Title: Integrating security within DevOps for continuous protection: securing software development through unified practices
Authors: Bahaa Eddine Elbaghazaoui; Tarik El Moudden; Salma El Omari; Soukaina Nai; Imane Moustati; Khalid Benabbes
Addresses: Laboratory of Research in Engineering Sciences and Innovation, National School of Applied Sciences (ENSA Beni-Mellal), Sultan Moulay Slimane University (USMS), Beni-Mellal, Morocco ' Interdisciplinary Laboratory of Sports Sciences, Institute of Sports Professions (IMS), Ibn Tofail University, Kenitra, Morocco ' Faculty of Sciences and Technics (FST), Sultan Moulay Slimane University, Beni Mellal, Morocco ' Computer Science Research Laboratory, Faculty of Sciences, Ibn Tofail University, Kenitra, Morocco ' National School of Applied Sciences (ENSA), Sultan Moulay Slimane University, Khouribga, Morocco ' M2IP Team, LM2I Laboratory, Department of Sciences, Ecole Normale Supérieure (ENS), Moulay Ismail University, Meknes, Morocco
Abstract: DevSecOps integrates security into the DevOps pipeline, embedding it as a core part of the software development lifecycle. This paper examines its evolution from traditional DevOps, emphasising principles such as Security as Code, Shift-Left Security and Continuous Monitoring, which together enable proactive vulnerability management and resilient delivery. It explores challenges including cultural resistance, skill gaps and the complexity of tool integration, while outlining practical solutions such as automating security checks, fostering a security-first culture and leveraging metrics to track progress. Future trends shaping DevSecOps are also discussed, including AI-driven threat detection, Zero Trust Architecture and Compliance-as-Code to streamline regulatory adherence. By addressing these aspects, organisations can achieve secure, agile and adaptive software delivery. The paper contributes an actionable, stage-wise adoption view that couples culture, process and CI/CD gate placement, illustrated with a small-business example and concrete outcome metrics to demonstrate practicality and measurable impact.
Keywords: DevSecOps; shift-left security; AI; artificial intelligence; zero trust architecture; compliance-as-code.
DOI: 10.1504/IJCAT.2026.154037
International Journal of Computer Applications in Technology, 2026 Vol.78 No.4, pp.348 - 364
Received: 06 Jan 2025
Accepted: 06 Nov 2025
Published online: 10 Jun 2026 *