Applying DevSecOps Approach in Legacy Computing Infrastructures: A Case Study in Public Sector of Brazil
Resumo
Legacy computing environments in the public sector present significant cybersecurity challenges due to outdated systems, technological heterogeneity and complex operational demands. In this context, this paper presents an initial study within a real-world case at a Brazilian governmental institution that applies the DevSecOps methodology in the CI/CD pipeline with two distinct security tools: Static Application Security Testing (SAST) and Vulnerability Management (VM). SAST was applied to assess application security at code level, while VM targeted infrastructure-level risks using metrics such as CVSS and EPSS. The results demonstrate the value of each approach in improving risk visibility and mitigation and the possibility of integrating both tools into a unified DevSecOps workflow, aiming for continuous security and greater operational resilience. This work provides practical insights for public institutions seeking to modernize their cybersecurity posture while addressing the constraints inherent to legacy systems, in alignment with frameworks such as NIST CSF and CIS Controls.
Publicado
27/10/2025
Como Citar
LIMA, João C. C.; CAMPOS, Francisco R. M.; GOMES, Rafael L.; RODRIGUES, Emanuel B.; ANDRADE, Rossana M. C.; SILVA, Clenival L.; BENTES, Daniel C.; CIALDINI, Alexandre S..
Applying DevSecOps Approach in Legacy Computing Infrastructures: A Case Study in Public Sector of Brazil. In: LATIN-AMERICAN SYMPOSIUM ON DEPENDABLE COMPUTING (LADC), 14. , 2025, Valparaíso/Chile.
Anais [...].
Porto Alegre: Sociedade Brasileira de Computação,
2025
.
p. 3-19.
