The role of standardization in DevSecOp practices in improving the security posture of software development in Sri Lanka

Show simple item record

dc.contributor.author Dharmarathne, D.N.S.
dc.contributor.author Shakya, R.D.N.
dc.contributor.author Kulatunge, R.
dc.contributor.author Abeysekara, J.
dc.date.accessioned 2024-04-17T04:41:46Z
dc.date.available 2024-04-17T04:41:46Z
dc.date.issued 2023-11-24
dc.identifier.issn 3021-6834
dc.identifier.uri http://ir.lib.ruh.ac.lk/handle/iruor/16848
dc.description.abstract The development, security, and operations (DevSecOps) paradigm, which involves incorporating security practices into the software development process, is becoming increasingly popular as an effective way to achieve secure and efficient software development. This research explores the crucial role of standardization in DevSecOps practices and its impact on enhancing the security posture of software development in Sri-Lanka while attempting to identify the current industry standards for DevSecOps. Secondly, it intends to choose a suitable standard to assess the security level of software development companies in Sri-Lanka and then to analyze the DevSecOps components that are most effective for measuring security levels. Additionally, a Standardization Maturity Model (SMM) is designed and developed to measure security levels based on the selected standard. Finally, the research measures security levels in Sri Lankan software development companies by utilizing the DevSecOps standards at the Department of Defense. The study employs a mixed-methods approach, to understand the current state of DevSecOps practices and standardization efforts in the Sri-Lankan software development industry. The research methodology involves surveys and interviews with DevOps stakeholders: practitioners, engineers, tech leads, and security professionals. The collected data were analyzed to assess the existing practices, identify security challenges, and evaluate the level of adoption of standardized DevSecOps practices in Sri-Lanka. The study contributes to the existing body of knowledge by highlighting the significance of standardization in DevSecOps practices in Sri-Lanka. The findings will shed light on the security landscape in software development, identify potential areas for improvement, and propose recommendations for adopting standardized DevSecOps practices. en_US
dc.language.iso en en_US
dc.publisher Faculty of Technology, University of Ruhuna, Sri Lanka en_US
dc.subject DevSecOps en_US
dc.subject Standardization en_US
dc.subject Security posture en_US
dc.title The role of standardization in DevSecOp practices in improving the security posture of software development in Sri Lanka en_US
dc.type Article en_US


Files in this item

This item appears in the following Collection(s)

Show simple item record

Search DSpace


Advanced Search

Browse

My Account