Integrating DevSecOps into Information Security for Software Development: A Systematic Review
Descripción del Articulo
The increase in cyber threats and the need to integrate security into the software lifecycle have driven the adoption of DevSecOps as an evolution of DevOps. This study aimed to analyze the benefits, challenges, and trends of integrating DevSecOps tools into information security applied to software...
| Autores: | , , |
|---|---|
| Formato: | artículo |
| Fecha de Publicación: | 2026 |
| Institución: | Universidad Privada de Tacna |
| Repositorio: | Revistas - Universidad Privada de Tacna |
| Lenguaje: | español |
| OAI Identifier: | oai:revistas.upt.edu.pe:article/1396 |
| Enlace del recurso: | https://revistas.upt.edu.pe/ojs/index.php/ingenieria/article/view/1396 |
| Nivel de acceso: | acceso abierto |
| Materia: | DevSecOps seguridad de la información desarrollo de software automatización CI/CD information security software development automation |
| id |
REVUPT_ec65a6555bf1872e948230d2d55caaf1 |
|---|---|
| oai_identifier_str |
oai:revistas.upt.edu.pe:article/1396 |
| network_acronym_str |
REVUPT |
| network_name_str |
Revistas - Universidad Privada de Tacna |
| repository_id_str |
|
| spelling |
Integrating DevSecOps into Information Security for Software Development: A Systematic ReviewIntegración de DevSecOps en la seguridad de la información para el desarrollo de software: Una revisión sistemáticaMonzon Llanos, Jhonatan EfrainAlayo Gamboa, Pamela DomingaMendoza de los Santos, Alberto CarlosDevSecOpsseguridad de la informacióndesarrollo de softwareautomatizaciónCI/CDDevSecOpsinformation securitysoftware developmentautomationCI/CDThe increase in cyber threats and the need to integrate security into the software lifecycle have driven the adoption of DevSecOps as an evolution of DevOps. This study aimed to analyze the benefits, challenges, and trends of integrating DevSecOps tools into information security applied to software development. For this purpose, the PRISMA methodology was used and searches were carried out in academic databases such as arXiv, Google Scholar, SCOPUS, and IEEE Xplore. This enabled the selection and analysis of 18 significant articles published between 2020 and 2025. The findings show that implementing DevSecOps allows for the early identification of vulnerabilities, improves the resilience of systems, and fosters a shared security culture among development groups. However, challenges related to tool compatibility, organizational development, and the need for integrative frameworks persist. Thus, DevSecOps is emerging as a key approach to optimizing software continuity and reliability. However, its long-term sustainability depends on future research investigating predictive models, evaluation metrics, and the use of technologies such as artificial intelligence and advanced automation.El incremento de amenazas cibernéticas y la necesidad de integrar la seguridad en el ciclo de vida del software han impulsado la adopción de DevSecOps como evolución de DevOps. El presente estudio tuvo como objetivo analizar los beneficios, desafíos y tendencias de la integración de herramientas DevSecOps en la seguridad de la información aplicada al desarrollo de software. Con este propósito, se utilizó la metodología PRISMA y se llevaron a cabo búsquedas en bases de datos académicas como arXiv, Google Académico, SCOPUS e IEEE Xplore. Esto posibilitó la selección y el análisis de 18 artículos significativos publicados entre 2020 y 2025. Los hallazgos muestran que implementar DevSecOps permite identificar vulnerabilidades de manera anticipada, mejora la capacidad de los sistemas para resistir y fomentar una cultura compartida de seguridad entre los grupos de desarrollo, sin embargo, persisten retos vinculados con la compatibilidad de herramientas, el desarrollo organizacional y la necesidad de marcos integradores. Es así que, DevSecOps se constituye como un enfoque clave para optimizar la continuidad y confiabilidad del software. Aunque, su sostenibilidad a largo plazo está condicionada a futuras investigaciones que indaguen sobre modelos predictivos, métricas de evaluación y la utilización de tecnologías como inteligencia artificial y automatización avanzada.UNIVERSIDAD PRIVADA DE TACNA2026-02-19info:eu-repo/semantics/articleinfo:eu-repo/semantics/publishedVersionapplication/pdftext/htmlhttps://revistas.upt.edu.pe/ojs/index.php/ingenieria/article/view/139610.47796/ing.v8i00.1396INGENIERÍA INVESTIGA; Vol. 8 (2026): Ingeniería Investiga; e1396INGENIERÍA INVESTIGA; Vol. 8 (2026): Ingeniería Investiga; e13962708-303910.47796/ing.v8i00reponame:Revistas - Universidad Privada de Tacnainstname:Universidad Privada de Tacnainstacron:UPTspahttps://revistas.upt.edu.pe/ojs/index.php/ingenieria/article/view/1396/1150https://revistas.upt.edu.pe/ojs/index.php/ingenieria/article/view/1396/1175Derechos de autor 2026 Jhonatan Efrain Monzon Llanos, Pamela Dominga Alayo Gamboa, Alberto Carlos Mendoza de los Santoshttp://creativecommons.org/licenses/by/4.0info:eu-repo/semantics/openAccessoai:revistas.upt.edu.pe:article/13962026-05-05T15:03:38Z |
| dc.title.none.fl_str_mv |
Integrating DevSecOps into Information Security for Software Development: A Systematic Review Integración de DevSecOps en la seguridad de la información para el desarrollo de software: Una revisión sistemática |
| title |
Integrating DevSecOps into Information Security for Software Development: A Systematic Review |
| spellingShingle |
Integrating DevSecOps into Information Security for Software Development: A Systematic Review Monzon Llanos, Jhonatan Efrain DevSecOps seguridad de la información desarrollo de software automatización CI/CD DevSecOps information security software development automation CI/CD |
| title_short |
Integrating DevSecOps into Information Security for Software Development: A Systematic Review |
| title_full |
Integrating DevSecOps into Information Security for Software Development: A Systematic Review |
| title_fullStr |
Integrating DevSecOps into Information Security for Software Development: A Systematic Review |
| title_full_unstemmed |
Integrating DevSecOps into Information Security for Software Development: A Systematic Review |
| title_sort |
Integrating DevSecOps into Information Security for Software Development: A Systematic Review |
| dc.creator.none.fl_str_mv |
Monzon Llanos, Jhonatan Efrain Alayo Gamboa, Pamela Dominga Mendoza de los Santos, Alberto Carlos |
| author |
Monzon Llanos, Jhonatan Efrain |
| author_facet |
Monzon Llanos, Jhonatan Efrain Alayo Gamboa, Pamela Dominga Mendoza de los Santos, Alberto Carlos |
| author_role |
author |
| author2 |
Alayo Gamboa, Pamela Dominga Mendoza de los Santos, Alberto Carlos |
| author2_role |
author author |
| dc.subject.none.fl_str_mv |
DevSecOps seguridad de la información desarrollo de software automatización CI/CD DevSecOps information security software development automation CI/CD |
| topic |
DevSecOps seguridad de la información desarrollo de software automatización CI/CD DevSecOps information security software development automation CI/CD |
| description |
The increase in cyber threats and the need to integrate security into the software lifecycle have driven the adoption of DevSecOps as an evolution of DevOps. This study aimed to analyze the benefits, challenges, and trends of integrating DevSecOps tools into information security applied to software development. For this purpose, the PRISMA methodology was used and searches were carried out in academic databases such as arXiv, Google Scholar, SCOPUS, and IEEE Xplore. This enabled the selection and analysis of 18 significant articles published between 2020 and 2025. The findings show that implementing DevSecOps allows for the early identification of vulnerabilities, improves the resilience of systems, and fosters a shared security culture among development groups. However, challenges related to tool compatibility, organizational development, and the need for integrative frameworks persist. Thus, DevSecOps is emerging as a key approach to optimizing software continuity and reliability. However, its long-term sustainability depends on future research investigating predictive models, evaluation metrics, and the use of technologies such as artificial intelligence and advanced automation. |
| publishDate |
2026 |
| dc.date.none.fl_str_mv |
2026-02-19 |
| dc.type.none.fl_str_mv |
info:eu-repo/semantics/article info:eu-repo/semantics/publishedVersion |
| format |
article |
| status_str |
publishedVersion |
| dc.identifier.none.fl_str_mv |
https://revistas.upt.edu.pe/ojs/index.php/ingenieria/article/view/1396 10.47796/ing.v8i00.1396 |
| url |
https://revistas.upt.edu.pe/ojs/index.php/ingenieria/article/view/1396 |
| identifier_str_mv |
10.47796/ing.v8i00.1396 |
| dc.language.none.fl_str_mv |
spa |
| language |
spa |
| dc.relation.none.fl_str_mv |
https://revistas.upt.edu.pe/ojs/index.php/ingenieria/article/view/1396/1150 https://revistas.upt.edu.pe/ojs/index.php/ingenieria/article/view/1396/1175 |
| dc.rights.none.fl_str_mv |
http://creativecommons.org/licenses/by/4.0 info:eu-repo/semantics/openAccess |
| rights_invalid_str_mv |
http://creativecommons.org/licenses/by/4.0 |
| eu_rights_str_mv |
openAccess |
| dc.format.none.fl_str_mv |
application/pdf text/html |
| dc.publisher.none.fl_str_mv |
UNIVERSIDAD PRIVADA DE TACNA |
| publisher.none.fl_str_mv |
UNIVERSIDAD PRIVADA DE TACNA |
| dc.source.none.fl_str_mv |
INGENIERÍA INVESTIGA; Vol. 8 (2026): Ingeniería Investiga; e1396 INGENIERÍA INVESTIGA; Vol. 8 (2026): Ingeniería Investiga; e1396 2708-3039 10.47796/ing.v8i00 reponame:Revistas - Universidad Privada de Tacna instname:Universidad Privada de Tacna instacron:UPT |
| instname_str |
Universidad Privada de Tacna |
| instacron_str |
UPT |
| institution |
UPT |
| reponame_str |
Revistas - Universidad Privada de Tacna |
| collection |
Revistas - Universidad Privada de Tacna |
| repository.name.fl_str_mv |
|
| repository.mail.fl_str_mv |
|
| _version_ |
1868353942638821376 |
| score |
13.411838 |
Nota importante:
La información contenida en este registro es de entera responsabilidad de la institución que gestiona el repositorio institucional donde esta contenido este documento o set de datos. El CONCYTEC no se hace responsable por los contenidos (publicaciones y/o datos) accesibles a través del Repositorio Nacional Digital de Ciencia, Tecnología e Innovación de Acceso Abierto (ALICIA).
La información contenida en este registro es de entera responsabilidad de la institución que gestiona el repositorio institucional donde esta contenido este documento o set de datos. El CONCYTEC no se hace responsable por los contenidos (publicaciones y/o datos) accesibles a través del Repositorio Nacional Digital de Ciencia, Tecnología e Innovación de Acceso Abierto (ALICIA).