Context: DevOps has become one of the fastest-growing software development paradigms in the industry. However, this trend has presented the challenge of ensuring secure software delivery while maintaining the agility of DevOps. The efforts to integrate security in DevOps have resulted in the DevSecOps paradigm, which is gaining significant interest from both industry and academia. However, the adoption of DevSecOps in practice is proving to be a challenge. Objective: This study aims to systemize the knowledge about the challenges faced by practitioners when adopting DevSecOps and the proposed solutions reported in the literature. We also aim to identify the areas that need further research in the future. Method: We conducted a Systematic Literature Review of 54 peer-reviewed studies. The thematic analysis method was applied to analyze the extracted data. Results: We identified 21 challenges related to adopting DevSecOps, 31 specific solutions, and the mapping between these findings. We also determined key gap areas in this domain by holistically evaluating the available solutions against the challenges. The results of the study were classified into four themes: People, Practices, Tools, and Infrastructure. Our findings demonstrate that tool-related challenges and solutions were the most frequently reported, driven by the need for automation in this paradigm. Shift-left security and continuous security assessment were two key practices recommended for DevSecOps. Conclusions: We highlight the need for developer-centered application security testing tools that target the continuous practices in DevSecOps. More research is needed on how the traditionally manual security practices can be automated to suit rapid software deployment cycles. Finally, achieving a suitable balance between the speed of delivery and security is a significant issue practitioners face in the DevSecOps paradigm.
翻译:DevSecOps的采用已成为该行业中一个增长最快的软件开发模式之一。然而,这一趋势也提出了确保安全软件交付同时又保持DevOps灵活性的挑战。DevOps的整合安全工作导致DevSecOps的版本,这引起了业界和学术界的极大兴趣。然而,在实践中采用DevSecOps是一个挑战。目标:这项研究旨在系统化关于从业人员在采用DevSecOps和文献中所报告的拟议解决方案时所面临挑战的知识。我们还旨在确定今后需要进一步研究的领域。方法:我们进行了54项同行审评研究的系统化文献审查。专题分析方法用于分析提取的数据。结果:我们查明了21项挑战,涉及采用DevSecOps、31项具体解决方案以及这些结论之间的绘图。我们还确定了这一领域的关键差距领域,从整体角度评价现有应对挑战的解决方案。研究结果分为四个主题:人、做法、工具和基础设施。我们关于安全部署系统化做法的系统化审查:我们关于安全方面的风险和解决方案的动态分析方法,最终被报告为安全SDFSEVEV的两次持续安全测试。我们关于安全方面的主要标准测试需要实现。