About | Contact Us | Register | Login
ProceedingsSeriesJournalsSearchEAI
Proceedings of the 4th International Conference on Information Technology, Civil Innovation, Science, and Management, ICITSM 2025, 28-29 April 2025, Tiruchengode, Tamil Nadu, India, Part I

Research Article

Advances in DevSecOps and the Future of Cybersecurity using Automation

Download12 downloads
Cite
BibTeX Plain Text
  • @INPROCEEDINGS{10.4108/eai.28-4-2025.2357955,
        author={M.  Pranav and I.  Madhesh and J.  Lenin and R.  Sasikumar},
        title={Advances in DevSecOps and the Future of Cybersecurity using Automation},
        proceedings={Proceedings of the 4th International Conference on Information Technology, Civil Innovation, Science, and Management, ICITSM 2025, 28-29 April 2025, Tiruchengode, Tamil Nadu, India, Part I},
        publisher={EAI},
        proceedings_a={ICITSM PART I},
        year={2025},
        month={10},
        keywords={devsecops automation threat modelling ci/cd pipeline sast dast software composition analysis cspm cybersecurity kubernetes security cloud security cnapp cspm},
        doi={10.4108/eai.28-4-2025.2357955}
    }
    
  • M. Pranav
    I. Madhesh
    J. Lenin
    R. Sasikumar
    Year: 2025
    Advances in DevSecOps and the Future of Cybersecurity using Automation
    ICITSM PART I
    EAI
    DOI: 10.4108/eai.28-4-2025.2357955
M. Pranav1,*, I. Madhesh1, J. Lenin1, R. Sasikumar1
  • 1: K. Ramakrishnan College of Engineering, India
*Contact email: pranavmuralidharan01@gmail.com

Abstract

DevSecOps (“Development” + “Security” + “Operations”) combines security practices into the DevOps lifecycle, for a holistic, unified, and continuous approach to software development and delivery. DevSecOps closes the divide between the dev and infrastructure teams, and solves the problems that occurred in earlier methods. This paper is a study of the most recent evolutions achieved by DevSecOps, with a particular emphasis on the centrality of automation for increasing security throughout the Software Development Life Cycle (hereafter, SDLC), thus turning it into a Secure SDLC (SSDLC). The idea of DevSecOps is to bake security practices into the software development lifecycle from planning to deployment rather than applying security as an after-the-fact layer over the top, as has been the case in traditional approaches to software development. What DevSecOps is really attempting to do, then, is move beyond “securing” a vulnerable application after the fact to a place where we get it right all along with consistent, secure code at a minimal level of reiterative action. We present a full scale DevSecOps automation blue print with latest cutting-edge technologies for automated Threat Modelling, Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), Software Composition Analysis (SCA), Docker Image Scanning, Container Scanning, Infrastructure-as-Code (IaC) Scanning, K8s Scanning, or CNAPP and CSPM.

Keywords
devsecops, automation, threat modelling, ci/cd pipeline, sast, dast, software composition analysis, cspm, cybersecurity, kubernetes security, cloud security, cnapp, cspm
Published
2025-10-13
Publisher
EAI
http://dx.doi.org/10.4108/eai.28-4-2025.2357955
Copyright © 2025–2025 EAI
EBSCOProQuestDBLPDOAJPortico
EAI Logo

About EAI

  • Who We Are
  • Leadership
  • Research Areas
  • Partners
  • Media Center

Community

  • Membership
  • Conference
  • Recognition
  • Sponsor Us

Publish with EAI

  • Publishing
  • Journals
  • Proceedings
  • Books
  • EUDL