Advancing DevSecOps in SMEs: Challenges and Best Practices for Secure CI/CD Pipelines

Fuente: arXiv
Enregistré dans:
Détails bibliographiques
Auteurs principaux: Cheenepalli, Jayaprakashreddy, Hastings, John D., Ahmed, Khandaker Mamun, Fenner, Chad
Format: Preprint
Publié: 2025
Sujets:
Accès en ligne:
Tags: Ajouter un tag
Pas de tags, Soyez le premier à ajouter un tag!
_version_ 1866918045235019776
author Cheenepalli, Jayaprakashreddy
Hastings, John D.
Ahmed, Khandaker Mamun
Fenner, Chad
author_facet Cheenepalli, Jayaprakashreddy
Hastings, John D.
Ahmed, Khandaker Mamun
Fenner, Chad
contents This study evaluates the adoption of DevSecOps among small and medium-sized enterprises (SMEs), identifying key challenges, best practices, and future trends. Through a mixed methods approach backed by the Technology Acceptance Model (TAM) and Diffusion of Innovations (DOI) theory, we analyzed survey data from 405 SME professionals, revealing that while 68% have implemented DevSecOps, adoption is hindered by technical complexity (41%), resource constraints (35%), and cultural resistance (38%). Despite strong leadership prioritization of security (73%), automation gaps persist, with only 12% of organizations conducting security scans per commit. Our findings highlight a growing integration of security tools, particularly API security (63%) and software composition analysis (62%), although container security adoption remains low (34%). Looking ahead, SMEs anticipate artificial intelligence and machine learning to significantly influence DevSecOps, underscoring the need for proactive adoption of AI-driven security enhancements. Based on our findings, this research proposes strategic best practices to enhance CI/CD pipeline security including automation, leadership-driven security culture, and cross-team collaboration.
format Preprint
id arxiv_https___arxiv_org_abs_2503_22612
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Advancing DevSecOps in SMEs: Challenges and Best Practices for Secure CI/CD Pipelines
Cheenepalli, Jayaprakashreddy
Hastings, John D.
Ahmed, Khandaker Mamun
Fenner, Chad
Cryptography and Security
Computers and Society
Software Engineering
D.2.2; K.6.5; D.2.9
This study evaluates the adoption of DevSecOps among small and medium-sized enterprises (SMEs), identifying key challenges, best practices, and future trends. Through a mixed methods approach backed by the Technology Acceptance Model (TAM) and Diffusion of Innovations (DOI) theory, we analyzed survey data from 405 SME professionals, revealing that while 68% have implemented DevSecOps, adoption is hindered by technical complexity (41%), resource constraints (35%), and cultural resistance (38%). Despite strong leadership prioritization of security (73%), automation gaps persist, with only 12% of organizations conducting security scans per commit. Our findings highlight a growing integration of security tools, particularly API security (63%) and software composition analysis (62%), although container security adoption remains low (34%). Looking ahead, SMEs anticipate artificial intelligence and machine learning to significantly influence DevSecOps, underscoring the need for proactive adoption of AI-driven security enhancements. Based on our findings, this research proposes strategic best practices to enhance CI/CD pipeline security including automation, leadership-driven security culture, and cross-team collaboration.
title Advancing DevSecOps in SMEs: Challenges and Best Practices for Secure CI/CD Pipelines
topic Cryptography and Security
Computers and Society
Software Engineering
D.2.2; K.6.5; D.2.9
url https://arxiv.org/abs/2503.22612