Empirical Investigation of Key Enablers for Secure DevOps Practices

Muhammad Azeem Akbar, Abeer Abdulaziz Alsanad · IEEE Access · 2025

DevSecOps integrates security practices from development to operations in the search for faster and more secure responses to business needs. DevSecOps is an approach based on the 4 pillars of the CAMS model (culture, measurement, automation, and sharing). On the other hand, there is an increasing interest in ensuring sustainability in software work making it more optimal and viable overtime. Given that sustainability has not received much attention in the DevSecOps arena, this study aims to identify the enablers that are important for addressing CAMS by means of a multivocal literature review and to check their practical implacability in real-world practices. To do so, firstly, 35 enablers related to CAMS principles were identified as a result of the multivocal literature review conducted. Based on the literature findings, a hypothetical model was developed based on the DevSecOps enablers. Next, a quantitative survey was executed, and 214 responses were collected from experts. Finally, authors used Smart-PLS (3.0) and analyzed collected data to form the final set of enablers. Results show that these enablers could positively impact the execution of DevSecOps practices in a sustainable way. Additionally, results also reveal that when deploying DevSecOps, practitioners should consider the enablers that were explored and mapped against culture, automation, measurement, and sharing. The findings of this study will help practitioners and academics to understand DevSecOps principles and the areas that need to be considered by industry professionals to make DevSecOps sustainable.

Read the paper · More papers on PaperTik