An Adaptive Risk-Driven DevSecOps Framework for Securing Multi-Cloud Enterprise Systems in the Era of Agentic AI
Nitin Bodade ()
International Journal of Innovative Science and Research Technology (IJISRT), 2026, vol. 11, issue 07, 214-223
Abstract:
The rapid adoption of cloud-native architectures, microservices, and continuous delivery pipelines has transformed enterprise software engineering by enabling faster deployment cycles, independent service evolution, and scalable digital delivery. However, these advantages also expand the cybersecurity attack surface across source code repositories, CI/CD pipelines, software supply chains, cloud identities, infrastructure-as-code templates, runtime workloads, and distributed multi-cloud environments. Prior research shows that DevSecOps improves software security by embedding security practices into development and operations workflows, yet organizations continue to face challenges related to toolchain fragmentation, inconsistent risk prioritization, limited automation, and weak integration between security findings and deployment decisions. This paper proposes the Adaptive Risk-Driven DevSecOps Framework (ARDDSF), a layered framework for securing multi-cloud enterprise systems in the era of agentic artificial intelligence. ARDDSF integrates real-time risk scoring, AI-assisted threat modeling, secure CI/CD orchestration, policy-as-code enforcement, Zero Trust-aligned access control, and continuous feedback loops across the software development lifecycle. Unlike static DevSecOps pipelines that treat security findings as isolated scan outputs, ARD-DSF prioritizes vulnerabilities using contextual risk factors such as asset criticality, exploitability, deployment stage, identity exposure, cloud configuration posture, regulatory relevance, and runtime telemetry. The primary contribution of this work is a unified, adaptive, and risk-aware DevSecOps architecture that bridges DevSecOps automation, AI-assisted security analysis, Zero Trust policy enforcement, and multi-cloud governance. The paper provides a formal risk scoring model, implementation workflow, experimental protocol, results templates, and architecture to support future validation in enterprise-scale software delivery environments.
Keywords: DevSecOps; Multi-Cloud Security; Agentic AI; Risk-Based Security; Secure SDLC; Zero Trust; AI-Assisted Threat Modeling; CI/CD Security; Policy-As-Code. (search for similar items in EconPapers)
Date: 2026
References: Add references at CitEc
Citations:
Downloads: (external link)
https://www.ijisrt.com/an-adaptive-riskdriven-devs ... he-era-of-agentic-ai (application/pdf)
Related works:
This item may be available elsewhere in EconPapers: Search for items with the same title.
Export reference: BibTeX
RIS (EndNote, ProCite, RefMan)
HTML/Text
Persistent link: https://EconPapers.repec.org/RePEc:cvr:ijisrt:2026:07:ijisrt26jul136
DOI: 10.38124/ijisrt/26jul136
Access Statistics for this article
More articles in International Journal of Innovative Science and Research Technology (IJISRT) from IJISRT Publication
Bibliographic data for series maintained by Rahul Goyel ().