Implementing Security by Design practice with DevSecOps Shift Left Approach
Abstract
This research paper explores the integration of security practices into the DevOps process, known as DevSecOps, focusing on implementing security by design principles. It investigates the challenges organizations face in ensuring the security of their software applications and examines the benefits of adopting a DevSecOps approach. The paper provides guidance on implementing security by design practices within the DevSecOps pipeline, presenting a comprehensive framework and recommending tools for planning, development, testing, and deployment phases.
Keywords
DevSecOps, Security by Design, Shift Left Strategy, Cybersecurity, Software Development Lifecycle (SDLC), Automated Security Testing, Secure Coding Practices, Infrastructure as Code (IaC), Vulnerability Assessment, Compliance Validation, Static Code Analysis, Dynamic Application Security Testing (DAST), Container Security, Threat Modeling, Continuous Integration/Continuous Deployment (CI/CD), Identity and Access Management (IAM), Logging and Monitoring, Security Automation and Orchestration