Integrating DevSecOps into Information Security for Software Development: A Systematic Review

Descripción del Articulo

The increase in cyber threats and the need to integrate security into the software lifecycle have driven the adoption of DevSecOps as an evolution of DevOps. This study aimed to analyze the benefits, challenges, and trends of integrating DevSecOps tools into information security applied to software...

Descripción completa

Detalles Bibliográficos
Autores: Monzon Llanos, Jhonatan Efrain, Alayo Gamboa, Pamela Dominga, Mendoza de los Santos, Alberto Carlos
Formato: artículo
Fecha de Publicación:2026
Institución:Universidad Privada de Tacna
Repositorio:Revistas - Universidad Privada de Tacna
Lenguaje:español
OAI Identifier:oai:revistas.upt.edu.pe:article/1396
Enlace del recurso:https://revistas.upt.edu.pe/ojs/index.php/ingenieria/article/view/1396
Nivel de acceso:acceso abierto
Materia:DevSecOps
seguridad de la información
desarrollo de software
automatización
CI/CD
information security
software development
automation
id REVUPT_ec65a6555bf1872e948230d2d55caaf1
oai_identifier_str oai:revistas.upt.edu.pe:article/1396
network_acronym_str REVUPT
network_name_str Revistas - Universidad Privada de Tacna
repository_id_str
spelling Integrating DevSecOps into Information Security for Software Development: A Systematic ReviewIntegración de DevSecOps en la seguridad de la información para el desarrollo de software: Una revisión sistemáticaMonzon Llanos, Jhonatan EfrainAlayo Gamboa, Pamela DomingaMendoza de los Santos, Alberto CarlosDevSecOpsseguridad de la informacióndesarrollo de softwareautomatizaciónCI/CDDevSecOpsinformation securitysoftware developmentautomationCI/CDThe increase in cyber threats and the need to integrate security into the software lifecycle have driven the adoption of DevSecOps as an evolution of DevOps. This study aimed to analyze the benefits, challenges, and trends of integrating DevSecOps tools into information security applied to software development. For this purpose, the PRISMA methodology was used and searches were carried out in academic databases such as arXiv, Google Scholar, SCOPUS, and IEEE Xplore. This enabled the selection and analysis of 18 significant articles published between 2020 and 2025. The findings show that implementing DevSecOps allows for the early identification of vulnerabilities, improves the resilience of systems, and fosters a shared security culture among development groups. However, challenges related to tool compatibility, organizational development, and the need for integrative frameworks persist. Thus, DevSecOps is emerging as a key approach to optimizing software continuity and reliability. However, its long-term sustainability depends on future research investigating predictive models, evaluation metrics, and the use of technologies such as artificial intelligence and advanced automation.El incremento de amenazas cibernéticas y la necesidad de integrar la seguridad en el ciclo de vida del software han impulsado la adopción de DevSecOps como evolución de DevOps. El presente estudio tuvo como objetivo analizar los beneficios, desafíos y tendencias de la integración de herramientas DevSecOps en la seguridad de la información aplicada al desarrollo de software. Con este propósito, se utilizó la metodología PRISMA y se llevaron a cabo búsquedas en bases de datos académicas como arXiv, Google Académico, SCOPUS e IEEE Xplore. Esto posibilitó la selección y el análisis de 18 artículos significativos publicados entre 2020 y 2025. Los hallazgos muestran que implementar DevSecOps permite identificar vulnerabilidades de manera anticipada, mejora la capacidad de los sistemas para resistir y fomentar una cultura compartida de seguridad entre los grupos de desarrollo, sin embargo, persisten retos vinculados con la compatibilidad de herramientas, el desarrollo organizacional y la necesidad de marcos integradores. Es así que, DevSecOps se constituye como un enfoque clave para optimizar la continuidad y confiabilidad del software. Aunque, su sostenibilidad a largo plazo está condicionada a futuras investigaciones que indaguen sobre modelos predictivos, métricas de evaluación y la utilización de tecnologías como inteligencia artificial y automatización avanzada.UNIVERSIDAD PRIVADA DE TACNA2026-02-19info:eu-repo/semantics/articleinfo:eu-repo/semantics/publishedVersionapplication/pdftext/htmlhttps://revistas.upt.edu.pe/ojs/index.php/ingenieria/article/view/139610.47796/ing.v8i00.1396INGENIERÍA INVESTIGA; Vol. 8 (2026): Ingeniería Investiga; e1396INGENIERÍA INVESTIGA; Vol. 8 (2026): Ingeniería Investiga; e13962708-303910.47796/ing.v8i00reponame:Revistas - Universidad Privada de Tacnainstname:Universidad Privada de Tacnainstacron:UPTspahttps://revistas.upt.edu.pe/ojs/index.php/ingenieria/article/view/1396/1150https://revistas.upt.edu.pe/ojs/index.php/ingenieria/article/view/1396/1175Derechos de autor 2026 Jhonatan Efrain Monzon Llanos, Pamela Dominga Alayo Gamboa, Alberto Carlos Mendoza de los Santoshttp://creativecommons.org/licenses/by/4.0info:eu-repo/semantics/openAccessoai:revistas.upt.edu.pe:article/13962026-05-05T15:03:38Z
dc.title.none.fl_str_mv Integrating DevSecOps into Information Security for Software Development: A Systematic Review
Integración de DevSecOps en la seguridad de la información para el desarrollo de software: Una revisión sistemática
title Integrating DevSecOps into Information Security for Software Development: A Systematic Review
spellingShingle Integrating DevSecOps into Information Security for Software Development: A Systematic Review
Monzon Llanos, Jhonatan Efrain
DevSecOps
seguridad de la información
desarrollo de software
automatización
CI/CD
DevSecOps
information security
software development
automation
CI/CD
title_short Integrating DevSecOps into Information Security for Software Development: A Systematic Review
title_full Integrating DevSecOps into Information Security for Software Development: A Systematic Review
title_fullStr Integrating DevSecOps into Information Security for Software Development: A Systematic Review
title_full_unstemmed Integrating DevSecOps into Information Security for Software Development: A Systematic Review
title_sort Integrating DevSecOps into Information Security for Software Development: A Systematic Review
dc.creator.none.fl_str_mv Monzon Llanos, Jhonatan Efrain
Alayo Gamboa, Pamela Dominga
Mendoza de los Santos, Alberto Carlos
author Monzon Llanos, Jhonatan Efrain
author_facet Monzon Llanos, Jhonatan Efrain
Alayo Gamboa, Pamela Dominga
Mendoza de los Santos, Alberto Carlos
author_role author
author2 Alayo Gamboa, Pamela Dominga
Mendoza de los Santos, Alberto Carlos
author2_role author
author
dc.subject.none.fl_str_mv DevSecOps
seguridad de la información
desarrollo de software
automatización
CI/CD
DevSecOps
information security
software development
automation
CI/CD
topic DevSecOps
seguridad de la información
desarrollo de software
automatización
CI/CD
DevSecOps
information security
software development
automation
CI/CD
description The increase in cyber threats and the need to integrate security into the software lifecycle have driven the adoption of DevSecOps as an evolution of DevOps. This study aimed to analyze the benefits, challenges, and trends of integrating DevSecOps tools into information security applied to software development. For this purpose, the PRISMA methodology was used and searches were carried out in academic databases such as arXiv, Google Scholar, SCOPUS, and IEEE Xplore. This enabled the selection and analysis of 18 significant articles published between 2020 and 2025. The findings show that implementing DevSecOps allows for the early identification of vulnerabilities, improves the resilience of systems, and fosters a shared security culture among development groups. However, challenges related to tool compatibility, organizational development, and the need for integrative frameworks persist. Thus, DevSecOps is emerging as a key approach to optimizing software continuity and reliability. However, its long-term sustainability depends on future research investigating predictive models, evaluation metrics, and the use of technologies such as artificial intelligence and advanced automation.
publishDate 2026
dc.date.none.fl_str_mv 2026-02-19
dc.type.none.fl_str_mv info:eu-repo/semantics/article
info:eu-repo/semantics/publishedVersion
format article
status_str publishedVersion
dc.identifier.none.fl_str_mv https://revistas.upt.edu.pe/ojs/index.php/ingenieria/article/view/1396
10.47796/ing.v8i00.1396
url https://revistas.upt.edu.pe/ojs/index.php/ingenieria/article/view/1396
identifier_str_mv 10.47796/ing.v8i00.1396
dc.language.none.fl_str_mv spa
language spa
dc.relation.none.fl_str_mv https://revistas.upt.edu.pe/ojs/index.php/ingenieria/article/view/1396/1150
https://revistas.upt.edu.pe/ojs/index.php/ingenieria/article/view/1396/1175
dc.rights.none.fl_str_mv http://creativecommons.org/licenses/by/4.0
info:eu-repo/semantics/openAccess
rights_invalid_str_mv http://creativecommons.org/licenses/by/4.0
eu_rights_str_mv openAccess
dc.format.none.fl_str_mv application/pdf
text/html
dc.publisher.none.fl_str_mv UNIVERSIDAD PRIVADA DE TACNA
publisher.none.fl_str_mv UNIVERSIDAD PRIVADA DE TACNA
dc.source.none.fl_str_mv INGENIERÍA INVESTIGA; Vol. 8 (2026): Ingeniería Investiga; e1396
INGENIERÍA INVESTIGA; Vol. 8 (2026): Ingeniería Investiga; e1396
2708-3039
10.47796/ing.v8i00
reponame:Revistas - Universidad Privada de Tacna
instname:Universidad Privada de Tacna
instacron:UPT
instname_str Universidad Privada de Tacna
instacron_str UPT
institution UPT
reponame_str Revistas - Universidad Privada de Tacna
collection Revistas - Universidad Privada de Tacna
repository.name.fl_str_mv
repository.mail.fl_str_mv
_version_ 1868353942638821376
score 13.411838
Nota importante:
La información contenida en este registro es de entera responsabilidad de la institución que gestiona el repositorio institucional donde esta contenido este documento o set de datos. El CONCYTEC no se hace responsable por los contenidos (publicaciones y/o datos) accesibles a través del Repositorio Nacional Digital de Ciencia, Tecnología e Innovación de Acceso Abierto (ALICIA).