DevSecOps: A Comprehensive Survey of Secure Software Development and Deployment Practices
Abstract
DevSecOps brings together development, security, and operations approaches to incorporate security across the software development lifecycle, allowing organizations to discover and address vulnerabilities earlier while ensuring quick and dependable software delivery. This survey reviews the foundations, practices, technologies, challenges, and recent research associated with secure software development and deployment. The Secure SDLC is dissected, from security requirements and threat modeling to secure coding, testing, deployment, and continuous monitoring. The study further discusses shift-left security, continuous security testing, automated vulnerability management, Security as Code, CI/CD integration, and compliance automation. Key automated security technologies, including SAST, DAST, Software Composition Analysis, and Infrastructure-as-Code security scanning, are reviewed. The survey also highlights the growing role of AI and ML in vulnerability identification, threat intelligence, security analysis, and adaptive security automation. Recent literature is compared to identify major findings, limitations, and research directions. Overall, DevSecOps provides a proactive and collaborative approach for improving software security, resilience, scalability, compliance, and deployment efficiency while addressing organizational, legacy-system, toolchain, and performance challenges across increasingly complex cloud-native and distributed environments today.