返回
Enhancing cloud-native DevSecOps: A Zero Trust approach for the financial sector
DOI:10.1016/j.csi.2025.103975.png)
摘要
En 中文
Financial institutions increasingly adopt cloud-native environments and microservices architectures in response to digital transformation and application modernization, leading to a growing demand for cloud-native services. This transition accelerates the development of sophisticated Continuous Integration/Continuous Deployment (CI/CD) pipelines while simultaneously increasing the complexity of DevSecOps environments and expanding the attack surface. Asa result, the financial sector is paying greater attention to the Zero Trust security model to overcome traditional perimeter-based security's limitations and achieve automated, advanced cybersecurity capabilities. However, financial institutions need more concrete examples and foundational material to adopt Zero Trust. This study provides a foundational framework for financial institutions to evaluate and implement Zero Trust policies and technologies independently. It analyzes the relationship between cloud-native initiatives, microservices-based DevSecOps environments, and Zero Trust and identifies key considerations for implementing Zero Trust through a stage-by-stage analysis of the Software Development Life Cycle (SDLC). Furthermore, the study proposes a Zero Trust framework to enhance security and evaluates its applicability based on nine assessment criteria.
Keyword:
Cloud-native
DevSecOps
Microservices
Security
Zero Trust
期刊
C
IF:
3.1
论文数:
2.3K
被引数:
2.0K
机构
引用论文
VRBC: A Verifiable Redactable Blockchain With Efficient Query and Integrity AuditingVRBC:一种可验证的可擦除区块链,支持高效查询与完整性审计
Automation and Orchestration of Zero Trust Architecture: Potential Solutions and Challenges零信任架构的自动化和编排: 潜在的解决方案和挑战
没有更多内容

