Abstract
In addition to immediate course-level outcomes, this work also motivates the need for sustained integration of DevSecOps practices into curricula, with future plans to conduct longitudinal studies following graduates into professional practice to evaluate retention and industry impact.We present an undergraduate DevSecOps module that embeds real-world security tooling into a multi-stage CI/CD pipeline. Students build a small service (Flask/Express), then integrate automated build/test, SAST (SonarCloud), container scanning (Trivy), infrastructure-as-code checks (Checkov/Terraform), and optional DAST (OWASP ZAP). The module is delivered via project-based learning with scaffolded labs and a capstone pipeline project.Using a mixed-methods evaluation across two course offerings, we analyze pre/post knowledge assessments, CI/CD artifacts (workflows, scan reports), and student reflections. Results indicate substantial gains in secure delivery concepts and tool proficiency; 95% of teams implemented pipelines with at least four security-integrated stages, and average knowledge scores rose from 54% to 86%. Students reported high perceived realism and relevance compared to traditional labs.While results indicated strong student learning gains, assessing the quality of security remediation remained partly subjective, requiring instructor expertise. Future iterations will investigate more automated evaluation strategies, potentially leveraging AI/ML-based vulnerability classification and remediation analysis.We contribute: (1) a replicable, tool-centric DevSecOps curriculum emphasizing "shift-left"remediation, (2) an assessment approach leveraging authentic pipeline artifacts, and (3) practical guidance on scaling secure pipelines in academic settings (secrets management, cloud sandboxes, and automated grading). We also discuss challenges (tool complexity, integration overhead) and directions for wider adoption.
Author supplied keywords
Cite
CITATION STYLE
Mittal, A., Sudarsan, S., & Sekar, A. (2025). Curricular Integration of DevSecOps: A Real-World Pipeline Approach to Secure Software Engineering Education. In ACM SIGCITE 2025 - Proceedings of the 26th ACM Annual Conference on Cybersecurity and Information Technology Education (pp. 168–173). Association for Computing Machinery, Inc. https://doi.org/10.1145/3769694.3771132
Register to see more suggestions
Mendeley helps you to discover research relevant for your work.