Hier finden Sie wissenschaftliche Publikationen aus den Fraunhofer-Instituten.

SecDevOps: Is it a marketing buzzword? Mapping research on security in DevOps

: Mohan, V.; Ben Othmane, L.


Institute of Electrical and Electronics Engineers -IEEE-:
11th International Conference on Availability, Reliability and Security, ARES 2016 : Salzburg, Austria, 31 August - 2 September 2016; Proceedings
Los Alamitos, Calif.: IEEE Computer Society Conference Publishing Services (CPS), 2016
ISBN: 978-1-5090-0990-9
ISBN: 978-1-5090-0989-3
ISBN: 978-1-5090-0991-6
International Conference on Availability, Reliability and Security (ARES) <11, 2016, Salzburg>
Fraunhofer SIT ()

DevOps is changing the way organizations develop and deploy applications and service customers. Many organizations want to apply DevOps, but they are concerned by the security aspects of the produced software. This has triggered the creation of the terms SecDevOps and DevSecOps. These terms refer to incorporating security practices in a DevOps environment by promoting the collaboration between the development teams, the operations teams, and the security teams. This paper surveys the literature from academia and industry to identify the main aspects of this trend. The main aspects that we found are: definition, security best practices, compliance, process automation, tools for SecDevOps, software configuration, team collaboration, availability of activity data and information secrecy. Although the number of relevant publications is low, we believe that the terms are not buzzwords; they imply important challenges that the security and software communities shall address to help organizations develop secure software while applying DevOps processes.