Home / Current Issue / Paper 1712035
Devsecops in Practice: How Integrating Security into CI/CD Pipelines Changes the Way We Engineer Software
Subject area: Science,Engineering and Technology · Area of research: Software Engineering
Abstract
The Continuous Integration (CI) and Continuous Deployment (CD), which was rapidly ratified by the software engineering development industry, turned into a fast-paced process, causing new insecurity threat to be generated. This paper therefore, explains how integrating security into CI/CD pipelines changes the way we engineer software through Development Security Operations (DevSecOps). Integrating security into CI/CD pipelines via DevSecOps fundamentally transforms software engineering by shifting security from a late-stage bottleneck to an intrinsic, automated part of the entire development lifecycle, promoting early vulnerability detection, reducing costs and risks, fostering a collaborative culture, and ultimately enabling faster delivery of inherently more secure software. This "shifting left" approach uses automation and tools like Static Application Security Testing (SAST) and Dynamic Application Security Testing (DAST) to embed security checks, policy enforcement, and monitoring directly into developer workflows, ensuring security is a shared, continuous responsibility rather than a separate, disruptive activity.
References
[1] Adedamola Solanke (2022), Enterprise DevSecOps: Integrating Security into CI/CD Pipelines for Regulated Industries. February 2022. World Journal of Advanced Research and Reviews 13(02):633-648 DOI: 10.30574/wjarr.2022.13.2.0121
[2] Codefresh (2025), DevSecOps Pipeline: Steps, Challenges, and 5 Critical Best Practices. Codefresh by Octopus Deploy. 2025 Codefresh. Terms of Service.https://codefresh.io/learn/devsecops/devsecops-pipeline/
[3] Misbah Thevarmannil (2023), DevSecOps CI/CD: Enhancing Security in the Age of Continous Delivery. 16 November 202. Practical DevSecOps and Hysn Technologies Inc. registrations@practical-devsecops.com
[4] Naga Murali Krishna Koneru (2021), Integrating Security into CI/CD Pipelines: A DevSecOps Approach with SAST, DAST, and SCA Tools. October 2021. International Journal of Science and Research Archive 3(1):250-265DOI: 10.30574/ijsra.2021.3.1.0080
[5] Seemplicity (2025), DevSecOps. Yigal Alon St 94, building 2, Floor 14, Tel Aviv-Yafo, 6789139, Israel 181 Metro Drive, San Jose, CA 95110 sales@seemplicity.iopartners@seemplicity.io
How to cite this paper
@article{1712035,
author = {Udokporo Jamachi Bernard},
title = {Devsecops in Practice: How Integrating Security into CI/CD Pipelines Changes the Way We Engineer Software},
journal = {Iconic Research And Engineering Journals},
year = {2025},
volume = {9},
number = {5},
pages = {2832-2840},
issn = {2456-8880},
url = {https://www.irejournals.com/formatedpaper/1712035.pdf},
abstract = {The Continuous Integration (CI) and Continuous Deployment (CD), which was rapidly ratified by the software engineering development industry, turned into a fast-paced process, causing new insecurity threat to be generated. This paper therefore, explains how integrating security into CI/CD pipelines changes the way we engineer software through Development Security Operations (DevSecOps). Integrating security into CI/CD pipelines via DevSecOps fundamentally transforms software engineering by shifting security from a late-stage bottleneck to an intrinsic, automated part of the entire development lifecycle, promoting early vulnerability detection, reducing costs and risks, fostering a collaborative culture, and ultimately enabling faster delivery of inherently more secure software. This "shifting left" approach uses automation and tools like Static Application Security Testing (SAST) and Dynamic Application Security Testing (DAST) to embed security checks, policy enforcement, and monitoring directly into developer workflows, ensuring security is a shared, continuous responsibility rather than a separate, disruptive activity.},
month = {November},
doi = {https://doi.org/10.64388/IREV9I5-1712035}
}