Shifting Security Left In The Insurance SDLC: A Devsecops Maturity Model
DOI:
https://doi.org/10.64252/axevpt36Keywords:
Insurance, DevSecOps, Security, SDLCAbstract
In this paper, a DevSecOp Maturity Model (DSM 2 I) specific to insurance companies is proposed to help insure this software development lifecycle (SDLC) by moving the security to the left. Based on BSIMM and OWASP SAMM, along with our evaluations of five insurance companies, we can check the DevSecOps preparedness. Measurable data demonstrate the positive changes in the vulnerability remediation rates, compliance wherever it needs to be aligned, and automation performance after the incorporation of DevSecOps. Nonetheless, the capability of people and cultural integration is not developed. We have shown that the incorporation of well-organized feedback cycles, threat modelling and role-based training is an efficient way to improve security posture. DSM.