Secure DevSecOps Framework for Cloud Infrastructure Protection

Main Article Content

Kateryna Oblakevych

Abstract

The article is devoted to the development of a secure DevSecOps framework for cloud infrastructure protection. The purpose of the study is to substantiate the author's approach to building such a framework based on the integration of artificial intelligence-based cyber threat detection technologies and data leakage prevention mechanisms. The scientific research used general scientific methods of cognition, in particular analysis, synthesis, generalization, systematization and classification, as well as the Relative Importance Index to assess the priority of the author's development components. The results of the study show that cloud infrastructure protection covers at least six levels of architecture, each of which requires a separate set of control mechanisms, and the classes and models of cloud services form a different distribution of responsibility between the provider and the consumer. Modern security technologies are systematized, covering secure service networks, data categorization in transit, continuous integration pipeline certification, and AI-based vulnerability detection tools. Based on the analysis, a proprietary secure DevSecOps framework is proposed that combines behavioral anomaly assessment, automated SIEM event correlation, built-in secure development controls, project-based data leakage prevention, and cloud infrastructure hardening. An assessment of the framework components by the relative importance index showed that automated SIEM event correlation and behavioral anomaly assessment have the highest priority, while secure development controls, data leakage prevention, and infrastructure hardening play a supporting but necessary role. The practical significance of the research lies in the possibility of using the proposed framework by organizations implementing cloud services to build a holistic system for detecting and preventing cyber threats at all stages of the software development life cycle.

Downloads

Download data is not yet available.

| Abstract views: 8 | PDF Downloads: 3 |

Article Details

How to Cite
Oblakevych, K. (2026). Secure DevSecOps Framework for Cloud Infrastructure Protection. Global Prosperity, 6(3). https://doi.org/10.66556/2787-9364.3-6.oblakevych-k
Section
Articles

References

Boakye, M., Adanu, S. K., Adu-Gyamfi, C., Asare, R. K., Asantewaa-Tannor, P., Ayimah, J. C., & Agbosu, W. K. (2023). A Relative Importance Index Approach to On-Site Building Construction Workers' Perception of Occupational Hazards Assessment. Medycyna Pracy, 114(3), e2023024. DOI: https://doi.org/10.23749/mdl.v114i3.14240

Chandramouli, R. (2022). Implementation of DevSecOps for a Microservices-Based Application with Service Mesh. NIST Special Publication 800-204C. National Institute of Standards and Technology. DOI: 10.6028/NIST.SP.800-204C. URL: https://www.nist.gov/publications/implementation-devsecops-microservices-based-application-service-mesh

Chandramouli, R. (2024). Strategies for the Integration of Software Supply Chain Security in DevSecOps CI/CD Pipelines. NIST Special Publication 800-204D. National Institute of Standards and Technology. URL: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-204D.ipd.pdf

Chandramouli, R., & Hales, W. (2024). A Data Protection Approach for Cloud-Native Applications. NIST Interagency/Internal Report 8505. National Institute of Standards and Technology. DOI: 10.6028/NIST.IR.8505. URL: https://csrc.nist.gov/pubs/ir/8505/final

Erl, T., Puttini, R., & Mahmood, Z. (2013). Cloud Computing: Concepts, Technology & Architecture. Pearson Education. URL: https://ptgmedia.pearsoncmg.com/images/9780133387520/samplepages/0133387526.pdf

Fu, M., Pasuksmit, J., & Tantithamthavorn, C. (2024). AI for DevSecOps: A Landscape and Future Opportunities. arXiv. URL: https://arxiv.org/abs/2404.04839

Hashizume, K., Rosado, D. G., Fernández-Medina, E., & Fernandez, E. B. (2013). An Analysis of Security Issues for Cloud Computing. Journal of Internet Services and Applications, 4(1), 5. URL: https://jisajournal.springeropen.com/articles/10.1186/1869-0238-4-5

Kapoor, R., & Verma, S. (2025). An Exhaustive Analysis of Security Vulnerabilities in Modern Cloud Computing Environments: Taxonomy, Attack Surfaces, and Mitigation Frameworks. European Economic Letters. URL: https://www.eelet.org.uk/index.php/journal/article/view/3401

Liang, X., & Xu, Y. (2025). A Novel Framework to Identify Cybersecurity Challenges and Opportunities for Organizational Digital Transformation in the Cloud. Computers & Security, 151, 104339. DOI: 10.1016/j.cose.2025.104339. URL: https://doi.org/10.1016/j.cose.2025.104339

Mell, P., & Grance, T. (2011). The NIST Definition of Cloud Computing. NIST Special Publication 800-145. National Institute of Standards and Technology. URL: https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-145.pdf

Waseem, M., Liang, P., & Shahin, M. (2020). A Systematic Mapping Study on Microservices Architecture in DevOps. arXiv. URL: https://arxiv.org/abs/2008.07729