{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,25]],"date-time":"2026-07-25T16:15:38Z","timestamp":1784996138457,"version":"3.55.0"},"publisher-location":"Cham","reference-count":45,"publisher":"Springer International Publishing","isbn-type":[{"value":"9783319673820","type":"print"},{"value":"9783319673837","type":"electronic"}],"license":[{"start":{"date-parts":[[2017,1,1]],"date-time":"2017-01-01T00:00:00Z","timestamp":1483228800000},"content-version":"unspecified","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2017]]},"DOI":"10.1007\/978-3-319-67383-7_2","type":"book-chapter","created":{"date-parts":[[2017,9,11]],"date-time":"2017-09-11T19:25:59Z","timestamp":1505157959000},"page":"17-29","source":"Crossref","is-referenced-by-count":138,"title":["DevSecOps: A Multivocal Literature Review"],"prefix":"10.1007","author":[{"given":"H\u00e5vard","family":"Myrbakken","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Ricardo","family":"Colomo-Palacios","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2017,9,9]]},"reference":[{"key":"2_CR1","doi-asserted-by":"crossref","unstructured":"Mell, P.M., Grance, T.: The NIST definition of cloud computing. Special Publications (NIST SP)-800-145, 7 P. NIST Definitions on Cloud Computing, September 2011","DOI":"10.6028\/NIST.SP.800-145"},{"key":"2_CR2","doi-asserted-by":"crossref","first-page":"176","DOI":"10.1016\/j.jss.2015.06.063","volume":"123","author":"B Fitzgerald","year":"2017","unstructured":"Fitzgerald, B., Stol, K.J.: Continuous software engineering: a roadmap and agenda. J. Syst. Softw. 123, 176\u2013189 (2017)","journal-title":"J. Syst. Softw."},{"key":"2_CR3","doi-asserted-by":"crossref","first-page":"21","DOI":"10.1016\/j.infsof.2014.07.009","volume":"57","author":"RB Svensson","year":"2015","unstructured":"Svensson, R.B., Claps, G.G., Aurum, A.: On the journey to continuous deployment: technical and social challenges along the way. Inf. Softw. Technol. 57, 21\u201331 (2015)","journal-title":"Inf. Softw. Technol."},{"key":"2_CR4","first-page":"7","volume":"24","author":"J Humble","year":"2011","unstructured":"Humble, J., Joanne, M.: Why enterprises must adopt devops to enable continuous delivery. J. Inf. Technol. Manage. 24, 7 (2011)","journal-title":"J. Inf. Technol. Manage."},{"issue":"3","key":"2_CR5","doi-asserted-by":"crossref","first-page":"94","DOI":"10.1109\/MS.2016.68","volume":"33","author":"J Hernantes","year":"2016","unstructured":"Hernantes, J., Ebert, C., Gallardo, G., Serrano, N.: Devops. IEEE Softw. 33(3), 94\u2013100 (2016)","journal-title":"IEEE Softw."},{"key":"2_CR6","doi-asserted-by":"crossref","unstructured":"Yankel, J., Cois, C.A., Connell, A.: Modern devops: optimizing software development through effective system interactions. In: 2014 IEEE International Professional Communication Conference (IPCC), pp. 1\u20137, October 2014","DOI":"10.1109\/IPCC.2014.7020388"},{"issue":"3","key":"2_CR7","doi-asserted-by":"crossref","first-page":"53","DOI":"10.1109\/MS.2016.66","volume":"33","author":"M Callanan","year":"2016","unstructured":"Callanan, M., Spillane, A.: Devops: making it easy to do the right thing. IEEE Softw. 33(3), 53\u201359 (2016)","journal-title":"IEEE Softw."},{"issue":"3","key":"2_CR8","doi-asserted-by":"crossref","first-page":"4","DOI":"10.1109\/MS.2016.76","volume":"33","author":"D Spinellis","year":"2016","unstructured":"Spinellis, D.: Being a devops developer. IEEE Softw. 33(3), 4\u20135 (2016)","journal-title":"IEEE Softw."},{"key":"2_CR9","unstructured":"Hewlett Packard Enterprise: Application security and devops. Technical report, Hewlett Packard Enterprise (2016)"},{"key":"2_CR10","unstructured":"MacDonald, N., Head, I.: DevSecOps: How to Seamlessly Integrate Security Into DevOps. Technical report, Gartner (2016)"},{"key":"2_CR11","doi-asserted-by":"crossref","unstructured":"Mohan, V., Othmane, L.B.: Secdevops: is it a marketing buzzword? - mapping research on security in devops. In: 2016 11th International Conference on Availability, Reliability and Security (ARES), pp. 542\u2013547, August 2016","DOI":"10.1109\/ARES.2016.92"},{"key":"2_CR12","doi-asserted-by":"crossref","unstructured":"Ashfaque, A., Rahman, U., Williams, L.: Software security in devops: synthesizing practitioners\u2019 perceptions and practices. In: Proceedings of the International Workshop on Continuous Software Evolution and Delivery, CSED 2016, pp. 70\u201376. ACM, New York (2016)","DOI":"10.1145\/2896941.2896946"},{"key":"2_CR13","doi-asserted-by":"crossref","first-page":"87","DOI":"10.1016\/j.infsof.2017.01.009","volume":"86","author":"M Oivo","year":"2017","unstructured":"Oivo, M., Karvonen, T., Behutiye, W., Kuvaja, P.: Systematic literature review on the impacts of agile release engineering practices. Inf. Softw. Technol. 86, 87\u2013100 (2017)","journal-title":"Inf. Softw. Technol."},{"key":"2_CR14","doi-asserted-by":"crossref","first-page":"263","DOI":"10.1016\/j.jss.2015.12.015","volume":"123","author":"LE Lwakatare","year":"2017","unstructured":"Lwakatare, L.E., Teppola, S., Suomalainen, T., Eskeli, J., Karvonen, T., Kuvaja, P., Verner, J.M., Rodr\u00edguez, P., Haghighatkhah, A., Oivo, M.: Continuous deployment of software intensive products and services: a systematic mapping study. J. Syst. Softw. 123, 263\u2013291 (2017)","journal-title":"J. Syst. Softw."},{"key":"2_CR15","doi-asserted-by":"crossref","first-page":"48","DOI":"10.1016\/j.jss.2013.08.032","volume":"87","author":"D St\u00e5hl","year":"2014","unstructured":"St\u00e5hl, D., Bosch, J.: Modeling continuous integration practice differences in industry software development. J. Syst. Softw. 87, 48\u201359 (2014)","journal-title":"J. Syst. Softw."},{"issue":"3","key":"2_CR16","doi-asserted-by":"crossref","first-page":"265","DOI":"10.3102\/00346543061003265","volume":"61","author":"RT Ogawa","year":"1991","unstructured":"Ogawa, R.T., Malen, B.: Towards rigor in reviews of multivocal literatures: applying the exploratory case study method. Rev. Educ. Res. 61(3), 265\u2013286 (1991)","journal-title":"Rev. Educ. Res."},{"key":"2_CR17","doi-asserted-by":"crossref","first-page":"92","DOI":"10.1016\/j.infsof.2016.04.015","volume":"76","author":"V Garousi","year":"2016","unstructured":"Garousi, V., M\u00e4ntyl\u00e4, M.V.: When and what to automate in software testing? a multi-vocal literature review. Inf. Softw. Technol. 76, 92\u2013117 (2016)","journal-title":"Inf. Softw. Technol."},{"key":"2_CR18","doi-asserted-by":"crossref","unstructured":"Junior, H.J., de Fran\u00e7a, B.B.N., Travassos, G.H.: Characterizing devops by hearing multiple voices. In: Proceedings of the 30th Brazilian Symposium on Software Engineering, SBES 2016, pp. 53\u201362. ACM, New York (2016)","DOI":"10.1145\/2973839.2973845"},{"key":"2_CR19","doi-asserted-by":"crossref","first-page":"16","DOI":"10.1016\/j.infsof.2017.01.001","volume":"85","author":"M Felderer","year":"2017","unstructured":"Felderer, M., Garousi, V., Hacalo\u011flu, T.: Software test maturity assessment and test process improvement: a multivocal literature review. Inf. Softw. Technol. 85, 16\u201342 (2017)","journal-title":"Inf. Softw. Technol."},{"key":"2_CR20","doi-asserted-by":"crossref","unstructured":"Felderer, M., Garousi, V., M\u00e4ntyl\u00e4, M.V.: The need for multivocal literature reviews in software engineering: complementing systematic literature reviews with grey literature. In: Proceedings of the 20th International Conference on Evaluation and Assessment in Software Engineering, EASE 2016, pp. 26:1\u201326:6. ACM, New York (2016)","DOI":"10.1145\/2915970.2916008"},{"key":"2_CR21","unstructured":"Shackleford, D.: A devsecops playbook. SANS Institute InfoSec Reading Room. A DevSecOps Playbook, March 2016"},{"key":"2_CR22","unstructured":"Vonnegut, S.: 4 keys to integrating security into devops (2016), https:\/\/goo.gl\/aZ0S3i"},{"key":"2_CR23","unstructured":"Lietz, S.: Shifting security to the left (2016), https:\/\/goo.gl\/sbheKS"},{"key":"2_CR24","unstructured":"Bledsoe, G.: Getting to devsecops: 5 best practices for integrating security into your devops (2016), https:\/\/goo.gl\/ZPzgxa"},{"key":"2_CR25","unstructured":"Lim, F.: Devsecops is the krav maga of security (2016), https:\/\/goo.gl\/BH4MS2"},{"key":"2_CR26","unstructured":"Lietz, S.: Principles of devsecops (2015), https:\/\/goo.gl\/N8zcXV"},{"key":"2_CR27","unstructured":"Greene, T.: What security teams need to know about devops (2016), https:\/\/goo.gl\/c8VOn4"},{"key":"2_CR28","unstructured":"Anonymous User. Security breaks devops - here\u2019s how to fix it (2015). https:\/\/goo.gl\/Yr1jk3"},{"key":"2_CR29","unstructured":"Shackleford, D.: The devsecops approach to securing your code and your cloud. SANS Institute InfoSec Reading Room A DevSecOps Playbook, February 2017"},{"key":"2_CR30","unstructured":"Caum, C.: Getting started with policy-driven development and devsecops (2016). https:\/\/goo.gl\/AevVcX"},{"key":"2_CR31","unstructured":"Whitehat Security. Devops invites security to \u201cjoin the party\u201d (2016), https:\/\/goo.gl\/spj0wK"},{"key":"2_CR32","unstructured":"Hornbeek, M.: Devops makes security assurance affordable (2015), https:\/\/goo.gl\/g0iKfZ"},{"key":"2_CR33","unstructured":"Lindros, K.: How to craft an effective devsecops process with your team (2016), https:\/\/goo.gl\/ppWtjx"},{"key":"2_CR34","unstructured":"Romeo, C.: The 3 most crucial security behaviors in devsecops (2016), https:\/\/goo.gl\/FJKuYQ"},{"key":"2_CR35","unstructured":"Cureton, A.: Building security into devops: is devsecops the beginning of the future? (2017), https:\/\/goo.gl\/Npv2Py"},{"key":"2_CR36","unstructured":"McKay, J.: How to use devsecops to smooth cloud deployment (2016), https:\/\/goo.gl\/vqoh4L"},{"key":"2_CR37","unstructured":"Amazon Web Services. Introduction to devsecops on AWS (2016), https:\/\/goo.gl\/wxl3YM"},{"key":"2_CR38","unstructured":"Francis, R.: 7 ways devops benefits cisos and their security programs (2015), https:\/\/goo.gl\/RxieGr"},{"key":"2_CR39","unstructured":"Wallgreen, A.: Devsecops: 9 ways devops and automation bolster security, compliance (2015), https:\/\/goo.gl\/RyA9QZ"},{"key":"2_CR40","unstructured":"Rotenberg, M.: 7 essential steps to devsecops success (2016), https:\/\/goo.gl\/JAOQlF"},{"key":"2_CR41","unstructured":"Paul, F.: Secdevops: injecting security into devops processes (2015), https:\/\/goo.gl\/Eul2fn"},{"key":"2_CR42","unstructured":"Rohr, M.: Agile security and secdevops touch points (2015), https:\/\/goo.gl\/peuqpS"},{"key":"2_CR43","unstructured":"Goldschmidt, M., McKinnon, M.: Devsecops - agility with security. Technical report, Sense of Security (2016)"},{"key":"2_CR44","unstructured":"Elder, M.: Security considerations for devops adoption (2014), https:\/\/goo.gl\/b0CStP"},{"key":"2_CR45","doi-asserted-by":"crossref","unstructured":"Clarke, P.M., O\u2019Connor, R.V., Elger, P.: Continuous software engineering\u2013a microservices architecture perspective. J. Softw. Evol. Proc. 2017, e1866 (2017)","DOI":"10.1002\/smr.1866"}],"container-title":["Communications in Computer and Information Science","Software Process Improvement and Capability Determination"],"original-title":[],"link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-319-67383-7_2","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,25]],"date-time":"2025-06-25T17:53:48Z","timestamp":1750874028000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-319-67383-7_2"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2017]]},"ISBN":["9783319673820","9783319673837"],"references-count":45,"URL":"https:\/\/doi.org\/10.1007\/978-3-319-67383-7_2","relation":{},"ISSN":["1865-0929","1865-0937"],"issn-type":[{"value":"1865-0929","type":"print"},{"value":"1865-0937","type":"electronic"}],"subject":[],"published":{"date-parts":[[2017]]}}}