首页> 外文期刊>Computers & Security >Modeling continuous security: A conceptual model for automated DevSecOps using open-source software over cloud (ADOC)
【24h】

Modeling continuous security: A conceptual model for automated DevSecOps using open-source software over cloud (ADOC)

机译:建模连续安全性:使用云(ADOC)使用开源软件的自动Devsecops的概念模型

获取原文
获取原文并翻译 | 示例

摘要

Agile software development methodology and DevOps, together, have helped the business to achieve agility and velocity in delivering time-to-market applications and services. Open-source software (OSS) and cloud technologies are taking up business innovation and DevOps at new heights. However, in the quest of agility and velocity, user data security and privacy assurance often get lower priority as they are perceived as a time-consuming activity requiring specialized people, process, and technology. We see this problem being addressed by integrating security in DevOps processes. Security for DevOps has been institutionalized as DevSecOps with practical considerations for a given business context. In this work, we proposed a conceptual security model, ADOC, to facilitate adopting DevSecOps for the business processes capitalizing OSS over the cloud. This work contributes towards the following to integrate continuous security in application and service delivery: (ⅰ) A continuous security conceptual framework proposal based on the requirements elicited from the analysis of challenges in adopting DevSecOps using OSS over the cloud. (ⅱ) An integrationist security model, ADOC, based on the proposed continuous security conceptual framework, integrating development, security, and operation activities through automation of security controls using OSS over the cloud. (ⅲ) A set of inter-working OSS tools for automation of the proposed security controls in ADOC workflow and practices. (ⅳ) A set of metrics for performance measurement of the ADOC model. (v) Mapping of the solutions for the analyzed challenges using the proposed security controls, followed by a use case scenario to adopt the ADOC workflow and continuous practices. The ADOC transforms security being adhoc compliance-oriented activities into continuous assurance-oriented activities by codifying security controls into an automated delivery workflow. Its practical adoption enables businesses to deliver time-to-market security ready applications and services with accelerated velocity and sustainable agility in a cost-effective way.
机译:敏捷软件开发方法和DEVOPS,一起帮助业务实现了在提供市场上的应用和服务时实现灵活性和速度。开源软件(OSS)和云技术正在开展业务创新和销售新的高度。然而,在寻求敏捷和速度的情况下,用户数据安全和隐私保证通常会得到较低的优先级,因为它们被认为是需要专门的人,过程和技术的耗时的活动。通过在Devops进程中集成安全性,我们会看到此问题正在解决。 Devops的安全被制度化为DevSecops,具有对给定业务环境的实际考虑因素。在这项工作中,我们提出了一个概念安全模型,ADOC,以便于对商业流程的采用DevSecops将OSS放在云上。这项工作有助于实现申请和服务交付中的持续安全性:(Ⅰ)一个连续的安全概念框架提案,基于在云上使用OSS采用Devsecops的挑战来分析挑战的要求。 (Ⅱ)基于建议的连续安全概念框架,通过在云上使用OSS的安全控制自动化,基于拟议的连续安全概念框架,集成开发,安全性和操作活动的集成安全模型。 (三)A ADOC工作流程和实践中提出的安全控制自动化的一套工作室间OSS工具。 (ⅳ)ADOC模型性能测量的一组指标。 (v)利用所提出的安全控件对分析的挑战的映射,然后是使用ADOC工作流程和持续做法的用例方案。 ADOC通过将安全控件编纂到自动交付工作流程,将adhoc符合要求的活动转换为adhoc符合要求的活动。它的实际采用使企业能够以成本效益的方式提供市场上市的速度和可持续灵活性的时间。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号