Högskolan i Skövde

his.sePublications
Change search
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • apa-cv
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf
Evaluating Cloud Security in Terraform DevSecOps Architecture and DORA Metrics Compliance
University of Skövde, School of Informatics.
2025 (English)Independent thesis Advanced level (degree of Master (Two Years)), 20 credits / 30 HE creditsStudent thesis
Abstract [en]

This study explores the challenges of integrating DORA metrics, DevSecOps principles, and Terraform an Infrastructure as Code (IaC) tool, to improve cloud security and operational performance of the organization in the Azure cloud provider. The study evaulates the relationship between CPU monitoring, Mean Time to Recovery (MTTR), and system reliability, with the goal of ensuring business continuity.

Additionally, the study provides insights into the challenges and best practices for integrating DevSecOps principles into the software development lifecycle deployment pipeline, enhancing cloud security, and improving team agility by reducing the threat attack surface.

The study further investigates the benefits of integrating DevSecOps principles, such as shift-left security, continuous vulnerability scanning, automation, and real-time monitoring-as-code, to improve team organization performance and scale in DORA metrics (Elite/High).

The research methodology involves a review of existing related work on Terraform, DORA metric, and DevSecOps, an analysis of existing cloud security frameworks, and the development of a proposed framework. The proposed framework architecture integrates threat intelligence, DevSecOps, and Infrastructure as Code (IaC).

The study aims to bridge the gap between rapid software development lifecycle and robust security measures by fostering a culture of security awareness and resilience in each stage of the software development lifecycle.

Place, publisher, year, edition, pages
2025. , p. v, 68
Keywords [en]
Cloud security, Cloud Infrastructure, Azure, DORA Metrics, DevOps, DevSecOps, Infrastructure as code, DevSecOps, Continuous Integration and Continuous Deployment (CICD), Azure pipeline, Cloud Security Monitoring, Infrastructure Provisioning
National Category
Information Systems
Identifiers
URN: urn:nbn:se:his:diva-25505OAI: oai:DiVA.org:his-25505DiVA, id: diva2:1984098
External cooperation
Ericsson AB
Subject / course
Informationsteknologi
Educational program
Privacy, Information and Cyber Security - Master's Programme 120 ECTS
Supervisors
Examiners
Available from: 2025-07-14 Created: 2025-07-14 Last updated: 2025-09-29Bibliographically approved

Open Access in DiVA

fulltext(2011 kB)371 downloads
File information
File name FULLTEXT01.pdfFile size 2011 kBChecksum SHA-512
7696a5486faea47c96a28c146e1e06636f9ec69bf567510b97c043448e7280d42e60397de287fc9486cbbdde7659b45fa0157678bdecb20ccb1781fb8fea44a0
Type fulltextMimetype application/pdf

By organisation
School of Informatics
Information Systems

Search outside of DiVA

GoogleGoogle Scholar
Total: 372 downloads
The number of downloads is the sum of all downloads of full texts. It may include eg previous versions that are now no longer available

urn-nbn

Altmetric score

urn-nbn
Total: 226 hits
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • apa-cv
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf