Hyppää sisältöön
    • Suomeksi
    • På svenska
    • In English
  • Suomeksi
  • In English
  • Kirjaudu
Näytä aineisto 
  •   Etusivu
  • LUTPub
  • Tieteelliset julkaisut
  • Näytä aineisto
  •   Etusivu
  • LUTPub
  • Tieteelliset julkaisut
  • Näytä aineisto
JavaScript is disabled for your browser. Some features of this site may not work without it.

Management of DevSecOps Process: An Empirical Investigation

Akbar, Muhammad Azeem; Khan, Arif Ali; Mehmood, Sajjad; Hyrynsalmi, Sami (2025-03-13)

Katso/Avaa
akbar_et_al_management_of_devsecops_aam.pdf (1.225Mb)
Huom!
Sisältö avataan julkiseksi
: 14.03.2026

Post-print / Final draft

Akbar, Muhammad Azeem
Khan, Arif Ali
Mehmood, Sajjad
Hyrynsalmi, Sami
13.03.2025

Software: Practice and Experience

John Wiley & Sons Ltd.

School of Engineering Science

Kaikki oikeudet pidätetään.
© 2025 John Wiley & Sons Ltd.
https://doi.org/10.1002/spe.3419
Näytä kaikki kuvailutiedot
Julkaisun pysyvä osoite on
https://urn.fi/URN:NBN:fi-fe2025033122373

Tiivistelmä

Context: DevSecOps integrates security into the DevOps project lifecycle, uniting development, operations, and security practices. This integration, while beneficial for developing secure software, introduces complexity from a project management perspective. This study delves into this complexity by examining the ten knowledge areas of the Project Management Body of Knowledge (PMBOK) within the context of DevSecOps project management. Objective: This study aims to explore and understand the application of PMBOK's ten knowledge areas in managing DevSecOps projects, focusing on the guidelines that are important to consider in integration of security practices throughout the development lifecycle. Method: Our research approach involved two phases: Firstly, we developed a theoretical model grounded in DevSecOps guidelines identified from existing literature. Secondly, we conducted a quantitative survey targeting industry practitioners to gather insights into the practical application of the theoretical model. The study involved 138 responses from professionals, which were subsequently analyzed using correlation and Partial Least Squares (PLS) analysis to test the hypotheses posited in the theoretical model. Results: The analysis reveals critical insights into the management of DevSecOps projects, highlighting the importance of adhering to specific guidelines to navigate the complexities introduced by the integration of security practices. The empirical data support the theoretical model, underscoring the relevance of PMBOK's knowledge areas in the successful management of DevSecOps projects. Conclusion: For organizations committed to the DevSecOps paradigm, it is imperative to consider and implement the identified guidelines. These guidelines not only support the sustainable integration of security practices into DevOps projects but also contribute to the overall success and security of the software developed under this paradigm.

Lähdeviite

Akbar, M.A., Khan, A.A., Mahmood, S. and Hyrynsalmi, S. (2025), Management of DevSecOps Process: An Empirical Investigation. Softw: Pract Exper. https://doi.org/10.1002/spe.3419

Alkuperäinen verkko-osoite

https://onlinelibrary.wiley.com/doi/10.1002/spe.3419
Kokoelmat
  • Tieteelliset julkaisut [1763]
LUT-yliopisto
PL 20
53851 Lappeenranta
Ota yhteyttä | Tietosuoja | Saavutettavuusseloste
 

 

Tämä kokoelma

JulkaisuajatTekijätNimekkeetKoulutusohjelmaAvainsanatSyöttöajatYhteisöt ja kokoelmat

Omat tiedot

Kirjaudu sisäänRekisteröidy
LUT-yliopisto
PL 20
53851 Lappeenranta
Ota yhteyttä | Tietosuoja | Saavutettavuusseloste