2021/07/05 by Roshan Namal Rajapakse, Rajapakse, Roshan Namal, Mansooreh Zahedi +3
Computer Science · #Cryptography and Security (cs.CR) #FOS: Computer and information sciences #Software Engineering (cs.SE) #Software Engineering Techniques and Practices
paper · pdf · doi:10.48550/arxiv.2107.02096
openalex publication_date 2021/07/05 · openalex created_date 2022/07/25 · openalex updated_date 2026/07/28
Background: Security tools play a vital role in enabling developers to build\nsecure software. However, it can be quite challenging to introduce and fully\nleverage security tools without affecting the speed or frequency of deployments\nin the DevOps paradigm. Aims: We aim to empirically investigate the key\nchallenges practitioners face when integrating security tools into a DevOps\nworkflow in order to provide recommendations to overcome them. Method: We\nconducted a study involving 31 systematically selected webinars on integrating\nsecurity tools in DevOps. We used a qualitative data analysis method, i.e.,\nthematic analysis, to identify the challenges and emerging solutions related to\nintegrating security tools in rapid deployment environments. Results: We find\nthat while traditional security tools are unable to cater for the needs of\nDevOps, the industry is moving towards new generations of tools that have\nstarted focusing on these requirements. We have developed a DevOps workflow\nthat integrates security tools and a set of guidelines by synthesizing\npractitioners' recommendations in the analyzed webinars. Conclusion: While the\nlatest security tools are addressing some of the requirements of DevOps, there\nare many tool-related drawbacks yet to be adequately addressed.\n