Low-Code Paradox in DevOps: Security and Governance Insights from Practitioners
Muhammad Azeem Akbar, Saima Rafi, Arif Ali Khan

TL;DR
This paper explores how low-code development platforms impact security and governance in DevOps, highlighting risks and the need for proactive practices based on practitioner insights.
Contribution
It provides empirical insights into security and governance challenges of LCDPs in DevOps through interviews with IT professionals.
Findings
LCDPs automate tasks but increase security risks
Governance challenges are amplified by LCDP adoption
Proactive security practices are essential for safe LCDP integration
Abstract
DevOps has become a dominant paradigm in modern software engineering, while low-code development platforms (LCDPs) are increasingly adopted to streamline software development. The integration of these approaches promises efficiency gains but also raises critical concerns regarding security and governance. Despite their growing use, insufficient attention has been given to the implications of these platforms for security and governance in DevOps environments. This study investigates practitioners perspectives on the security and governance implications of LCDPs in DevOps environments. Twelve semi-structured interviews were conducted with IT professionals experienced in low-code and DevOps practices. The data were analyzed using a grounded theory approach to identify emergent themes. Findings reveal that LCDPs help automate tasks; however, they also increase security risks and governance…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
