DevSecOps Practices for GDPR, HIPAA or LGPD Compliance in Software Development: A Systematic Review
Denisson S. A. de Freitas, Adicinéia Aparecida de Oliveira, Edward David Moreno, Gilton J. F. da Silva · 2025
Context: The current software development scenario requires integrating security and regulatory compliance practices, especially after implementing regulations such as LGPD, GDPR, and HIPAA. Problem: There is a lack of frameworks that effectively combine security, regulatory compliance, and continuous software delivery in DevSecOps environments. Solution: This study aims to identify and analyze approaches, methods, tools, and frameworks that promote regulatory compliance in DevSecOps practices through a systematic literature review. IS Theory: Sociotechnical Theory underpins the analysis, considering the interaction between technical (automated tools and processes) and social (organizational culture and collaborative practices) aspects necessary to effectively implement regulatory compliance. Method: A systematic review was carried out following the guidelines for performing systematic literature reviews in software engineering and analyzing 15 primary studies identified in five scientific databases (ACM Digital Library, IEEE Xplore Digital Library,Web of Science, Science Direct and Scopus). Summarization of Results: The need for automation of compliance checks, early integration of security practices, and establishing an organizational culture that prioritizes regulatory compliance was identified. Contributions and Impact on IS: The study provides an overview of existing practices and frameworks, highlighting the need for a sociotechnical approach that integrates technological and organizational aspects to ensure regulatory compliance in DevSecOps environments, contributing to the advancement of secure software development practices.