Home / Current Issue / Paper 1712035
Devsecops in Practice: How Integrating Security into CI/CD Pipelines Changes the Way We Engineer Software
Subject area: Science,Engineering and Technology · Area of research: Software Engineering
DOI: https://doi.org/10.64388/IREV9I5-1712035
Abstract
The Continuous Integration (CI) and Continuous Deployment (CD), which was rapidly ratified by the software engineering development industry, turned into a fast-paced process, causing new insecurity threat to be generated. This paper therefore, explains how integrating security into CI/CD pipelines changes the way we engineer software through Development Security Operations (DevSecOps). Integrating security into CI/CD pipelines via DevSecOps fundamentally transforms software engineering by shifting security from a late-stage bottleneck to an intrinsic, automated part of the entire development lifecycle, promoting early vulnerability detection, reducing costs and risks, fostering a collaborative culture, and ultimately enabling faster delivery of inherently more secure software. This "shifting left" approach uses automation and tools like Static Application Security Testing (SAST) and Dynamic Application Security Testing (DAST) to embed security checks, policy enforcement, and monitoring directly into developer workflows, ensuring security is a shared, continuous responsibility rather than a separate, disruptive activity.
How to cite this paper
@article{1712035,
author = {Udokporo Jamachi Bernard},
title = {Devsecops in Practice: How Integrating Security into CI/CD Pipelines Changes the Way We Engineer Software},
journal = {Iconic Research And Engineering Journals},
year = {2025},
volume = {9},
number = {5},
pages = {2832-2840},
issn = {2456-8880},
url = {https://www.irejournals.com/formatedpaper/1712035.pdf},
abstract = {The Continuous Integration (CI) and Continuous Deployment (CD), which was rapidly ratified by the software engineering development industry, turned into a fast-paced process, causing new insecurity threat to be generated. This paper therefore, explains how integrating security into CI/CD pipelines changes the way we engineer software through Development Security Operations (DevSecOps). Integrating security into CI/CD pipelines via DevSecOps fundamentally transforms software engineering by shifting security from a late-stage bottleneck to an intrinsic, automated part of the entire development lifecycle, promoting early vulnerability detection, reducing costs and risks, fostering a collaborative culture, and ultimately enabling faster delivery of inherently more secure software. This "shifting left" approach uses automation and tools like Static Application Security Testing (SAST) and Dynamic Application Security Testing (DAST) to embed security checks, policy enforcement, and monitoring directly into developer workflows, ensuring security is a shared, continuous responsibility rather than a separate, disruptive activity.},
month = {November},
doi = {https://doi.org/10.64388/IREV9I5-1712035}
}