Author

Nitin Bodade

1 paper indexed here

Fetches their full publication history.

Not the right person? Other researchers publish under this name.

Open access Jul 2026

An Adaptive Risk-Driven DevSecOps Framework for Securing Multi-Cloud Enterprise Systems in the Era of Agentic AI

The rapid adoption of cloud-native architectures, microservices, and continuous delivery pipelines has transformed enterprise software engineering by enabling faster deployment cycles, independent service evolution, and scalable digital delivery. However, these advantages also expand the cybersecurity attack surface across source code repositories, CI/CD pipelines, software supply chains, cloud identities, infrastructure-as-code templates, runtime workloads, and distributed multi-cloud environments. Prior research shows that DevSecOps improves software security by embedding security practices into development and operations workflows, yet organizations continue to face challenges related to toolchain fragmentation, inconsistent risk prioritization, limited automation, and weak integration between security findings and deployment decisions. This paper proposes the Adaptive Risk-Driven DevSecOps Framework (ARDDSF), a layered framework for securing multi-cloud enterprise systems in the era of agentic artificial intelligence. ARDDSF integrates real-time risk scoring, AI-assisted threat modeling, secure CI/CD orchestration, policy-as-code enforcement, Zero Trust-aligned access control, and continuous feedback loops across the software development lifecycle. Unlike static DevSecOps pipelines that treat security findings as isolated scan outputs, ARD-DSF prioritizes vulnerabilities using contextual risk factors such as asset criticality, exploitability, deployment stage, identity exposure, cloud configuration posture, regulatory relevance, and runtime telemetry. The primary contribution of this work is a unified, adaptive, and risk-aware DevSecOps architecture that bridges DevSecOps automation, AI-assisted security analysis, Zero Trust policy enforcement, and multi-cloud governance. The paper provides a formal risk scoring model, implementation workflow, experimental protocol, results templates, and architecture to support future validation in enterprise-scale software delivery environments.

Nitin Bodade · 0 citations