
Research Article
Advances in DevSecOps and the Future of Cybersecurity using Automation
@INPROCEEDINGS{10.4108/eai.28-4-2025.2357955, author={M. Pranav and I. Madhesh and J. Lenin and R. Sasikumar}, title={Advances in DevSecOps and the Future of Cybersecurity using Automation}, proceedings={Proceedings of the 4th International Conference on Information Technology, Civil Innovation, Science, and Management, ICITSM 2025, 28-29 April 2025, Tiruchengode, Tamil Nadu, India, Part I}, publisher={EAI}, proceedings_a={ICITSM PART I}, year={2025}, month={10}, keywords={devsecops automation threat modelling ci/cd pipeline sast dast software composition analysis cspm cybersecurity kubernetes security cloud security cnapp cspm}, doi={10.4108/eai.28-4-2025.2357955} }
- M. Pranav
I. Madhesh
J. Lenin
R. Sasikumar
Year: 2025
Advances in DevSecOps and the Future of Cybersecurity using Automation
ICITSM PART I
EAI
DOI: 10.4108/eai.28-4-2025.2357955
Abstract
DevSecOps (“Development” + “Security” + “Operations”) combines security practices into the DevOps lifecycle, for a holistic, unified, and continuous approach to software development and delivery. DevSecOps closes the divide between the dev and infrastructure teams, and solves the problems that occurred in earlier methods. This paper is a study of the most recent evolutions achieved by DevSecOps, with a particular emphasis on the centrality of automation for increasing security throughout the Software Development Life Cycle (hereafter, SDLC), thus turning it into a Secure SDLC (SSDLC). The idea of DevSecOps is to bake security practices into the software development lifecycle from planning to deployment rather than applying security as an after-the-fact layer over the top, as has been the case in traditional approaches to software development. What DevSecOps is really attempting to do, then, is move beyond “securing” a vulnerable application after the fact to a place where we get it right all along with consistent, secure code at a minimal level of reiterative action. We present a full scale DevSecOps automation blue print with latest cutting-edge technologies for automated Threat Modelling, Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), Software Composition Analysis (SCA), Docker Image Scanning, Container Scanning, Infrastructure-as-Code (IaC) Scanning, K8s Scanning, or CNAPP and CSPM.