Skip to content
Open access

Secure DevSecOps Framework for Cloud Infrastructure Protection

Jul 2026 · Global Prosperity · 0 citations · 10 references

TL;DR

An assessment of the framework components by the relative importance index showed that automated SIEM event correlation and behavioral anomaly assessment have the highest priority, while secure development controls, data leakage prevention, and infrastructure hardening play a supporting but necessary role.

Abstract

The article is devoted to the development of a secure DevSecOps framework for cloud infrastructure protection. The purpose of the study is to substantiate the author's approach to building such a framework based on the integration of artificial intelligence-based cyber threat detection technologies and data leakage prevention mechanisms. The scientific research used general scientific methods of cognition, in particular analysis, synthesis, generalization, systematization and classification, as well as the Relative Importance Index to assess the priority of the author's development components. The results of the study show that cloud infrastructure protection covers at least six levels of architecture, each of which requires a separate set of control mechanisms, and the classes and models of cloud services form a different distribution of responsibility between the provider and the consumer. Modern security technologies are systematized, covering secure service networks, data categorization in transit, continuous integration pipeline certification, and AI-based vulnerability detection tools. Based on the analysis, a proprietary secure DevSecOps framework is proposed that combines behavioral anomaly assessment, automated SIEM event correlation, built-in secure development controls, project-based data leakage prevention, and cloud infrastructure hardening. An assessment of the framework components by the relative importance index showed that automated SIEM event correlation and behavioral anomaly assessment have the highest priority, while secure development controls, data leakage prevention, and infrastructure hardening play a supporting but necessary role. The practical significance of the research lies in the possibility of using the proposed framework by organizations implementing cloud services to build a holistic system for detecting and preventing cyber threats at all stages of the software development life cycle.

Read PDF

Similar papers

Open access Jul 2026

Cloud-Native Security in Informatics: A Bibliometric Analysis of Emerging Research

Fast development of cloud computing technologies has led to the emergence of cloud-native architecture, which created both new possibilities and challenges in the area of informatics, in particular cybersecurity. Being a set of flexible and scalable cloud-native technologies, such as containers, microservices, Kubernet...

L. Judijanto · 0 citations
Conference Jul 2026

Review of Cyber Threat Detection Techniques in Cloud Computing Environment

Cloud is the essential component for modern computer systems, offering businesses flexible scalability and on-demand resources. However, as attackers use more complex techniques to compromise cloud networks, this technological advancement has ushered in a new era of cybersecurity challenges. Wide-ranging effects, such...

Pradnya Patil, J. Bakal · 0 citations
Review Open access Jul 2026

Penetration Testing in System Security

This review's results show that penetration testing is an important part of improving cybersecurity because it helps identify weaknesses before they become problems and reduces risk.

Shruti Agarwal, S. Sharma · 1 citation
Review Open access 2026

Review of Security-aware Software Engineering Frameworks for Internet of Things

—Internet of Things (IoT) environments are rapidly growing, which in turn has accelerated security threats that are often mitigated by re-activistic deployment-stage controls rather than actively embedded throughout the software development process. Although many other works suggest technical security solutions, little...

Nada Mohammed Hassan Moter · 0 citations
Review Open access Aug 2026

Cloud Security Challenges and Risk Management in Modern Cloud Computing Environment

The study demonstrates that the key factors to achieving effective cloud security are continuous monitoring, robust governance policies, employee awareness training, and high-level cybersecurity frameworks.

Veeramani Sampathkumar, Dinesh Kumar Ramaraj, Rajesh Kotha et al. · 0 citations
Open access 2026

A Theoretical Framework for Evaluating Security Risks in Cloud, Edge and Fog Computing

The spread of the distributed computing paradigms such as cloud, edge, and fog computing has made a difference in current information systems architecture. Although each of these technologies provides incredible scalability, low latency, and a greater level of computational efficiency, they also create intricate multi-...

K. Mulenga, S. Tembo · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.