Advancing DevSecOps in SMEs: Challenges and Best Practices for Secure CI/CD Pipelines
Fuente:
arXiv
Enregistré dans:
| Auteurs principaux: | , , , |
|---|---|
| Format: | Preprint |
| Publié: |
2025
|
| Sujets: | |
| Accès en ligne: | |
| Tags: |
Ajouter un tag
Pas de tags, Soyez le premier à ajouter un tag!
|
| _version_ | 1866918045235019776 |
|---|---|
| author | Cheenepalli, Jayaprakashreddy Hastings, John D. Ahmed, Khandaker Mamun Fenner, Chad |
| author_facet | Cheenepalli, Jayaprakashreddy Hastings, John D. Ahmed, Khandaker Mamun Fenner, Chad |
| contents | This study evaluates the adoption of DevSecOps among small and medium-sized enterprises (SMEs), identifying key challenges, best practices, and future trends. Through a mixed methods approach backed by the Technology Acceptance Model (TAM) and Diffusion of Innovations (DOI) theory, we analyzed survey data from 405 SME professionals, revealing that while 68% have implemented DevSecOps, adoption is hindered by technical complexity (41%), resource constraints (35%), and cultural resistance (38%). Despite strong leadership prioritization of security (73%), automation gaps persist, with only 12% of organizations conducting security scans per commit.
Our findings highlight a growing integration of security tools, particularly API security (63%) and software composition analysis (62%), although container security adoption remains low (34%). Looking ahead, SMEs anticipate artificial intelligence and machine learning to significantly influence DevSecOps, underscoring the need for proactive adoption of AI-driven security enhancements. Based on our findings, this research proposes strategic best practices to enhance CI/CD pipeline security including automation, leadership-driven security culture, and cross-team collaboration. |
| format | Preprint |
| id |
arxiv_https___arxiv_org_abs_2503_22612 |
| institution | arXiv |
| publishDate | 2025 |
| record_format | arxiv |
| spellingShingle | Advancing DevSecOps in SMEs: Challenges and Best Practices for Secure CI/CD Pipelines Cheenepalli, Jayaprakashreddy Hastings, John D. Ahmed, Khandaker Mamun Fenner, Chad Cryptography and Security Computers and Society Software Engineering D.2.2; K.6.5; D.2.9 This study evaluates the adoption of DevSecOps among small and medium-sized enterprises (SMEs), identifying key challenges, best practices, and future trends. Through a mixed methods approach backed by the Technology Acceptance Model (TAM) and Diffusion of Innovations (DOI) theory, we analyzed survey data from 405 SME professionals, revealing that while 68% have implemented DevSecOps, adoption is hindered by technical complexity (41%), resource constraints (35%), and cultural resistance (38%). Despite strong leadership prioritization of security (73%), automation gaps persist, with only 12% of organizations conducting security scans per commit. Our findings highlight a growing integration of security tools, particularly API security (63%) and software composition analysis (62%), although container security adoption remains low (34%). Looking ahead, SMEs anticipate artificial intelligence and machine learning to significantly influence DevSecOps, underscoring the need for proactive adoption of AI-driven security enhancements. Based on our findings, this research proposes strategic best practices to enhance CI/CD pipeline security including automation, leadership-driven security culture, and cross-team collaboration. |
| title | Advancing DevSecOps in SMEs: Challenges and Best Practices for Secure CI/CD Pipelines |
| topic | Cryptography and Security Computers and Society Software Engineering D.2.2; K.6.5; D.2.9 |
| url | https://arxiv.org/abs/2503.22612 |