The impact of cloud services on secure software development
Abstract
The evolution of cloud computing has significantly changed the approaches to developing, testing, deploying, and securing software. The paper aimed to examine the integration of cloud technologies into all stages of the Software Development Life Cycle (SDLC) with a focus on implementing and enforcing security practices throughout the development process. To achieve the objectives of the study, a comparative analysis was used that covers cloud implementations of the SDLC relative to traditional models in terms of key indicators: cost-effectiveness, speed of deployment, level of collaboration, scalability, and security. Real-world case studies that demonstrate the use of cloud tools and platforms were considered, including Infrastructure as Code and Continuous Integration/ Continuous Deployment, to increase productivity, agility, and early implementation of security controls (a “security shift to the left” approach). The analysis results has shown that the use of cloud practices in a secure SDLC helps to reduce time to market, increases the level of proactive security management, and supports iterative and agile development cycles. At the same time, challenges related to compliance with regulatory requirements, user identity management, and vendor lock-in risk were identified. A set of best practices for implementing secure cloud SDLC workflows was proposed and areas for further research are identified, including automated security testing and integration of artificial intelligence into secure software delivery processes. The practical value of the study lies in the formulation of recommendations that will help organisations create sustainable, efficient, and secure cloud development environments
Keywords
cybersecurity practices in development; infrastructure as code; continuous integration and delivery pipelines; automated vulnerability testing; configuration management; cloud responsibility models; system
References
- Amazon Web Services. (n.d.a). AWS well-architected framework – security pillar. Retrieved from https://docs.aws.amazon.com/ wellarchitected/latest/security-pillar.
- Amazon Web Services. (n.d.b). AWS shared responsibility model. Retrieved from https://docs.aws.amazon.com/whitepapers/ latest/introduction-devops-aws/shared-responsibility.htm.
- Basili, V.R., & Turner, A.J. (1975). Iterative enhancement: A practical technique for software development. IEEE Transactions on Software Engineering, SE-1(4), 390-396. doi: 10.1109/TSE.1975.6312870.
- Chauhan, M., & Shiaeles, S. (2023). An analysis of cloud security frameworks, problems and proposed solutions. Network, 3(3), 422-450. doi: 10.3390/network3030018.
- Das, B.S., & Chu, V. (2023). Security as code. Boston: O’Reilly Media Inc.
- Davis, N. (2005). Secure software development life cycle processes: A technology scouting report. Retrieved from https://api.semanticscholar.org/CorpusID:110809329.
- Feio, R., Santos, N., Escravana, N., & Pacheco, B. (2024). An empirical study of DevSecOps focused on continuous security testing. In 2024 IEEE European symposium on security and privacy workshops (EuroS&PW) (pp. 610-617). doi: 10.1109/EuroSPW61312.2024.00074.
- Gadani, N.N. (2024). Security challenges in cloud-based software development: A DevSecOps perspective. The Journal of Scientific and Engineering Research, 11(5), 287-294.
- Google Cloud. (n.d.). Retrieved from https://cloud.google.com/security/solutions/software-supply-chainsecurity?hl=uk.
- IEEE Computer Society. (2024). Guide to the software engineering body of knowledge (SWEBOK V3.0). Retrieved from https://www.computer.org/education/bodies-of-knowledge/software-engineering.
- Jagli, D., & Yeddu, S. (2017). CloudSDLC: Cloud software development life cycle. International Journal of Computer Applications, 168(8), 6-10. doi: 10.5120/ijca2017914468.
- Joseph, W. (2025). DevSecOps in the cloud-native era: Automation, security, and continuous integration. Retrieved from https://www.researchgate.net/publication/391077724_DevSecOps_in_the_Cloud-Native_Era_ Automation_Security_and_Continuous_Integration.
- Kiashemshaki, K., Torkamani, M.J., & Mahmoudi, N. (2025). Secure coding for web applications: Frameworks, challenges, and the role of LLMs. ArXiv. doi: 10.48550/arXiv.2507.22223.
- Kim, G., Behr, K., & Spafford, G. (2013). The Phoenix project: A novel about IT, DevOps, and helping your business win. Portland: IT Revolution Press.
- Leshchenko, I., Horbachova, N., & Bielov, A. (2024). Integrating DevSecOps into the software development lifecycle: A comprehensive model for securing containerized and cloud-native environments. In Proceedings of the cybersecurity providing in information and telecommunication systems II (pp. 153-161). Aachen: CEUR.
- Matseniuk, Y., & Partyka, A. (2024). The concept of automated compliance verification as the foundation of a fundamental cloud security model. Computer Systems and Networks, 6(1), 108-123. doi: 10.23939/ csn2024.01.108.
- Microsoft. (n.d.). Zero Trust security model. https://www.microsoft.com/en-us/security/business/zero-trust.
- Myrbakken, H., & Colomo-Palacios, R. (2017). DevSecOps practices and tools: A multivocal literature review. In Software process improvement and capability determination. SPICE 2017 (pp. 17-29). Cham: Springer. doi: 10.1007/978-3-319-67383-7_2.
- NIST. (2018). Framework for improving critical infrastructure cybersecurity.Retrieved from https://nvlpubs.nist.gov/nistpubs/ CSWP/NIST.CSWP.04162018.pdf.
- OWASP Foundation. (n.d.). OWASP secure SDLC cheat sheet. Retrieved from https://owasp.org/www-project-cheat-sheets/.
- Pawar, A.S. (2025). Cloud-native security: A review of modern approaches. International Journal of Scientific Research & Engineering Trends, 11(2), 1703-1706.
- Pranav, M., Madhesh, I., Lenin, J., & Sasikumar, R. (2025a). Advances in DevSecOps and the future of cybersecurity using automation. In Proceedings of the 4th international conference on information technology, civil innovation, science, and management (pp. 1-18). Tiruchengode: EAI. doi: 10.4108/eai.28-4-2025.2357955.
- Pranav, M., Madhesh, I., Lenin, J., & Sasikumar, R. (2025b). An introduction to adaptive software security. ArXiv. doi: 10.48550/arXiv.2312.17358.
- Saleh, S.M., Madhavji, N., & Steinbacher, J. (2024). A systematic literature review on continuous integration and deployment (CI/CD) for secure cloud computing. In Proceedings of the 20th international conference on web information systems and technologies WEBIST (pp. 331-342). Porto: SciTePress. doi: 10.5220/0013018500003825.
- Saltzer, J.H., & Schroeder, M.D. (1975). The protection of information in computer systems. Proceedings of the IEEE, 63(9), 1278-1308. doi: 10.1109/PROC.1975.9939.
- Umeugo, W.C. (2023). Secure software development lifecycle: A case for adoption in software SMEs. International Journal of Advanced Research in Computer Science, 14(1), 5-12. doi: 10.26483/ijarcs.v14i1.6949.
- Vakhula, O., & Opirskyy, I. (2023). Research on security issues in cloud environments and solutions using the “security as code” approach. Ukrainian Scientific Journal of Information Security, 25(3), 113-122. doi: 10.18372/2410-7840.25.17936.