Era of DevOps, Cybersecurity, and Artificial Intelligence: A Continuous Value and Risk Engineering Framework for Enterprise Software Delivery

Authors

  • Vivek Kadam, Mohammad Bari Syed, Mayank Dwivedi

Keywords:

software engineering, enterprise governance, CI/CD, value stream management, cyber-risk prediction, continuous compliance, artificial intelligence, DevSecOps

Abstract

Enterprise software delivery is increasingly governed by three objectives that are usually optimized in isolation: delivery throughput, cyber-risk containment, and business value realization. This paper proposes the Continuous Value and Risk Engineering Framework (CVREF), a closed-loop design that treats business value and cyber risk as simultaneous decision variables across the DevOps lifecycle. CVREF combines telemetry ingestion, AI-supported risk prediction, threat intelligence, continuous policy evaluation, multi-objective release control, and outcome-based learning. A design-science evaluation is reported for an author-supplied hybrid-cloud testbed comprising 48 applications, 820 microservices, 210 CI/CD pipelines, 26 Kubernetes clusters, 7,800 runtime containers, and 360 experimental runs over 120 days. CVREF is compared with seven DevOps, DevSecOps, commercial-platform, AI-automation, and continuous-risk baselines. On the supplied aggregate results, CVREF achieved 98.2% deployment success, 97.8% vulnerability detection, 98.1% threat detection, a 94.8 Business Value Index, 98.4% compliance, and 46.7% return on investment. Relative to the strongest reported baseline for each metric, mean time to detect and mean time to recover decreased by 26.2% and 30.5%, respectively. The supplied statistical summary reports p < 0.001, Cohen’s d = 1.18, and ten-fold ROC-AUC = 0.986. The paper formalizes the Business Value Index, Risk-to-Value Ratio, governance constraints, decision policy, and reproducibility controls needed to test these claims independently. Findings indicate that a value-aware release gate can improve the alignment of security intervention with enterprise outcomes, but causal and cross-organizational generalization remains contingent on access to run-level data, transparent baseline configuration, and prospective replication.

References

A. R. Hevner, S. T. March, J. Park, and S. Ram, “Design science in information systems research,” *MIS Q.*, vol. 28, no. 1, pp. 75-105, 2004.

C. Autio et al., “Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile,” NIST AI 600-1, 2024, doi: 10.6028/NIST.AI.600-1.

CISA, “Secure by Design,” Cybersecurity and Infrastructure Security Agency, 2025. [Online]. Available: [https://www.cisa.gov/securebydesign](https://www.cisa.gov/securebydesign?utm_source=chatgpt.com)

D. Farley, *Modern Software Engineering*. Boston, MA, USA: Addison-Wesley, 2022.

F. M. A. Erich, C. Amrit, and M. Daneva, “A qualitative study of DevOps usage in practice,” *J. Softw. Evol. Process*, vol. 29, no. 6, e1885, 2017, doi: 10.1002/smr.1885.

G. Kim, J. Humble, P. Debois, J. Willis, and N. Forsgren, *The DevOps Handbook*, 2nd ed. Portland, OR, USA: IT Revolution, 2021.

GitHub, “GitHub Advisory Database,” 2026. [Online]. Available: [https://github.com/advisories](https://github.com/advisories?utm_source=chatgpt.com)

Google Cloud DORA, “Accelerate State of DevOps Report 2024,” Google, 2024. [Online]. Available: [https://dora.dev/research/2024/dora-report/](https://dora.dev/research/2024/dora-report/?utm_source=chatgpt.com)

Google Cloud DORA, “State of AI-assisted software development 2025,” Google, 2025. [Online]. Available: [https://dora.dev/dora-report-2025/](https://dora.dev/dora-report-2025/?utm_source=chatgpt.com)

H. Booth et al., “Secure Software Development Practices for Generative AI and Dual-Use Foundation Models,” NIST SP 800-218A, 2024, doi: 10.6028/NIST.SP.800-218A.

ISO/IEC, “ISO/IEC 27001:2022 Information security management systems - Requirements,” Geneva, Switzerland, 2022.

J. Cappos et al., “in-toto: Providing farm-to-table guarantees for bits and bytes,” in *Proc. 28th USENIX Security Symp.*, 2019, pp. 1393-1410.

J. Humble and D. Farley, *Continuous Delivery*. Boston, MA, USA: Addison-Wesley, 2010.

J. Y. Zhang et al., “Quantitative DevSecOps metrics for cloud-based web applications,” *IEEE Access*, 2024.

K. Peffers, T. Tuunanen, M. A. Rothenberger, and S. Chatterjee, “A design science research methodology for information systems research,” *J. Manage. Inf. Syst.*, vol. 24, no. 3, pp. 45-77, 2007.

L. Leite, C. Rocha, F. Kon, D. Milojicic, and P. Meirelles, “A survey of DevOps concepts and challenges,” *ACM Comput. Surv.*, vol. 52, no. 6, pp. 1-35, 2019, doi: 10.1145/3359981.

M. A. Akbar et al., “A systematic study to improve the requirements engineering process in the domain of global software development,” *J. Softw. Evol. Process*, vol. 32, no. 5, e2230, 2020.

M. Kersten, *Project to Product: How to Survive and Thrive in the Age of Digital Disruption with the Flow Framework*. Portland, OR, USA: IT Revolution, 2018.

M. Myrbakken and R. Colomo-Palacios, “DevSecOps: A multivocal literature review,” in *Software Process Improvement and Capability Determination*, Springer, 2017, pp. 17-29.

M. Souppaya, K. Scarfone, and D. Dodson, “Secure Software Development Framework (SSDF) Version 1.1,” NIST SP 800-218, 2022, doi: 10.6028/NIST.SP.800-218.

MITRE, “MITRE ATT&CK knowledge base,” 2026. [Online]. Available: [https://attack.mitre.org/](https://attack.mitre.org/?utm_source=chatgpt.com)

N. Forsgren, J. Humble, and G. Kim, *Accelerate: The Science of Lean Software and DevOps*. Portland, OR, USA: IT Revolution, 2018.

National Institute of Standards and Technology, “Artificial Intelligence Risk Management Framework (AI RMF 1.0),” NIST AI 100-1, 2023, doi: 10.6028/NIST.AI.100-1.

National Institute of Standards and Technology, “National Vulnerability Database,” 2026. [Online]. Available: [https://nvd.nist.gov/](https://nvd.nist.gov/?utm_source=chatgpt.com)

National Institute of Standards and Technology, “Security and Privacy Controls for Information Systems and Organizations,” NIST SP 800-53 Rev. 5, upd. 1, 2020, doi: 10.6028/NIST.SP.800-53r5.

National Institute of Standards and Technology, “The NIST Cybersecurity Framework (CSF) 2.0,” NIST CSWP 29, 2024, doi: 10.6028/NIST.CSWP.29.

OpenSSF, “Scorecard: Security health metrics for open source,” 2025. [Online]. Available: [https://securityscorecards.dev/](https://securityscorecards.dev/?utm_source=chatgpt.com)

OWASP Foundation, “OWASP Benchmark,” 2025. [Online]. Available: [https://owasp.org/www-project-benchmark/](https://owasp.org/www-project-benchmark/?utm_source=chatgpt.com)

R. C. B. Ramos et al., “Cybersecurity in DevOps environments: A systematic literature review,” *IEEE Access*, 2025.

S. Hendrick and K. Mar, “Software Bill of Materials (SBOM) sharing lifecycle report,” CISA, 2024.

S. M. Lundberg and S.-I. Lee, “A unified approach to interpreting model predictions,” in *Advances in Neural Information Processing Systems 30*, 2017, pp. 4765-4774.

S. Nagasundari et al., “Extensive review of threat models for DevSecOps,” *IEEE Access*, 2025.

SLSA, “Supply-chain Levels for Software Artifacts specification,” OpenSSF, 2024. [Online]. Available: [https://slsa.dev/](https://slsa.dev/?utm_source=chatgpt.com)

T. T. Bannon, “Infusing artificial intelligence into software engineering and the DevSecOps continuum,” *Computer*, vol. 57, 2024.

Downloads

How to Cite

Vivek Kadam, Mohammad Bari Syed, Mayank Dwivedi. (2026). Era of DevOps, Cybersecurity, and Artificial Intelligence: A Continuous Value and Risk Engineering Framework for Enterprise Software Delivery. International Journal of Research & Technology, 14(3), 930–960. Retrieved from https://ijrt.org/j/article/view/1767

Similar Articles

<< < 56 57 58 59 60 61 62 63 64 65 > >> 

You may also start an advanced similarity search for this article.