributed Object Computing Conference (EDOC) (pp. 145–154). https://doi.org/10.1109/EDOC49727.2020.00026

Sánchez-Gordón, M., & Colomo-Palacios, R. (2020). Security as culture: A systematic literature review of DevSecOps. In Proceedings of the IEEE/ACM 42nd International Conference on Software Engineering Workshops (ICSEW 2020) (pp. 266–269). https://doi.org/10.1145/3387940.3392233

Sandu, A. K. (2024). DevSecOps: Integrating security into the DevOps lifecycle for enhanced resilience. https://www.researchgate.net/publication/380629263

Sermpezis, E., Karapiperis, D., & Tjortjis, C. (2024). Integration of security in the DevOps methodology. Journal of Global Information Technology, 15(3), 45–52.

Vangala, V. (2025). DevSecOps: Integrating security into the DevOps lifecycle.

Veeramachaneni, V. (2023). A systematic review of DevSecOps: Bridging security and agile development for resilient software systems. 21(07), 1251–1255. https://doi.org/10.48047/nq.2023.21.7.nq23114

Articles Per Source

Downloads

Published

18-09-2026

How to Cite

Kuye, O., Kolapo, R., Atoyebi, T., Eru, A. N., & Solomon, A. (2026). DEVSECOPS: A Systematic Literature Review on Security Integration in Development and Operations. FUDMA Journal of Sciences, 10(18), 50-57. https://doi.org/10.33003/fjs-2026-1018-5733

Most read articles by the same author(s)