⚠ Official Notice: www.ijisrt.com is the official website of the International Journal of Innovative Science and Research Technology (IJISRT) Journal for research paper submission and publication. Please beware of fake or duplicate websites using the IJISRT name.



An Adaptive Risk-Driven DevSecOps Framework for Securing Multi-Cloud Enterprise Systems in the Era of Agentic AI


Authors : Nitin Bodade

Volume/Issue : Volume 11 - 2026, Issue 7 - July


Google Scholar : https://tinyurl.com/2v8h5ahc

Scribd : https://tinyurl.com/5er725d9

DOI : https://doi.org/10.38124/ijisrt/26jul136

Note : A published paper may take 4-5 working days from the publication date to appear in PlumX Metrics, Semantic Scholar, and ResearchGate.


Abstract : The rapid adoption of cloud-native architectures, microservices, and continuous delivery pipelines has transformed enterprise software engineering by enabling faster deployment cycles, independent service evolution, and scalable digital delivery. However, these advantages also expand the cybersecurity attack surface across source code repositories, CI/CD pipelines, software supply chains, cloud identities, infrastructure-as-code templates, runtime workloads, and distributed multi-cloud environments. Prior research shows that DevSecOps improves software security by embedding security practices into development and operations workflows, yet organizations continue to face challenges related to toolchain fragmentation, inconsistent risk prioritization, limited automation, and weak integration between security findings and deployment decisions. This paper proposes the Adaptive Risk-Driven DevSecOps Framework (ARDDSF), a layered framework for securing multi-cloud enterprise systems in the era of agentic artificial intelligence. ARDDSF integrates real-time risk scoring, AI-assisted threat modeling, secure CI/CD orchestration, policy-as-code enforcement, Zero Trust-aligned access control, and continuous feedback loops across the software development lifecycle. Unlike static DevSecOps pipelines that treat security findings as isolated scan outputs, ARD-DSF prioritizes vulnerabilities using contextual risk factors such as asset criticality, exploitability, deployment stage, identity exposure, cloud configuration posture, regulatory relevance, and runtime telemetry. The primary contribution of this work is a unified, adaptive, and risk-aware DevSecOps architecture that bridges DevSecOps automation, AI-assisted security analysis, Zero Trust policy enforcement, and multi-cloud governance. The paper provides a formal risk scoring model, implementation workflow, experimental protocol, results templates, and architecture to support future validation in enterprise-scale software delivery environments.

Keywords : DevSecOps; Multi-Cloud Security; Agentic AI; Risk-Based Security; Secure SDLC; Zero Trust; AI-Assisted Threat Modeling; CI/CD Security; Policy-As-Code.

References :

  1. X. Zhou, R. Mao, H. Zhang, Q. Dai, H. Huang, H. Shen, J. Li, and G. Rong, “Revisit security in the era of DevOps: An evidence-based inquiry into DevSecOps industry,” IET Software, vol. 17, no. 4, pp. 435–454, 2023, doi: 10.1049/sfw2.12132.
  2. F. Lombardi and A. Fanton, “From DevOps to DevSecOps is not enough. CyberDevOps: an extreme shifting-left architecture to bring cybersecurity within software security lifecycle pipeline,” Software Quality Journal, vol. 31, no. 2, pp. 619–654, 2023, doi: 10.1007/s11219-023-09619-3.
  3. M. Waseem, P. Liang, and M. Shahin, “A systematic mapping study on Microservices Architecture in DevOps,” Journal of Systems and Software, vol. 170, Article 110798, 2020, doi: 10.1016/j.jss.2020.110798.
  4. P. Di Francesco, P. Lago, and I. Malavolta, “Architecting with microservices: A systematic mapping study,” Journal of Systems and Software, vol. 150, pp. 77–97, 2019, doi: 10.1016/j.jss.2019.01.001.
  5. S. Singh, Y. S. Jeong, and J. H. Park, “A survey on cloud computing security: Issues, threats, and solutions,” Journal of Network and Computer Applications, vol. 75, pp. 200–222, 2016, doi: 10.1016/j.jnca.2016.09.002.
  6. S. Subashini and V. Kavitha, “A survey on security issues in service delivery models of cloud computing,” Journal of Network and Computer Applications, vol. 34, no. 1, pp. 1–11, 2011, doi: 10.1016/j.jnca.2010.07.006.
  7. C. Modi, D. Patel, H. Patel, B. Borisaniya, A. Patel, and M. Rajarajan, “A survey of intrusion detection techniques in Cloud,” Journal of Network and Computer Applications, vol. 36, no. 1, pp. 42–57, 2013, doi: 10.1016/j.jnca.2012.05.003.
  8. Y. Xin et al., “Machine Learning and Deep Learning Methods for Cybersecurity,” IEEE Access, vol. 6, pp. 35365–35381, 2018, doi: 10.1109/ACCESS.2018.2836950.
  9. A. L. Buczak and E. Guven, “A Survey of Data Mining and Machine Learning Methods for Cyber Security Intrusion Detection,” IEEE Communications Surveys & Tutorials, vol. 18, no. 2, pp. 1153–1176, 2016, doi: 10.1109/COMST.2015.2494502.
  10. K. He, D. D. Kim, and M. R. Asghar, “Adversarial Machine Learning for Network Intrusion Detection Systems: A Comprehensive Survey,” IEEE Communications Surveys & Tutorials, vol. 25, no. 1, pp. 538–566, 2023, doi: 10.1109/COMST.2022.3233793.
  11. S. Chakraborty, R. Krishna, Y. Ding, and B. Ray, “Deep Learning Based Vulnerability Detection: Are We There Yet?” IEEE Transactions on Software Engineering, 2021, doi: 10.1109/TSE.2021.3087402.
  12. S. Rose, O. Borchert, S. Mitchell, and S. Connelly, “Zero Trust Architecture,” NIST Special Publication 800-207, 2020, doi: 10.6028/NIST.SP.800-207.
  13. Joint Task Force, “Security and Privacy Controls for Information Systems and Organizations,” NIST Special Publication 800-53 Revision 5, 2020, doi: 10.6028/NIST.SP.800-53r5.
  14. OWASP Foundation, “OWASP Top 10:2021,” 2021. Available: https://owasp.org/Top10/2021/.
  15. J. Humble and D. Farley, Continuous Delivery: Reliable Software Releases through Build, Test, and Deployment Automation. Addison-Wesley, 2010. ISBN: 9780321601919.

The rapid adoption of cloud-native architectures, microservices, and continuous delivery pipelines has transformed enterprise software engineering by enabling faster deployment cycles, independent service evolution, and scalable digital delivery. However, these advantages also expand the cybersecurity attack surface across source code repositories, CI/CD pipelines, software supply chains, cloud identities, infrastructure-as-code templates, runtime workloads, and distributed multi-cloud environments. Prior research shows that DevSecOps improves software security by embedding security practices into development and operations workflows, yet organizations continue to face challenges related to toolchain fragmentation, inconsistent risk prioritization, limited automation, and weak integration between security findings and deployment decisions. This paper proposes the Adaptive Risk-Driven DevSecOps Framework (ARDDSF), a layered framework for securing multi-cloud enterprise systems in the era of agentic artificial intelligence. ARDDSF integrates real-time risk scoring, AI-assisted threat modeling, secure CI/CD orchestration, policy-as-code enforcement, Zero Trust-aligned access control, and continuous feedback loops across the software development lifecycle. Unlike static DevSecOps pipelines that treat security findings as isolated scan outputs, ARD-DSF prioritizes vulnerabilities using contextual risk factors such as asset criticality, exploitability, deployment stage, identity exposure, cloud configuration posture, regulatory relevance, and runtime telemetry. The primary contribution of this work is a unified, adaptive, and risk-aware DevSecOps architecture that bridges DevSecOps automation, AI-assisted security analysis, Zero Trust policy enforcement, and multi-cloud governance. The paper provides a formal risk scoring model, implementation workflow, experimental protocol, results templates, and architecture to support future validation in enterprise-scale software delivery environments.

Keywords : DevSecOps; Multi-Cloud Security; Agentic AI; Risk-Based Security; Secure SDLC; Zero Trust; AI-Assisted Threat Modeling; CI/CD Security; Policy-As-Code.

Paper Submission Last Date
31 - July - 2026

SUBMIT YOUR PAPER CALL FOR PAPERS
Video Explanation for Published paper

Never miss an update from Papermashup

Get notified about the latest tutorials and downloads.

Subscribe by Email

Get alerts directly into your inbox after each post and stay updated.
Subscribe
OR

Subscribe by RSS

Add our RSS to your feedreader to get regular updates from us.
Subscribe