Repository logo
 

Identifying the Primary Dimensions of DevSecOps: A Multi-Vocal Literature Review

aut.relation.articlenumber112063
aut.relation.endpage112063
aut.relation.journalJournal of Systems and Software
aut.relation.startpage112063
aut.relation.volume214
dc.contributor.authorZhao, X
dc.contributor.authorClear, Tony
dc.contributor.authorLal, R
dc.date.accessioned2024-05-16T23:21:31Z
dc.date.available2024-05-16T23:21:31Z
dc.date.issued2024-04-30
dc.description.abstractContext: Security as a key non-functional requirement of software development is often ignored and devalued in DevOps programs, with security seen as an inhibitor to high velocity required in DevOps implementation. Hence, the DevSecOps approach as a security-orientated expansion to DevOps, has aimed to integrate security into DevOps implementation by promoting collaboration among development, operation and security teams. DevSecOps is a topical concept and rapidly emerging area of practice in both academic and industrial settings. Objective: We reviewed both the white and grey literature to identify recent researches and practical trends of DevSecOps, aiming to: (a) review, document and analyze the current state of DevSecOps in the existing literature; (b) investigate the application of DevSecOps in Global Software Engineering (GSE) contexts. Method: A Multi-vocal Literature Review on DevSecOps and its global application was conducted, by executing a dual-track strategy including white (104 studies) and grey (43 studies) literature from 2012 to 2021. A Thematic Analysis was performed to identify, synthesize and analyze the themes within data for reporting the MLR results. Results: Through the Multi-vocal Literature Review and Thematic Analysis, this paper identifies five major aspects of DevSecOps (Definitions, Challenges, Practices, Tools/Technologies, and Metrics/Measurement); collects related themes of each aspect; and generates a Challenge-Practice-Tool-Metric (CPTM) model by integrating the themes of the latter four aspects within a lifecycle model. Moreover, an unexplored area relating to the global application of DevSecOps has been identified. Conclusion: Based on MLR results, a CPTM (Challenge-Practice-Tool-Metric) model is built to reveal the current status of DevSecOps. The model provides a breakdown and a broad landscape of DevSecOps, from which researchers and practitioners may select an area of focus to improve their knowledge or practice. With DevSecOps spanning the many stages of the lifecycle, we believe the model will enable emphases and absences such as global aspects to be investigated. Editor's note: Open Science material was validated by the Journal of Systems and Software Open Science Board.
dc.identifier.citationJournal of Systems and Software, ISSN: 0164-1212 (Print), Elsevier BV, 214, 112063-112063. doi: 10.1016/j.jss.2024.112063
dc.identifier.doi10.1016/j.jss.2024.112063
dc.identifier.issn0164-1212
dc.identifier.urihttp://hdl.handle.net/10292/17557
dc.languageen
dc.publisherElsevier BV
dc.relation.urihttps://www.sciencedirect.com/science/article/pii/S0164121224001080
dc.rights© 2024 The Author(s). Published by Elsevier Inc. This is an open access article under the CC BY license (http://creativecommons.org/licenses/by/4.0/).
dc.rights.accessrightsOpenAccess
dc.rights.urihttp://creativecommons.org/licenses/by/4.0/
dc.subject46 Information and Computing Sciences
dc.subject4612 Software Engineering
dc.subject4 Quality Education
dc.subject0803 Computer Software
dc.subject0804 Data Format
dc.subject0806 Information Systems
dc.subjectSoftware Engineering
dc.subject46 Information and computing sciences
dc.titleIdentifying the Primary Dimensions of DevSecOps: A Multi-Vocal Literature Review
dc.typeJournal Article
pubs.elements-id548008

Files

Original bundle

Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
Zhao et al_2024_Identifying the primary dimensions of DevSecOps.pdf
Size:
4.42 MB
Format:
Adobe Portable Document Format
Description:
Journal article