DEVSECOPS: A Systematic Literature Review on Security Integration in Development and Operations
In a world in which organizations are continually trying to deliver their software as quickly as possible. Keeping security strong throughout the development process is becoming a pressing challenge. Usually, security is put in at the end of the development process, typically resulting in high and extensive cost in order to rectify security loopholes in the software. DevSecOps changes that by weaving security into every level of the DevOps workflows and developing closer collaborations between the developers, operations, and security teams. This translates to software that is designed and developed security-first. This paper is a systematic literature review to examine the integration of security in the DevOps procedures, the demands for successful DevSecOps implementations, and the hurdles that institutions face when implementing it. Automated security testing, infrastructure as code, threat modeling and container security are used in DevSecOps practices to ensure the security of every level of the devops operations, as evidenced by an in-depth analysis of 22 scientific peer-reviewed articles published between 2020 and 2025. However, the review also uncovered some persistent challenges so as some of the solutions to these problems. Lack of existing literature is a gap with calls to develop more standardized frameworks and tools that can be used in the DevSecOps implementations to make them more readily adopted by organizations. Through investigating this area of growing interest in DevOps, it becomes possible to contribute to the knowledge of incorporating security more proactively into DevOps channels with the aim of creating more secure software systems.