Shifting Security Left in Software Development: "A Systematic Review of Strategies, Challenges, and Tools"
Keywords:
Shift-Left Security, DevSecOps, Secure Software DevelopmentAbstract
With the advent of Agile, DevOps and CI/CD, software systems are becoming more complex and developing faster, making traditional reactive security methods less effective. Many people are familiar with the paradigm of Shift-Left Security, a strategy that seeks to incorporate security activities into the initial stages of the Software Development Lifecycle (SDLC) as opposed to a last check step. A systematic evaluation of 28 peer-reviewed papers from Scopus, IEEE Xplore, ACM Digital Library and other well-known academic databases, this research pulls together some of the existing strategies, barriers, supporting tools, and benefits that have been reported in the field for implementing Shift-Left Security and DevSecOps. Selected studies were grouped into five themes: (1) DevSecOps Adoption and AI Integration, (2) Shift-Left Security Practices, (3) Organizational and Cultural Challenges, (4) Security Requirements Engineering, and (5) Security Automation Tools (SAST, DAST, IAST, SCA).
References
.






