Title: Integrating security within DevOps for continuous protection: securing software development through unified practices

Authors: Bahaa Eddine Elbaghazaoui; Tarik El Moudden; Salma El Omari; Soukaina Nai; Imane Moustati; Khalid Benabbes

Addresses: Laboratory of Research in Engineering Sciences and Innovation, National School of Applied Sciences (ENSA Beni-Mellal), Sultan Moulay Slimane University (USMS), Beni-Mellal, Morocco ' Interdisciplinary Laboratory of Sports Sciences, Institute of Sports Professions (IMS), Ibn Tofail University, Kenitra, Morocco ' Faculty of Sciences and Technics (FST), Sultan Moulay Slimane University, Beni Mellal, Morocco ' Computer Science Research Laboratory, Faculty of Sciences, Ibn Tofail University, Kenitra, Morocco ' National School of Applied Sciences (ENSA), Sultan Moulay Slimane University, Khouribga, Morocco ' M2IP Team, LM2I Laboratory, Department of Sciences, Ecole Normale Supérieure (ENS), Moulay Ismail University, Meknes, Morocco

Abstract: DevSecOps integrates security into the DevOps pipeline, embedding it as a core part of the software development lifecycle. This paper examines its evolution from traditional DevOps, emphasising principles such as Security as Code, Shift-Left Security and Continuous Monitoring, which together enable proactive vulnerability management and resilient delivery. It explores challenges including cultural resistance, skill gaps and the complexity of tool integration, while outlining practical solutions such as automating security checks, fostering a security-first culture and leveraging metrics to track progress. Future trends shaping DevSecOps are also discussed, including AI-driven threat detection, Zero Trust Architecture and Compliance-as-Code to streamline regulatory adherence. By addressing these aspects, organisations can achieve secure, agile and adaptive software delivery. The paper contributes an actionable, stage-wise adoption view that couples culture, process and CI/CD gate placement, illustrated with a small-business example and concrete outcome metrics to demonstrate practicality and measurable impact.

Keywords: DevSecOps; shift-left security; AI; artificial intelligence; zero trust architecture; compliance-as-code.

DOI: 10.1504/IJCAT.2026.154037

International Journal of Computer Applications in Technology, 2026 Vol.78 No.4, pp.348 - 364

Received: 06 Jan 2025
Accepted: 06 Nov 2025

Published online: 10 Jun 2026 *

Full-text access for editors Full-text access for subscribers Purchase this article Comment on this article