Aug 2026· International Journal of Combinatorial Optimization Problems and Informatics· Vol 17, pp. 25-40· 0 citations· 1 references
Abstract
The implementation of DevSecOps has emerged as an essential strategy for incorporating security from the early stages of software development. Its adoption allows for reducing vulnerabilities, streamlining threat detection, and complying with security regulations. Using a Systematic Literature Review, the study retrieved thirty research articles that met the requirements for inclusion in the review. The objective is to provide an overview of the current state of existing empirical studies on DevSecOps practices, which can help define strengths and areas of opportunity, and allow for planning future studies. Finally, studies reveal several advantages to adopting the DevSecOps approach, such as creating more secure and resilient software, improving cybersecurity defenses, and fostering a safe and open culture through communication and collaboration among development teams. However, the literature highlighted specific challenges or barriers to adopting this approach, such as organizational resistance, cultural transformations, and the complexity of implementing new security tools and procedures.
Spanish-language metadata / Metadatos en españolTítulo en español:
DevSecOps para el desarrollo seguro de software: una revisión sistemática de la literatura sobre prácticas, beneficios y barreras de adopciónResumen:
La implementación de DevSecOps se ha consolidado como una estrategia esencial para incorporar la seguridad desde las primeras etapas del desarrollo de software. Su adopción permite reducir vulnerabilidades, agilizar la detección de amenazas y cumplir con las normativas de seguridad. Mediante una revisión sistemática de la literatura, el estudio recuperó treinta artículos de investigación que cumplieron los criterios de inclusión establecidos. El objetivo es ofrecer una visión general del estado actual de los estudios empíricos existentes sobre las prácticas de DevSecOps, con el fin de identificar sus fortalezas y áreas de oportunidad, así como facilitar la planificación de futuras investigaciones. Finalmente, los estudios revelan varias ventajas asociadas con la adopción del enfoque DevSecOps, entre ellas el desarrollo de software más seguro y resiliente, la mejora de las defensas de ciberseguridad y el fomento de una cultura segura y abierta mediante la comunicación y la colaboración entre los equipos de desarrollo. Sin embargo, la literatura también destaca desafíos o barreras específicas para la adopción de este enfoque, como la resistencia organizacional, las transformaciones culturales y la complejidad de implementar nuevas herramientas y procedimientos de seguridad.
Palabras Claves:
DevSecOps; desarrollo seguro de software; ciclo de vida del desarrollo de software; revisión sistemática de la literatura; seguridad por diseño; seguridad continua; prácticas de seguridad del software; resiliencia de ciberseguridad; detección de amenazas; barreras para la adopción de DevSecOps; cultura organizacional; automatización de la seguridad.
Smart citations:
https://scite.ai/reports/10.61467/2007.1558.2026.v17i4.1299Dimensions.Open Alex.
The increasing complexity of modern software systems and the growing demand for continuous software delivery have accelerated the adoption of DevOps practices. However, existing approaches remain largely fragmented, providing limited integration of security, quality assurance (QA), and user experience (UX), thereby creating challenges related to software security, quality, and user acceptance. This study proposes DevSecOpsUX, a reference framework that integrates security, quality assurance, and user experience into a unified model for continuous software delivery. The research follows a mixed-method approach, combining a systematic mapping study of 118 publications with the conceptual design and expert validation of the proposed framework. The framework is structured around four interconnected pillars—SecUX, SecDev, SecQA, and SecOps—and defines thirteen security milestones embedded throughout the software lifecycle that support continuous validation, traceability, and cross-functional integration. The framework was evaluated by thirteen cybersecurity professionals, achieving agreement levels exceeding 90% across the assessed dimensions of relevance, clarity, conceptual coherence, and applicability. The expert evaluation suggests that integrating security, quality assurance, and user experience within a unified lifecycle model may improve the consistency of software validation processes, reduce fragmentation across DevSecOps practices, and enhance user trust in security mechanisms. These findings should be interpreted as an exploratory assessment based on expert judgment rather than evidence of effectiveness in industrial environments. The proposed framework provides an adaptable and measurable reference model for secure and user-centered software delivery while offering practical guidance for organizations seeking to integrate security, quality assurance, and user experience throughout continuous software delivery lifecycles. Future research should focus on empirical validation through industrial case studies and real-world DevSecOps implementations.
Jonathan Alejandro López Acevedo, G. M. Ramírez, C. Huidobro· IEEE Access· 0 citations
This research aims to conduct an empirical analysis of the development of Information Security Maturity Models (ISMMs) from 2021 to 2025, focusing on challenges of fragmentation, standardization and the integration of data-driven analytics within information security maturity frameworks.
A Systematic Literature Review was undertaken following the PRISMA protocol. Data were synthesized from 25 empirical studies retrieved from Scopus, Web of Science, IEEE Xplore, ScienceDirect and Google Scholar. Thematic and analytical synthesis (QA1–QA6) was conducted to form the basis for comprehensive analysis.
Four key themes emerged: 1. Gaps in fragmentation and standardization 2. Adaptability and contextual pliability 3. Assimilation of data-driven intelligence 4. Governance and organizational readiness. The study highlights a transition in contemporary ISMMs from a static compliance-focused approach to a more adaptive and analytical framework.
The results of this study indicate that successful implementation of the ISMM will require a balance of architectural approach, between structural standardization and context flexibility. Maturity models are not to be understood as strict compliance tool only, but as a governance structure, which can be adjusted to the current risk profile, degree of digital maturity and organizational resources.
This research advances the fragmented theoretical and empirical streams into a composite theory on sustainable cyber resilience. By integrating standardization, data analytics and organizational readiness, it contributes to the development of more sophisticated ISMMs and supports trailblazing studies on AI-driven security maturity models.
Siti Zaleha Abd Goni, Muhamad Khairulnizam Zaini, Qamarul Nazrin Harun et al.· Information & Computer S...· 0 citations
Over the last decade, the number of organizations adopting GSD to access a wide range of international talent and reduce their development costs is increasing.. Although, the geographical distance, time-zone, and cultural differences associated with GSD have introduced a number of risks for globally distributed software development teams, continuing to cause a high rate of project failures. To build a more holistic approach and address these challenges, we conducted a Systematic Literature Review (SLR) based on the PRISMA 2020 guidelines. We systematically analyzed a highly filtered set of 19 top-tier, high-impact primary studies published between 2015 and 2025. The objective of this research paper is to perform a formal requirements elicitation, identifying Critical Success Factors (CSFs) to form the architectural foundation of a future GSD project management ecosystem. Our synthesis of the literature reveals seven major CSFs that drive success in globally distributed projects. Crucially, these dimensions were not identified solely based on their frequency of occurrence in the selected studies (appearing in over 50% of the papers), but because the primary sources consistently assigned them high weights and priority rankings using advanced decision-making models. These core dimensions are: Communication and Coordination (100%), Human Resources and Skills (95%), Technology and Infrastructure (74%), Knowledge Management (63%), Management Support and Leadership (58%), Requirements Engineering (58%), and Cost and Time Efficiency (58%).These findings highlight a major paradigm shift within the software industry: socio-technical skills and reliable technology now carry significantly more weight than strict, traditional processes. By integrating these highly validated factors through this requirements elicitation, we outline the fundamental architectural parameters necessary to build a future GSD management ecosystem capable of overcoming the complexities arising from geographical distance.
Chellal Mostafa, Mohammed Saber, M. Belkasmi· EPJ Web of Conferences· 0 citations
Large Language Models (LLMs) have rapidly evolved into powerful general-purpose systems with advanced natural language processing, code generation, and reasoning capabilities, leading to their increasing adoption in cybersecurity. However, their dual-use nature introduces both significant defensive opportunities and emerging offensive threats. This study presents a PRISMA-ScR-guided scoping review to systematically map the current landscape of LLM applications in cybersecurity, addressing their roles as both threat enablers and defensive tools while identifying key governance challenges and future research directions. Literature published between January 2017 and December 2024 was identified through structured searches of IEEE Xplore, ACM Digital Library, Scopus, Web of Science, and arXiv, supplemented by grey literature and citation snowballing. Studies were screened using predefined inclusion and exclusion criteria, and relevant information was extracted using a standardized data-charting framework followed by thematic narrative synthesis. The review synthesizes evidence from 153 eligible studies, demonstrating that LLMs substantially enhance offensive capabilities such as phishing, malware generation, vulnerability discovery, and adversarial attacks, while simultaneously improving defensive functions including threat detection, vulnerability management, incident response, security automation, and analyst support. The review further identifies critical limitations related to hallucinations, model reliability, privacy, misuse, and governance, highlighting the need for trustworthy deployment frameworks, standardized evaluation benchmarks, and robust regulatory safeguards. By integrating evidence across technical, operational, and governance perspectives, this scoping review provides a comprehensive evidence-based synthesis of the evolving role of LLMs in cybersecurity and outlines priorities for future research and responsible deployment.