On DevSecOps and Risk Management in Critical Infrastructures: Practitioners´Insights on Needs and Goals
Xhesika Ramaj1, Mary Sanchez-Gordon1, Vasileios Gkioulos2, Ricardo Colomo-Palacios3. 1: Østfold University College, Norway; 2: Norwegian University of Science and Technology, Norway; 3: Universidad Politécnica de Madrid, Spain.
Abstract:
Risk management is essential for ensuring the sustained viability of organizations over the long term. It plays a pivotal role in business by helping to identify potential threats and vulnerabilities, thereby enabling well-informed decision-making. Within the context of critical infrastructures, it takes on even greater significance. DevSecOps is an innovative approach to bolstering security of software applications. This approach is being heralded as a transformative solution that encourages the adoption of robust security practices, reduces risk, and ensures uninterrupted business continuity. This study conducts a qualitative approach to unveil the needs and goals of implementing DevSecOps in critical infrastructures from the perspective of DevOps, developers, and security experts. Findings show that the relevance of DevSecOps in critical infrastructures emerges from the need for proactive work, increased efficiency, automation, monitoring mechanisms, security, and outstanding products and services. Findings also identify the goals for establishing a stronger market presence, increasing revenues, and maintaining a leading position in the market. The study contributes to the existing DevSecOps literature by providing insights on DevSevOps in risk management in critical infrastructures. This can potentially encourage the adoption of DevSecOps and guide practitioners interested in leveraging the inherent benefits of this approach in the context of critical infrastructures.
Mon 15 AprDisplayed time zone: Lisbon change
14:00 - 15:30 | Training, knowledge and Industrial challengesEnCyCriS/SVM at Amadeo de Souza-Cardoso Chair(s): John Eidar Simensen IFE | ||
14:00 20mFull-paper | Building a Cybersecurity Knowledge Graph with CyberGraph EnCyCriS/SVM A: Paolo Falcarin Ca' Foscari University of Venice, A: Fabio Dainese Ca' Foscari University of Venice | ||
14:20 20mFull-paper | Training Developers to Code Securely: Theory and Practice EnCyCriS/SVM A: Ita Ryan University College Cork, A: Utz Roedig University College Cork, A: Klaas-Jan Stol Lero; University College Cork; SINTEF Digital | ||
14:40 20mFull-paper | On DevSecOps and Risk Management in Critical Infrastructures: Practitioners´Insights on Needs and Goals EnCyCriS/SVM A: Xhesika Ramaj Østfold University College (HiØ) / Norwegian University of Science and Technology (NTNU), A: Mary Sánchez-Gordón Østfold University College, A: Vasileios Gkioulos NTNU, A: Ricardo Colomo-Palacios Universidad Politécnica de Madrid | ||
15:00 20mFull-paper | Cyber-incident Response in Industrial Control Systems: Practices and Challenges in the Petroleum Industry EnCyCriS/SVM A: Vahiny Gnanasekaran Norwegian University of Science and Technology NTNU, A: Maria Bartnes Norwegian University of Science and Technology NTNU, A: Tor Olav Grøtan SINTEF Digital, Poul Einar Heegaard Norwegian University of Science and Technology NTNU |