This study examines the challenges of securing DevOps environments through a unique combination of technical framework analysis and behavioural science insights. This is a conceptual analysis based on qualitative review and coding of publicly available DevSecOps frameworks. By analysing frameworks from organisations, such as Open Web Application Security Project, Cloud Security Alliance, the US National Institute of Standards and Technology, and the US Department of Defense, while applying behavioural economics and decision theory, the research investigates how cognitive biases affect security decision-making in DevSecOps and evaluates existing frameworks’ gaps. The analysis reveals a significant lack of mature, comprehensive, and regularly updated DevSecOps frameworks, with existing guidelines often lacking clarity, usability, or consideration of human factors. The study identifies key cognitive biases impacting security decisions and demonstrates how these are exacerbated by the absence of robust frameworks. While the research is limited by DevSecOps’ evolving nature and ongoing framework development, this limitation itself reflects the field’s nascent state and highlights opport
📖 افتح في inklap 🔗 DOI 📮 اطلب بحثاً