Please use this identifier to cite or link to this item: https://er.chdtu.edu.ua/handle/ChSTU/10009
Title: The impact of cloud services on secure software development
Other Titles: Вплив хмарних сервісів на безпечну розробку програмного забезпечення
Authors: Shishkin, Maksym
Шишкін, Максим
Keywords: cybersecurity practices in development;infrastructure as code;continuous integration and delivery pipelines;automated vulnerability testing;configuration management;cloud responsibility models;system oversight and monitoring;практики кіберзахисту у розробці;інфраструктура як код;конвеєри безперервної інтеграції та доставки;автоматизоване тестування вразливостей;управління конфігураціями;моделі розподілу відповідальності у хмарі;наглядовість та моніторинг систем
Issue Date: 2026
Publisher: Вісник Черкаського державного технологічного університету
Abstract: The evolution of cloud computing has significantly changed the approaches to developing, testing, deploying, and securing software. The paper aimed to examine the integration of cloud technologies into all stages of the Software Development Life Cycle (SDLC) with a focus on implementing and enforcing security practices throughout the development process. To achieve the objectives of the study, a comparative analysis was used that covers cloud implementations of the SDLC relative to traditional models in terms of key indicators: cost-effectiveness, speed of deployment, level of collaboration, scalability, and security. Real-world case studies that demonstrate the use of cloud tools and platforms were considered, including Infrastructure as Code and Continuous Integration/ Continuous Deployment, to increase productivity, agility, and early implementation of security controls (a “security shift to the left” approach). The analysis results has shown that the use of cloud practices in a secure SDLC helps to reduce time to market, increases the level of proactive security management, and supports iterative and agile development cycles. At the same time, challenges related to compliance with regulatory requirements, user identity management, and vendor lock-in risk were identified. A set of best practices for implementing secure cloud SDLC workflows was proposed and areas for further research are identified, including automated security testing and integration of artificial intelligence into secure software delivery processes. The practical value of the study lies in the formulation of recommendations that will help organisations create sustainable, efficient, and secure cloud development environments.
Еволюція хмарних обчислень суттєво змінила підходи до розроблення, тестування, розгортання та захисту програмного забезпечення. Метою дослідження було проведення аналізу інтеграції хмарних технологій у всі етапи життєвого циклу розробки програмного забезпечення (SDLC) з акцентом на систематичне впровадження та застосування практик безпеки протягом усього процесу розробки. Для досягнення цілей дослідження використано порівняльний та контент-аналіз, що охопив хмарні реалізації SDLC у співвідношенні з традиційними моделями за ключовими показниками: економічною ефективністю, швидкістю розгортання, рівнем співпраці, масштабованістю та безпекою. Розглянуто реальні тематичні приклади, які демонструють використання хмарних інструментів і платформ, зокрема Інфраструктури як коду та Безперервної інтеграції/Безперервного розгортання, для підвищення продуктивності, гнучкості та раннього впровадження механізмів контролю безпеки (підхід «зміщення безпеки вліво»). Результати аналізу показали, що застосування хмарних практик у безпечному SDLC сприяє скороченню часу виходу продукту на ринок, підвищує рівень проактивного управління безпекою та підтримує ітеративні й гнучкі цикли розробки. Водночас виявлено виклики, пов’язані з дотриманням нормативних вимог, управлінням ідентифікацією користувачів і ризиком залежності від постачальника. Запропоновано набір найкращих практик для впровадження безпечних хмарних робочих процесів SDLC і визначено напрями подальших досліджень, зокрема автоматизоване тестування безпеки та інтеграцію штучного інтелекту у процеси безпечної доставки програмного забезпечення. Практична цінність дослідження полягає у формуванні рекомендацій, що допоможуть організаціям створювати стійкі, ефективні та безпечні хмарні середовища розробки.
URI: https://er.chdtu.edu.ua/handle/ChSTU/10009
ISSN: 2306-4412 (print)
2708-6070 (online)
DOI: https://doi.org/10.62660/bcstu/1.2026.85
Volume: 31
Issue: 1
First Page: 85
End Page: 100
Appears in Collections:том 31, №1/2026

Files in This Item:
File Description SizeFormat 
9.pdf443.46 kBAdobe PDFThumbnail
View/Open
зміст.pdf149.89 kBAdobe PDFThumbnail
View/Open
титул.pdf283.8 kBAdobe PDFThumbnail
View/Open


Items in DSpace are protected by copyright, with all rights reserved, unless otherwise indicated.