{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,24]],"date-time":"2026-07-24T14:59:46Z","timestamp":1784905186628,"version":"3.55.0"},"publisher-location":"New York, NY, USA","reference-count":36,"publisher":"ACM","license":[{"start":{"date-parts":[[2024,6,18]],"date-time":"2024-06-18T00:00:00Z","timestamp":1718668800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2024,6,18]]},"DOI":"10.1145\/3661167.3661238","type":"proceedings-article","created":{"date-parts":[[2024,6,14]],"date-time":"2024-06-14T12:24:25Z","timestamp":1718367865000},"page":"528-533","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":5,"title":["Towards People Maturity for Secure Development and Operations: A vision"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-4906-6495","authenticated-orcid":false,"given":"Muhammad Azeem","family":"Akbar","sequence":"first","affiliation":[{"name":"Software Engineering, LUT University, Finland"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-9807-6235","authenticated-orcid":false,"given":"Saima","family":"Rafi","sequence":"additional","affiliation":[{"name":"School of Computing , Engineering and the Built Environment Edinburgh Napier University Edinburgh, United Kingdom"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-5073-3750","authenticated-orcid":false,"given":"Sami","family":"Hyrynsalmi","sequence":"additional","affiliation":[{"name":"Department Software Engineering, LUT University, Finland"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8479-1481","authenticated-orcid":false,"given":"Arif Ali","family":"Khan","sequence":"additional","affiliation":[{"name":"M3S Empirical Software Engineering Research Unit, University of Oulu, Finland"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2024,6,18]]},"reference":[{"key":"e_1_3_2_1_1_1","doi-asserted-by":"crossref","unstructured":"Leite L. Rocha C. Kon F. Milojicic D. and Meirelles P. 2019. A survey of DevOps concepts and challenges.\u00a0ACM Computing Surveys (CSUR) \u00a052(6) pp.1-35.","DOI":"10.1145\/3359981"},{"key":"e_1_3_2_1_2_1","doi-asserted-by":"crossref","unstructured":"Erich FMA Amrit C Daneva M. A qualitative study of DevOps usage in practice. J Softw Evol Process. 2017;29(6):1-20:e1885.","DOI":"10.1002\/smr.1885"},{"key":"e_1_3_2_1_3_1","volume-title":"Continuously deploying culture: scaling culture at Etsy. Retrieved","author":"Rembetsy M","year":"2019","unstructured":"Rembetsy M, McDonnell P. Continuously deploying culture: scaling culture at Etsy. Retrieved September 9, 2019. http:\/\/www.slideshare.net\/ mcdonnps\/continuously-deploying-culturescaling-culture-at-etsy-14588485 2012. 2019"},{"key":"e_1_3_2_1_4_1","volume-title":"Hats off to DevSecOps. In\u00a0Enigma 2018 (Enigma","author":"Lietz S.","year":"2018","unstructured":"Lietz, S., 2018. Hats off to DevSecOps. In\u00a0Enigma 2018 (Enigma 2018)."},{"key":"e_1_3_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.1109\/ISSREW.2018.00013"},{"key":"e_1_3_2_1_6_1","volume-title":"In\u00a0European Conference on Software Process Improvement\u00a0(pp. 453-464)","author":"Larrucea X.","unstructured":"Larrucea, X., Berreteaga, A. and Santamaria, I., 2019, September. Dealing with security in a real DevOps environment. In\u00a0European Conference on Software Process Improvement\u00a0(pp. 453-464). Springer, Cham."},{"key":"e_1_3_2_1_7_1","volume-title":"In\u00a0International Conference on Human-Computer Interaction\u00a0(pp. 217-229)","author":"Al-Darwish A.I.","unstructured":"Al-Darwish, A.I. and Choe, P., 2019, July. A framework of information security integrated with human factors. In\u00a0International Conference on Human-Computer Interaction\u00a0(pp. 217-229). Springer, Cham."},{"key":"e_1_3_2_1_8_1","volume-title":"Security: Human Nature and Behaviour. In\u00a0Building a Cybersecurity Culture in Organizations\u00a0(pp. 23-47)","author":"Corradini I.","year":"2020","unstructured":"Corradini, I., 2020. Security: Human Nature and Behaviour. In\u00a0Building a Cybersecurity Culture in Organizations\u00a0(pp. 23-47). Springer, Cham."},{"key":"e_1_3_2_1_9_1","doi-asserted-by":"crossref","unstructured":"Houston N. 2019. The Impact of Human Behavior on Cyber Security. In\u00a0Multigenerational Online Behavior and Media Use: Concepts Methodologies Tools and Applications\u00a0(pp. 1245-1266). IGI Global.","DOI":"10.4018\/978-1-5225-7909-0.ch068"},{"key":"e_1_3_2_1_10_1","volume-title":"The Human Factor in IT Security: How Employees are Making Businesses Vulnerable from Within","author":"Kaspersky","year":"2017","unstructured":"Kaspersky-blog. The Human Factor in IT Security: How Employees are Making Businesses Vulnerable from Within, 2017, https:\/\/www.kaspersky.com\/blog\/the-human-factor-in-it-security\/"},{"key":"e_1_3_2_1_11_1","doi-asserted-by":"crossref","unstructured":"Williams L. McGraw G. and Migues S. 2018. Engineering security vulnerability prevention detection and response.\u00a0IEEE Software \u00a035(5) pp.76-80.","DOI":"10.1109\/MS.2018.290110854"},{"key":"e_1_3_2_1_12_1","volume-title":"Data Breaches Compromised 4.5 Billion Records in First Half of 2018","author":"Mezak","year":"2018","unstructured":"S. Mezak, \u201cData Breaches Compromised 4.5 Billion Records in First Half of 2018,\u201d, 2018, https:\/\/www.sttinfo.fi\/tiedote\/databreaches-compromised-45-billion-records-in-first-half-of2018?publisherId=58763726releaseId=69844038."},{"key":"e_1_3_2_1_13_1","unstructured":"SelfKey-Blog Data Breaches in 2019 - 2021 - An Alarming Timeline https:\/\/selfkey.org."},{"key":"e_1_3_2_1_14_1","volume-title":"In\u00a02019 International Conference on Cyber Security and Protection of Digital Services (Cyber Security)\u00a0(pp. 1-8). IEEE.","author":"Tomas N.","year":"2019","unstructured":"Tomas, N., Li, J., & Huang, H. (2019, June). An empirical study on culture, automation, measurement, and sharing of devsecops. In\u00a02019 International Conference on Cyber Security and Protection of Digital Services (Cyber Security)\u00a0(pp. 1-8). IEEE."},{"key":"e_1_3_2_1_15_1","volume-title":"In\u00a0Proceedings of the IEEE\/ACM 42nd International Conference on Software Engineering Workshops\u00a0(pp. 266-269)","author":"S\u00e1nchez-Gord\u00f3n M.","unstructured":"S\u00e1nchez-Gord\u00f3n, M. and Colomo-Palacios, R., 2020, June. Security as Culture: A Systematic Literature Review of DevSecOps. In\u00a0Proceedings of the IEEE\/ACM 42nd International Conference on Software Engineering Workshops\u00a0(pp. 266-269)."},{"key":"e_1_3_2_1_16_1","volume-title":"November. Integrating Security with DevSecOps: Techniques and Challenges. In\u00a02019 International Conference on Digitization (ICD)\u00a0(pp. 178-182)","author":"Ahmed Z.","unstructured":"Ahmed, Z. and Francis, S.C., 2019, November. Integrating Security with DevSecOps: Techniques and Challenges. In\u00a02019 International Conference on Digitization (ICD)\u00a0(pp. 178-182). IEEE."},{"key":"e_1_3_2_1_17_1","volume-title":"In\u00a02016 11th international conference on availability, reliability and security (ARES)\u00a0(pp. 542-547)","author":"Mohan V.","unstructured":"Mohan, V. and Othmane, L.B., 2016, August. Secdevops: Is it a marketing buzzword?-mapping research on security in devops. In\u00a02016 11th international conference on availability, reliability and security (ARES)\u00a0(pp. 542-547). IEEE."},{"key":"e_1_3_2_1_18_1","volume-title":"In\u00a0International Conference on Software Process Improvement and Capability Determination\u00a0(pp. 17-29)","author":"Myrbakken H.","unstructured":"Myrbakken, H. and Colomo-Palacios, R., 2017, October. DevSecOps: a multivocal literature review. In\u00a0International Conference on Software Process Improvement and Capability Determination\u00a0(pp. 17-29). Springer, Cham."},{"key":"e_1_3_2_1_19_1","volume-title":"In\u00a02020 IEEE 20th International Conference on Software Quality, Reliability and Security (QRS)\u00a0(pp. 450-457)","author":"Mao R.","unstructured":"Mao, R., Zhang, H., Dai, Q., Huang, H., Rong, G., Shen, H., Chen, L. and Lu, K., 2020, December. Preliminary findings about devsecops from grey literature. In\u00a02020 IEEE 20th International Conference on Software Quality, Reliability and Security (QRS)\u00a0(pp. 450-457). IEEE."},{"key":"e_1_3_2_1_20_1","volume-title":"In\u00a02016 IEEE\/ACM International Workshop on Continuous Software Evolution and Delivery (CSED)\u00a0(pp. 70-76)","author":"Rahman A.A.U.","unstructured":"Rahman, A.A.U. and Williams, L., 2016, May. Software security in devops: Synthesizing practitioners\u2019 perceptions and practices. In\u00a02016 IEEE\/ACM International Workshop on Continuous Software Evolution and Delivery (CSED)\u00a0(pp. 70-76). IEEE."},{"key":"e_1_3_2_1_21_1","volume-title":"In\u00a0European Conference on Software Process Improvement\u00a0(pp. 453-464)","author":"Larrucea X.","unstructured":"Larrucea, X., Berreteaga, A. and Santamaria, I., 2019, September. Dealing with security in a real DevOps environment. In\u00a0European Conference on Software Process Improvement\u00a0(pp. 453-464). Springer, Cham."},{"key":"e_1_3_2_1_22_1","volume-title":"Challenges and solutions when adopting DevSecOps: A systematic review.\u00a0arXiv preprint arXiv:2103.08266","author":"Rajapakse R. N.","year":"2021","unstructured":"Rajapakse, R. N., Zahedi, M., Babar, M. A., & Shen, H. (2021). Challenges and solutions when adopting DevSecOps: A systematic review.\u00a0arXiv preprint arXiv:2103.08266."},{"key":"e_1_3_2_1_23_1","volume-title":"In\u00a0Proceedings of the 14th ACM\/IEEE International Symposium on empirical software engineering and measurement (ESEM)\u00a0(pp. 1-11)","author":"Lie M.F.","unstructured":"Lie, M.F., S\u00e1nchez-Gord\u00f3n, M. and Colomo-Palacios, R., 2020, October. DevOps in an ISO 13485 regulated environment: A multivocal literature review. In\u00a0Proceedings of the 14th ACM\/IEEE International Symposium on empirical software engineering and measurement (ESEM)\u00a0(pp. 1-11)."},{"key":"e_1_3_2_1_24_1","doi-asserted-by":"crossref","unstructured":"Hidellaarachchi D. Grundy J. Hoda R. and Madampe K. 2021. The Effects of Human Aspects on the Requirements Engineering Process: A Systematic Literature Review.\u00a0IEEE Transactions on Software Engineering.","DOI":"10.1109\/TSE.2021.3051898"},{"key":"e_1_3_2_1_25_1","volume-title":"June 6-10","author":"OWASP","year":"2022","unstructured":"OWASP, Devsecops Maturity Model, June 6-10, 2022. https:\/\/dsomm.timo-pagel.de."},{"key":"e_1_3_2_1_26_1","doi-asserted-by":"crossref","unstructured":"Kumar R. and Goyal R. 2020. Modeling continuous security: A conceptual model for automated DevSecOps using open-source software over cloud (ADOC).\u00a0Computers & Security \u00a097 p.101967.","DOI":"10.1016\/j.cose.2020.101967"},{"key":"e_1_3_2_1_27_1","volume-title":"May 17, 2021. https:\/\/tinyurl.com\/wbtbahvx.","author":"Do D","unstructured":"DoD Publishes DevSecOps 2.0 Docs For Accelerating Apps, May 17, 2021. https:\/\/tinyurl.com\/wbtbahvx."},{"key":"e_1_3_2_1_28_1","volume-title":"OWASP AppSec Europe, (Amsterdam","author":"Schneider","year":"2015","unstructured":"C. Schneider, \u201cSecurity DevOps - staying secure in agile projects,\u201d in OWASP AppSec Europe, (Amsterdam, Netherlands), 2015."},{"key":"e_1_3_2_1_29_1","unstructured":"CMMI Product Team. \u201cCMMI for Development. Technical Report CMU\/SEI-2010-TR-032 Software Engineering Institute Carnegie Mellon University Pittsburgh Pennsylvania 2010."},{"key":"e_1_3_2_1_30_1","doi-asserted-by":"crossref","unstructured":"Curtis B. Hefley B. and Miller S. 2009.\u00a0People capability maturity model (P-CMM) version 2.0. CARNEGIE-MELLON UNIV PITTSBURGH PA SOFTWARE ENGINEERING INST.","DOI":"10.21236\/ADA512354"},{"key":"e_1_3_2_1_31_1","first-page":"2007","article-title":"Guidelines for performing systematic literature reviews in software engineering. Technical report","volume":"2","author":"Kitchenham B.","unstructured":"Kitchenham, B. and Charters, S. Guidelines for performing systematic literature reviews in software engineering. Technical report, Ver.2.2, EBSE-TR-2007-01.","journal-title":"Ver.2"},{"key":"e_1_3_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.infsof.2018.09.006"},{"key":"e_1_3_2_1_33_1","first-page":"532","volume-title":"Building theories from case study research.\u00a0Academy of management review,\u00a014(4)","author":"Eisenhardt K.M.","unstructured":"Eisenhardt, K.M., 1989. Building theories from case study research.\u00a0Academy of management review,\u00a014(4), pp.532-550."},{"key":"e_1_3_2_1_34_1","unstructured":"S. U. Khan \"Software outsourcing vendors' readiness model (SOVRM) \" Keele University 2011."},{"key":"e_1_3_2_1_35_1","unstructured":"M. K. Niazi \u2018\u2018A framework for assisting the design of effective implementation strategies for software process improvement \u2019\u2019 Ph.D. dissertation Faculty Inf. Technol. Univ. Technol. Sydney Ultimo NSW Australia 2004A."},{"key":"e_1_3_2_1_36_1","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2017.2728603"}],"event":{"name":"EASE 2024: 28th International Conference on Evaluation and Assessment in Software Engineering","location":"Salerno Italy","acronym":"EASE 2024"},"container-title":["Proceedings of the 28th International Conference on Evaluation and Assessment in Software Engineering"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3661167.3661238","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3661167.3661238","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,8,22]],"date-time":"2025-08-22T11:14:04Z","timestamp":1755861244000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3661167.3661238"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,6,18]]},"references-count":36,"alternative-id":["10.1145\/3661167.3661238","10.1145\/3661167"],"URL":"https:\/\/doi.org\/10.1145\/3661167.3661238","relation":{},"subject":[],"published":{"date-parts":[[2024,6,18]]},"assertion":[{"value":"2024-06-18","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}