SecDevOps: Is It a Marketing Buzzword? - Mapping Research on Security in DevOps

Vaishnavi Mohan, Lotfi Ben Othmane

2016 · 103 citations · 6 references

Concepts

TL;DR

DevOps is reshaping application development and deployment, yet many organizations hesitate due to security concerns, prompting the emergence of SecDevOps/DevSecOps terms that emphasize integrating security practices through collaboration among development, operations, and security teams. This paper surveys academic and industry literature to identify the main aspects of the SecDevOps trend. The authors perform a comprehensive literature review of both academic and industry sources to map SecDevOps practices. The survey uncovers key SecDevOps aspects—definition, security best practices, compliance, process automation, tooling, software configuration, team collaboration, activity data availability, and information secrecy—and concludes that, despite few publications, the terms represent real challenges rather than buzzwords.

Abstract

DevOps is changing the way organizations develop and deploy applications and service customers. Many organizations want to apply DevOps, but they are concerned by the security aspects of the produced software. This has triggered the creation of the terms SecDevOps and DevSecOps. These terms refer to incorporating security practices in a DevOps environment by promoting the collaboration between the development teams, the operations teams, and the security teams. This paper surveys the literature from academia and industry to identify the main aspects of this trend. The main aspects that we found are: definition, security best practices, compliance, process automation, tools for SecDevOps, software configuration, team collaboration, availability of activity data and information secrecy. Although the number of relevant publications is low, we believe that the terms are not buzzwords, they imply important challenges that the security and software communities shall address to help organizations develop secure software while applying DevOps processes.

References

6