Skip to content
Open access

DevSecOpsUX: An Integrated Framework for Security, Quality Assurance, and User Experience in Continuous Software Delivery

2026 · IEEE Access · Vol 14, pp. 129668-129682 · 0 citations · 45 references

Abstract

The increasing complexity of modern software systems and the growing demand for continuous software delivery have accelerated the adoption of DevOps practices. However, existing approaches remain largely fragmented, providing limited integration of security, quality assurance (QA), and user experience (UX), thereby creating challenges related to software security, quality, and user acceptance. This study proposes DevSecOpsUX, a reference framework that integrates security, quality assurance, and user experience into a unified model for continuous software delivery. The research follows a mixed-method approach, combining a systematic mapping study of 118 publications with the conceptual design and expert validation of the proposed framework. The framework is structured around four interconnected pillars—SecUX, SecDev, SecQA, and SecOps—and defines thirteen security milestones embedded throughout the software lifecycle that support continuous validation, traceability, and cross-functional integration. The framework was evaluated by thirteen cybersecurity professionals, achieving agreement levels exceeding 90% across the assessed dimensions of relevance, clarity, conceptual coherence, and applicability. The expert evaluation suggests that integrating security, quality assurance, and user experience within a unified lifecycle model may improve the consistency of software validation processes, reduce fragmentation across DevSecOps practices, and enhance user trust in security mechanisms. These findings should be interpreted as an exploratory assessment based on expert judgment rather than evidence of effectiveness in industrial environments. The proposed framework provides an adaptable and measurable reference model for secure and user-centered software delivery while offering practical guidance for organizations seeking to integrate security, quality assurance, and user experience throughout continuous software delivery lifecycles. Future research should focus on empirical validation through industrial case studies and real-world DevSecOps implementations.

Read PDF