{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,30]],"date-time":"2026-05-30T02:09:29Z","timestamp":1780106969031,"version":"3.54.0"},"publisher-location":"New York, NY, USA","reference-count":20,"publisher":"ACM","license":[{"start":{"date-parts":[[2020,6,27]],"date-time":"2020-06-27T00:00:00Z","timestamp":1593216000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2020,6,27]]},"DOI":"10.1145\/3387940.3392233","type":"proceedings-article","created":{"date-parts":[[2020,9,25]],"date-time":"2020-09-25T15:22:31Z","timestamp":1601047351000},"page":"266-269","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":55,"title":["Security as Culture"],"prefix":"10.1145","author":[{"given":"Mary","family":"S\u00e1nchez-Gord\u00f3n","sequence":"first","affiliation":[{"name":"Department of Computer Sciences, \u00d8stfold University College, Halden, Norway"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Ricardo","family":"Colomo-Palacios","sequence":"additional","affiliation":[{"name":"Department of Computer Sciences, \u00d8stfold University College, Halden, Norway"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2020,9,25]]},"reference":[{"key":"e_1_3_2_1_1_1","volume-title":"Andrew King, Vidyababu Kuppusamy, and Mano Malayanur.","author":"Brunelle Justin F","year":"2018"},{"key":"e_1_3_2_1_2_1","unstructured":"Justin F Brunelle Cameron Boozarjomehri David Hansen Christine Kim R Scott Paul Quang Nguyen Rock Sabetto Gavin Schmidt Mari Spina Joseph Walter Katy Warren Adam Yee and Tom Suder. 2019. Federal Cloud & Infrastructure Summit Report. The MITRE Corporation. Retrieved from https:\/\/atarc.org\/wp-content\/uploads\/2019\/08\/Cloud-White-Paper-Cover-Letter-merged.pdf  Justin F Brunelle Cameron Boozarjomehri David Hansen Christine Kim R Scott Paul Quang Nguyen Rock Sabetto Gavin Schmidt Mari Spina Joseph Walter Katy Warren Adam Yee and Tom Suder. 2019. Federal Cloud & Infrastructure Summit Report. The MITRE Corporation. Retrieved from https:\/\/atarc.org\/wp-content\/uploads\/2019\/08\/Cloud-White-Paper-Cover-Letter-merged.pdf"},{"key":"e_1_3_2_1_3_1","doi-asserted-by":"publisher","DOI":"10.1109\/MS.2017.3571578"},{"key":"e_1_3_2_1_4_1","doi-asserted-by":"crossref","unstructured":"Sara Carturan and Denise Goya. 2019. Major Challenges of Systems-of-Systems with Cloud and DevOps -- A Financial Experience Report. In 2019 IEEE\/ACM 7th International Workshop on Software Engineering for Systems-of-Systems and 13th Workshop on Distributed Software Development Software Ecosystems and Systems-of-Systems Montreal QC Canada 10--17. DOI:https:\/\/doi.org\/10.1109\/SESoS\/WDES.2019.00010  Sara Carturan and Denise Goya. 2019. Major Challenges of Systems-of-Systems with Cloud and DevOps -- A Financial Experience Report. In 2019 IEEE\/ACM 7th International Workshop on Software Engineering for Systems-of-Systems and 13th Workshop on Distributed Software Development Software Ecosystems and Systems-of-Systems Montreal QC Canada 10--17. DOI:https:\/\/doi.org\/10.1109\/SESoS\/WDES.2019.00010","DOI":"10.1109\/SESoS\/WDES.2019.00010"},{"key":"e_1_3_2_1_5_1","volume-title":"Jennifer Flamm, Seth Goldrich, Diane Hanf, Michael Kristan, Justin F Brunelle, Tim Harvey, and Tom Suder.","author":"Casagni Michelle","year":"2018"},{"key":"e_1_3_2_1_6_1","unstructured":"Rebecca Deck. 2019. Adapting AppSec to a DevOps World. Retrieved from https:\/\/pdfs.semanticscholar.org\/74c3\/ce0f45a4624b9a0d67051d8ea305c3b8be78.pdf  Rebecca Deck. 2019. Adapting AppSec to a DevOps World. Retrieved from https:\/\/pdfs.semanticscholar.org\/74c3\/ce0f45a4624b9a0d67051d8ea305c3b8be78.pdf"},{"key":"e_1_3_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-1-4842-3612-3"},{"key":"e_1_3_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1109\/TechDebt.2019.00012"},{"key":"e_1_3_2_1_9_1","volume-title":"The DevOps Handbook: How to create world-class agility, reliability, & security in technology organizations","author":"Kim Gene"},{"key":"e_1_3_2_1_10_1","unstructured":"Barbara Kitchenham and S. Charters. 2007. Guidelines for performing Systematic Literature Reviews in Software Engineering. School of Computer Science and Mathematics Keele University.  Barbara Kitchenham and S. Charters. 2007. Guidelines for performing Systematic Literature Reviews in Software Engineering. School of Computer Science and Mathematics Keele University."},{"key":"e_1_3_2_1_11_1","unstructured":"Andi Mann Michael Stahnke Alanna Brow and Nigel Kersten. 2019. 2019 State of DevOps Report. PuppetLabs. CircleCI and Splunk. Retrieved from https:\/\/puppet.com\/resources\/report\/state-of-devops-report\/  Andi Mann Michael Stahnke Alanna Brow and Nigel Kersten. 2019. 2019 State of DevOps Report. PuppetLabs. CircleCI and Splunk. Retrieved from https:\/\/puppet.com\/resources\/report\/state-of-devops-report\/"},{"key":"e_1_3_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1016\/S1353-4858(18)30070-9"},{"key":"e_1_3_2_1_13_1","first-page":"5","article-title":"Silver Bullet Talks with Tanya Janca","volume":"16","author":"McGraw Gary","year":"2018","journal-title":"IEEE Secur. Priv."},{"key":"e_1_3_2_1_14_1","volume-title":"DevSecOps: A Multivocal Literature Review. In International Conference on Software Process Improvement and Capability Determination, Springer, 17--29","author":"Myrbakken Havard","year":"2017"},{"key":"e_1_3_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.1145\/3349266.3351420"},{"key":"e_1_3_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICTER.2017.8257807"},{"key":"e_1_3_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1145\/2896941.2896946"},{"key":"e_1_3_2_1_18_1","volume-title":"Software Process Improvement and Capability Determination (Communications in Computer and Information Science)","author":"S\u00e1nchez-Gord\u00f3n Mary"},{"key":"e_1_3_2_1_19_1","volume-title":"The DevOps Adoption Playbook: A Guide to Adopting DevOps in a Multi-Speed IT Enterprise | Wiley","author":"Sharma Sanjeev","year":"2020"},{"key":"e_1_3_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1109\/CyberSecPODS.2019.8884935"}],"event":{"name":"ICSE '20: 42nd International Conference on Software Engineering","location":"Seoul Republic of Korea","acronym":"ICSE '20","sponsor":["SIGSOFT ACM Special Interest Group on Software Engineering","KIISE Korean Institute of Information Scientists and Engineers","IEEE CS"]},"container-title":["Proceedings of the IEEE\/ACM 42nd International Conference on Software Engineering Workshops"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3387940.3392233","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3387940.3392233","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T22:38:47Z","timestamp":1750199927000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3387940.3392233"}},"subtitle":["A Systematic Literature Review of DevSecOps"],"short-title":[],"issued":{"date-parts":[[2020,6,27]]},"references-count":20,"alternative-id":["10.1145\/3387940.3392233","10.1145\/3387940"],"URL":"https:\/\/doi.org\/10.1145\/3387940.3392233","relation":{},"subject":[],"published":{"date-parts":[[2020,6,27]]},"assertion":[{"value":"2020-09-25","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}