Press Release Checkmarx Fusion: Hybrid Scanning Delivers the Most Complete Vulnerability Detection Available Read Now
Gartner® Checkmarx Named a Leader in the 2026 Gartner® Magic Quadrant™ for Software Supply Chain Security Get the Report
Outlook Report The Future of Application Security in the Era of AI Download Now
Webinar The AppSec Bottleneck Has Moved Downstream: Why visibility is no longer enough in the age of AI-generated code Watch Now
Latest Innovations
Checkmarx for Developers
Partners
Blog
Research

What is DevOps Security?

application security cover image

Industry research consistently shows that most successful attacks against an application exploit vulnerabilities that are already well understood, and for which a patch or remediation recommendation is available. Some say that DevOps can by its very nature make software less secure. That’s because DevOps teams work with agile methodologies, and often in continuous deployment environments that may quickly fall behind the application security practices used in environments with fewer deployments.

It’s suggested that DevOps Security suffers from an inherent weakness in these environments where the organization begins to lose a cohesive communications structure because of the rapid nature of the work. The added responsibility given to each developer over the quality of their code means that it is up to them to ensure the code meets their organization’s application security policy. Unfortunately, since developers are not all proficient in the intricacies of secure coding, this can lead to areas in the application that are vulnerable to attacks.

Today this discipline is more often called DevSecOps, and its scope has widened considerably. The surge in AI-generated code, a sharper focus on software supply chain risk, and the automation of security testing inside the pipeline have all reshaped how teams protect applications without slowing delivery.

DevOps becomes DevOps Security (DevSecOps)

DevOps teams don’t exist in isolation from the organizations they serve. The rapid evolution of applications through agile methods is a huge gain when it comes to testing and rapid deployment of robust systems. So the question is not if DevOps is inherently insecure, but rather how it is that DevOps teams can integrate security into their development lifecycle.

DevOps Security really involves bringing security closer to the development of the application. It shouldn’t be viewed as an optional extra or a function of another team to provide. Instead the ideal DevOps Security environment is one where information security is prioritized. It becomes an adaptive and ideally programmable function so that from inception, applications and services are understood to need information security, and that this requirement is part of the design and testing phase throughout the application’s development.

DevOps vs DevSecOps differences infographic

This integrated approach is now widely known as DevSecOps, where security is a shared responsibility across the pipeline rather than a separate gate at the end. The stakes have grown as nearly all developers now use AI coding assistants, making it essential that security keeps pace with the speed and volume of AI-assisted development.

DevOps Security and Continuous Application Deployment

Continuous application deployment environments are no different. If DevOps Security is part of application design then it will also be part of the test design for the environment. That means as an application is deployed, it should be tested. It may not be possible to test 100% of your code but as with any test environment it’s possible for a DevOps team to identify security priorities for testing. Coverage of high-risk areas should be 100%, and areas that represent a much lower risk for exploitation and/or minimal consequences in the event of a security breach may receive a lower priority.

Unit-testing in particular allows for security processes to be tested on the fly, as the application is deployed. Security should be part of the strategy for integration and final systems testing too. It’s likely that a Security oriented DevOps team will focus on regular unit tests and occasional integration tests throughout the development cycle and then use system testing to ensure lower risk areas are appropriately managed at the end of development.

Modern pipelines also extend testing beyond first-party code to the open-source components an application depends on. Generating a software bill of materials and continuously scanning these dependencies has become a standard practice for managing software supply chain risk and catching vulnerable or compromised packages before release.

There is no inherent weakness in the DevOps theory or usage – it just needs to ensure that appropriate precautions are taken to focus on security as part of development.

Securing AI-Generated Code in DevOps

The rapid adoption of AI coding assistants has reshaped DevOps security priorities. Recent research analyzing more than 100 large language models found that roughly 45% of AI-generated code samples contain security flaws. Weaknesses such as cross-site scripting and log injection appear in the majority of vulnerable cases, because AI tools generate functional code without understanding an application’s security context.

For DevOps teams, this means AI-generated code cannot be trusted by default and must face the same scrutiny as human-written code. Embedding automated scanning directly in the pipeline catches these vulnerabilities before AI-assisted contributions reach production, while clear governance over how and where AI tools are used helps teams capture the productivity gains without expanding their attack surface.

Checkmarx One Agentic Appsec Platform enhances the introduction of security to the DevOps methodology.

It will scan code before it has been compiled so that security analysis is supported right from the start of the development lifecycles. There are several plugins available for InteliJ, Visual Studio and Eclipse where the developer may initiate a scan from within the development environment. They then receive the results with any security vulnerabilities identified. These vulnerabilities are detailed by severity, allowing the developer to prioritize mitigation.

The vulnerable code is flagged too and that allows a member of the DevOps team to identify the best fix locations and come up with the most effective remediation advice.

AppSec Software Built to Secure
What AI Can’t

Checkmarx secures the risk AI creates. High-fidelity findings, validated prioritization, and governed remediation — delivered through a hybrid engine built for every stage of the AI-driven SDLC.

Risk Inputs
Code
Supply Chain
AI Components
Runtime
Checkmarx ASPM
Unified Risk Intelligence & AI-BOM
Fidelity Filter
FAE Validation F-score Signal Exploitability Context Risk Orchestration
Outputs
Prioritized Risk
Context-Aware Fix
Governed Decision