DevSecOps as an Integrated Architecture for Modern Software Engineering: Automation, Continuous Security, and Organizational Resilience

Authors

DOI:

https://doi.org/10.70208/3007.8245.v6.n1.356

Keywords:

DevSecOps, continuous integration, cybersecurity, automation, software engineering

Abstract

DevSecOps has emerged as a foundational paradigm in contemporary software engineering, integrating development, operations, and security practices into a continuous and automated workflow. This article presents a conceptual and documentary review of the theoretical and practical evolution of DevSecOps as an integrated architecture for organizations seeking resilience, scalability, and protection against increasingly sophisticated threats. The study examines core principles of the model, including continuous integration, continuous delivery, automated testing, infrastructure as code, and intelligent monitoring. It also analyzes the incorporation of security controls from the earliest stages of the software development lifecycle, contrasting this approach with traditional models in which security was added at the end of the process. The methodology combines a systematic documentary review with a comparative analysis of DevOps, SecOps, and DevSecOps models, enabling the identification of structural, operational, and cultural differences. Findings indicate that DevSecOps not only reduces vulnerabilities but also enhances organizational efficiency through automated pipelines and collaborative practices. Practical applications are highlighted in sectors such as banking, healthcare, and government services, where security is critical. The study also discusses limitations related to organizational culture, adoption costs, and shortages of specialized talent. The analysis concludes that DevSecOps constitutes an essential approach for organizations aiming to develop secure, agile, and sustainable software in highly dynamic environments.

References

Bass, L., Weber, I., & Zhu, L. (2023). DevOps and software architecture in modern systems. Springer.

Bautista Ramos, R. C., & Yoo, S. G. (2025). Ciberseguridad en entornos DevOps: Una revisión sistemática de la literatura. IEEE Access, PP(99), 1–1.

https://doi.org/10.1109/ACCESS.2025.3582892

Erich, F., Amrit, C., & Daneva, M. (2017). DevOps literature review. Procedia Computer Science, 121, 180–193. https://doi.org/10.13140/2.1.5125.1201

GitLab. (2023). Global DevSecOps Report 2023: Security and automation trends. GitLab Research.

Guda, D. P. (2024). AI-driven threat detection in DevSecOps pipelines for insurance applications. International Journal of Intelligent Systems and Applications in Engineering, 12(23s). https://doi.org/10.17762/ijisae.v12i23s.7759

Kaithe, B. K. (2025). Shift Left Security: A paradigm shift in software development security integration. European Journal of Computer Science and Information Technology, 13(24), 96–102. https://doi.org/10.37745/ejcsit.2013/vol13n2496102

Kim, G., Humble, J., Debois, P., & Willis, J. (2022). The DevOps handbook: How to create world-class agility, reliability, and security in technology organizations (2nd ed.). IT Revolution Press.

Kitchenham, B., Budgen, D., & Brereton, P. (2022). Evidence-based software engineering and systematic reviews (2nd ed.). CRC Press.

Koneru, N. M. K. (2021). Integrando la seguridad en las canalizaciones CI/CD: Un enfoque DevSecOps con herramientas SAST, DAST y SCA. International Journal of Science and Research Archive, 3(1), 250–265. https://doi.org/10.30574/ijsra.2021.3.1.0080

Microsoft. (2023). Security in cloud-native development: A DevSecOps approach. Microsoft Research.

Mohammed, K. I., Shanmugam, B., & El Den, J. (2025). Evolución de DevSecOps y su influencia en la seguridad de aplicaciones: Una revisión sistemática de la literatura. Technologies, 13(12), 548. https://doi.org/10.3390/technologies13120548

Pressman, R., & Maxim, B. (2022). Software engineering: A practitioner’s approach (10th ed.). McGraw-Hill.

Rahman, M. M., & Williams, L. (2016). Seguridad del software en DevOps: Sintetizando las percepciones y prácticas de los profesionales. In Proceedings of the 38th International Conference on Software Engineering Companion (pp. 143–152).

https://doi.org/10.1145/2896941.2896946

Rajapakse, R. N., Zahedi, M., & Babar, M. A. (2021). An empirical analysis of practitioners’ perspectives on security tool integration into DevOps (arXiv:2107.02096v3 [cs.CR]). arXiv.

https://arxiv.org/abs/2107.02096

Rajapakse, R., Zahedi, M., Babar, M. A., & Shen, H. (2021). Desafíos y soluciones al adoptar DevSecOps: Una revisión sistemática. Information and Software Technology, 141, 106700.

https://doi.org/10.1016/j.infsof.2021.106700

Red Hat. (2023). State of DevSecOps in enterprise environments. Red Hat Insights.

Rose, S., Borchert, O., Mitchell, S., & Connelly, S. (2020). Zero Trust Architecture (NIST SP 800 207). https://doi.org/10.6028/NIST.SP.800-207

Sarker, I. H. (2022). Aprendizaje automático para el análisis inteligente de datos y la automatización en ciberseguridad: Perspectivas actuales y futuras. Annals of Data Science, 10(3), 1–26. https://doi.org/10.1007/s40745-022-00444-2

Shahin, M., Babar, M. A., & Zhu, L. (2017). Integración, entrega y despliegue continua: Una revisión sistemática sobre enfoques, herramientas, desafíos

Published

2026-03-12

How to Cite

Ortega Ovalle, M. T. (2026). DevSecOps as an Integrated Architecture for Modern Software Engineering: Automation, Continuous Security, and Organizational Resilience. Horizonte Academico, 6(1), 638–661. https://doi.org/10.70208/3007.8245.v6.n1.356

Issue

Section

Artículos