Home
World Journal of Advanced Engineering Technology and Sciences
International, Peer reviewed, Referred, Open access | ISSN Approved Journal

Main navigation

  • Home
    • Journal Information
    • Abstracting and Indexing
    • Editorial Board Members
    • Reviewer Panel
    • Journal Policies
    • WJAETS CrossMark Policy
    • Publication Ethics
    • Instructions for Authors
    • Article processing fee
    • Track Manuscript Status
    • Get Publication Certificate
    • Issue in Progress
    • Current Issue
    • Past Issues
    • Become a Reviewer panel member
    • Join as Editorial Board Member
  • Contact us
  • Downloads

ISSN: 2582-8266 (Online)  || UGC Compliant Journal || Google Indexed || Impact Factor: 9.48 || Crossref DOI

Fast Publication within 2 days || Low Article Processing charges || Peer reviewed and Referred Journal

Research and review articles are invited for publication in Volume 18, Issue 2 (February 2026).... Submit articles

The security-first agile playbook: Embedding DevSecOps into program management practices

Breadcrumb

  • Home
  • The security-first agile playbook: Embedding DevSecOps into program management practices

Geetha Aradhyula *

Program Management Office Zolon Tech Inc. Herndon Virginia United States.

Review Article

World Journal of Advanced Engineering Technology and Sciences, 2025, 16(03), 015–031

Article DOI: 10.30574/wjaets.2025.16.3.1313

DOI url: https://doi.org/10.30574/wjaets.2025.16.3.1313

Received on 20 July 2025; revised on 25 August 2025; accepted on 29 August 2025

In a time when digital transformation has accelerated and cyber threats have become increasingly complex; organizations face the double whammy of needing to keep Agile delivery speeds high while holding security and compliance at an inseparable level of consideration. Traditional Agile methods promote very fast iterations and placing value in their customer, oftentimes depriving security of its due share of time or relegating it to after development, which leads to either vulnerabilities or compliance issues, and expensive reworks. Hence such a gap has been addressed by this research: it introduces the Security-First Agile Playbook, a coherent mechanism to weave DevSecOps practices into the program management continuum. So, in simple terms, the playbook treats security as a continuous, collaborative, and measurement-based activity that is ingrained in their sprints and release cycle.
The core tenets in the framework revolve around security by design, i.e., vulnerability scanning by automation, threat modeling, secure coding practices, and compliance checking in real-time within development pipelines. Bringing in DevSecOps pipelines offers the prospect of shifting security left allowing issues to be found much earlier, remediated in a timely fashion, and in-built metrics like mean time to remediation (MTTR) and vulnerability density to be tracked through compliance adherence. Furthermore, the playbook emphasizes the role of program managers as security enablers, embedding security champions in cross-functional teams, aligning sprint goals with risk management objectives, and harmonizing Agile governance with regulatory frameworks.
Borrowing insights across highly regulated industries such as finance, healthcare, and defense, the study has illustrated some practical pathways for implementing the Security-First Agile Playbook, including cultural transformation, automated tool adoption, and adaptive governance. From the findings, we conclude that embedding security in program management mitigates risks while simultaneously enhancing organizational resilience, stakeholder trust, and fast-tracking secure innovation. Therefore, the Security-First Agile Playbook provides a pragmatic, adaptive framework for organizations to weight speed, assurance, and resilience in an increasingly volatile digital world. 
 

Agile Software Development, DevSecOps, Program Management, Secure Software Development Lifecycle (SSDLC), Continuous Compliance, Cyber Resilience

https://wjaets.com/sites/default/files/fulltext_pdf/WJAETS-2025-1313.pdf

Preview Article PDF

Geetha Aradhyula. The security-first agile playbook: Embedding DevSecOps into program management practices. World Journal of Advanced Engineering Technology and Sciences, 2025, 16(03), 015-031. Article DOI: https://doi.org/10.30574/wjaets.2025.16.3.1313.

Get Certificates

Get Publication Certificate

Download LoA

Check Corssref DOI details

Issue details

Issue Cover Page

Editorial Board

Table of content


Copyright © Author(s). All rights reserved. This article is published under the terms of the Creative Commons Attribution 4.0 International License (CC BY 4.0), which permits use, sharing, adaptation, distribution, and reproduction in any medium or format, as long as appropriate credit is given to the original author(s) and source, a link to the license is provided, and any changes made are indicated.


Copyright © 2026 World Journal of Advanced Engineering Technology and Sciences

Developed & Designed by VS Infosolution