Policy-as-Code for Secure Delivery: Embedding Compliance Controls into DevSecOps Pipelines

research-article
Received: Feb 22, 2022
Published: May 10, 2022
Authors:

Abstract

Security and compliance requirements are frequently enforced through manual reviews that slow delivery and introduce inconsistency. This paper presents a policy-as-code framework that embeds compliance controls directly into DevSecOps pipelines using declarative rules, automated evidence capture, and continuous verification. The framework standardizes controls across build, test, and deployment stages, enabling deterministic enforcement of least privilege, secret hygiene, artifact provenance, and infrastructure guardrails. Results show reduced audit preparation time, fewer policy exceptions, and improved security posture without sacrificing deployment velocity.

Cite this article

(2022). Policy-as-Code for Secure Delivery: Embedding Compliance Controls into DevSecOps Pipelines. Research Explorations in Global Knowledge & Technology (REGKT), 1 (2). Retrieved from https://regkt.com/article.php?id=773&slug=policy-as-code-secure-delivery-embedding-compliance-controls-devsecops-pipelines

Premium Membership Required

You need a premium account to view or download this article.

Become Premium