Advancing Secure DevSecOps Models to Strengthen Cyber Resilience of U.S. Government Cloud and Federal Information Systems
Taiwo Justice Olorunlana1*, Sodiq Ogunmola2
Abstract
The rapid transition of U.S. federal systems to cloud infrastructures has introduced new opportunities while simultaneously increasing cybersecurity risks. Traditional, episodic security assessments and perimeter-focused defenses are ill-suited to cloud-native architectures and continuous delivery practices. Secure DevSecOps embedding security throughout development, deployment, and operations presents a pragmatic pathway to increase the cyber resilience of government cloud services and federal information systems. This article synthesizes secondary data from federal standards (NIST SP 800-series), federal programs (FedRAMP), oversight reports (GAO), cybersecurity agencies (CISA), and peer-reviewed literature to (1) characterize the current resilience gap, (2) review DevSecOps mechanisms and evidence for their effectiveness in cloud contexts, (3) present a theoretical framework that links systems engineering resilience to DevSecOps practices, and (4) propose policy and technical recommendations for advancing secure DevSecOps adoption across federal agencies. Findings emphasize automation (IaC & policy-as-code), continuous monitoring/authorization, supply-chain controls, workforce development, and organizational culture as core enablers of resilient federal cloud operations.
Keywords:
DevSecOps, Secure DevSecOps, Cyber Resilience, Federal Information Systems, Government Cloud, Zero Trust, FedRAMP, NIST, Continuous Authorization, Supply Chain Security
![International Journal of Science, Architecture, Technology and Environment [E-ISSN: 3048-8222]](https://i0.wp.com/ijsate.com/wp-content/uploads/2026/05/LOGO-1.png?fit=723%2C680&ssl=1)