Automating Cybersecurity Compliance in DevSecOps with Open Information Model for Security as Code
Henry Haverinen, Tomi Janhunen, Tero Päivärinta, Sami Lempinen, Suvi Kaartinen, Sami Merilä · 2024
Software development teams meet increasing requirements to implement cybersecurity management in compliance with standards and regulations. However, adopting a compliant cybersecurity management system and DevSecOps practices as part of a software development process has turned out to be tedious and expensive in practice. Open-source communities and open ecosystems, which lack tools and realistic practices for compliant cybersecurity management, face these difficulties as well.