Framework Keandalan Sistem Informasi dengan Pendekatan DevSecOps pada Lembaga Keuangan

Authors

  • Citra Dewi Sari Universitas Ibnu Sina
  • Nanda Jarti Universitas Ibnu Sina Batam

Keywords:

sistem informasi, Framework, DevSecOps, Lembaga Keuangan

Abstract

Keandalan sistem informasi merupakan prasyarat utama bagi lembaga keuangan dalam menjaga stabilitas operasional, keamanan data, dan kepercayaan publik di tengah percepatan transformasi digital. Kompleksitas arsitektur berbasis cloud, otomatisasi layanan, serta integrasi sistem yang semakin luas meningkatkan eksposur risiko keamanan dan gangguan layanan. Pendekatan pengelolaan sistem informasi yang terfragmentasi antara pengembangan, operasional, dan keamanan terbukti tidak lagi memadai. Penelitian ini bertujuan untuk mengembangkan framework keandalan sistem informasi dengan pendekatan DevSecOps yang kontekstual bagi lembaga keuangan. Penelitian menggunakan pendekatan kualitatif dengan desain pengembangan kerangka konseptual berbasis studi literatur sistematis terhadap publikasi ilmiah bereputasi yang membahas DevSecOps, keandalan sistem, resiliensi digital, dan sistem keuangan. Data dianalisis melalui analisis tematik dan sintesis konseptual untuk mengidentifikasi dimensi utama keandalan sistem serta relasinya dengan praktik DevSecOps. Hasil penelitian menunjukkan bahwa keandalan sistem informasi tidak hanya ditentukan oleh kontrol keamanan teknis, tetapi oleh integrasi berkelanjutan antara DevSecOps, prinsip Zero Trust, observabilitas, dan Site Reliability Engineering. Integrasi tersebut membentuk mekanisme pencegahan, deteksi, respons, dan pemulihan yang saling memperkuat. Penelitian ini menghasilkan framework keandalan sistem informasi berbasis DevSecOps yang menempatkan keamanan, resiliensi, dan kepatuhan sebagai bagian struktural dari siklus hidup sistem. Framework ini diharapkan menjadi acuan strategis dan operasional bagi lembaga keuangan dalam membangun sistem informasi yang andal, adaptif, dan berkelanjutan

References

Alonso, J., Piliszek, R., Cankar, M., & Truscan, D. (2023). Embracing infrastructure as code through the DevSecOps philosophy: Concepts, challenges, and a reference framework. IEEE Software, 40(1), 68–76. https://doi.org/10.1109/MS.2022.3212194

Aradhyula, G. (2025). The security-first agile playbook: Embedding DevSecOps into program management practices. World Journal of Advanced Engineering Technology and Sciences, 16(3), 1313–1322. https://doi.org/10.30574/wjaets.2025.16.3.1313

Arivuchudar, R. (2022). Continuous security in DevOps: Implementing DevSecOps for FinTech. International Journal for Multidisciplinary Research, 4(2), 12061. https://doi.org/10.36948/ijfmr.2022.v04i02.12061

Brighente, A., Burato, E., & Conti, M. (2025). Are you sure that is secure? Assessing organizations security readiness via a DevSecOps maturity model. In Proceedings of the IEEE European Symposium on Security and Privacy Workshops (pp. 1–10). IEEE. https://doi.org/10.1109/EuroSPW67616.2025.00068

Coston, I., Hezel, K. D., Plotnizky, E., & Glick, R. (2025). Enhancing secure software development with AZTRM-D: An AI-integrated approach combining DevSecOps, risk management, and Zero Trust. Applied Sciences, 15(15), 8163. https://doi.org/10.3390/app15158163

Daah, C., Qureshi, A., & Awan, I. (2023). Zero Trust model implementation considerations in financial institutions: A proposed framework. In Proceedings of the International Conference on Future Cloud Computing and Data Analytics (pp. 1–8). IEEE. https://doi.org/10.1109/FiCloud58648.2023.00019

Dasanayake, S. D. L. V., Senanayake, J., & Wijayanayake, W. M. J. I. (2025). DevSecOps for continuous security in trading software application development: A systematic literature review. Journal of Desk Research Review and Analysis, 2(2), 1–15. https://doi.org/10.4038/jdrra.v2i2.52

David, P., Kushwaha, M. K., & Suseela, G. (2024). DevSecOps in finance: Strengthening the security model of applications. In Proceedings of the IEEE International Conference on Distributed Computing and Electrical Circuits and Systems (pp. 1–6). IEEE. https://doi.org/10.1109/ICDECS59733.2023.10502917

Enoiu, E. P., Truscan, D., Sadovykh, A., & Gallina, B. (2023). VeriDevOps software methodology: Security verification and validation for DevOps practices. ACM. https://doi.org/10.1145/3600160.3605054

Gupta, A. (2022). An integrated framework for DevSecOps adoption. International Journal of Computer Trends and Technology, 70(6), 102–108. https://doi.org/10.14445/22312803/IJCTT-V70I6P102

Halliday, N. (2023). A conceptual framework for financial network resilience integrating cybersecurity, risk management, and digital infrastructure stability. Journal of Digital Resilience and Risk Analysis, 3(2), 45–58. https://doi.org/10.62225/2583049x.2023.3.2.4887

Kamlakshya, T. (2023). Enhancing cybersecurity in digital banking transformation: A framework for secure payment ecosystems. World Journal of Advanced Engineering Technology and Sciences, 10(2), 309–318. https://doi.org/10.30574/wjaets.2023.10.2.0309

Kohli, S. (2025). Financial resilience: Cloud architecture and AI risk integration. Journal of International Crisis and Risk Communication Research. https://doi.org/10.63278/jicrcr.vi.3254

Kushwaha, M. K., David, P., & Suseela, G. (2024). Automation and DevSecOps: Streamlining security measures in financial systems. IEEE CONECCT Proceedings, 1–6. https://doi.org/10.1109/CONECCT62155.2024.10677271

Mahida, A. (2024). Integrating observability with DevOps practices in financial services technologies: A study on enhancing software development and operational resilience. International Journal of Advanced Computer Science and Applications, 15(1), 45–54. https://doi.org/10.14569/IJACSA.2024.0150701

Mishra, A. (2025). DevSecOps-driven security framework for CI/CD pipeline risk mitigation. International Journal of Computing and Engineering. https://doi.org/10.47941/ijce.3047

Osundare, O. S., & Ige, A. B. (2024). Developing a robust security framework for inter-bank data transfer systems in the financial service sector. International Journal of Scholarly Research in Science and Technology, 5(1), 29–37. https://doi.org/10.56781/ijsrst.2024.5.1.0029

Palamakula, S. N. (2025). AI-augmented DevSecOps toolchains for compliance-critical cloud applications in healthcare and finance. International Journal of Leading Research Publication, 6(7), 1686–1695. https://doi.org/10.70528/ijlrp.v6.i7.1686

Popentiu-Vladicescu, F., & Albeanu, G. (2022). Increasing system-of-systems dependability by DevSecOps. In Proceedings of the International Conference on Emerging Technologies for Computing, Communication and Control (pp. 1–6). IEEE. https://doi.org/10.1109/ICETECC56662.2022.10069468

Ramaj, X. (2022). A DevSecOps-enabled framework for risk management of critical infrastructures. In Proceedings of the International Conference on Software Engineering Companion (pp. 1–6). ACM. https://doi.org/10.1145/3510454.3517053

Santos, E. B. L. P. dos. (2021). Arquiteturas resilientes para infraestruturas críticas: Uma abordagem híbrida com engenharia de software, IA e monitoramento contínuo. RCMOS, 1(8), 1–12. https://doi.org/10.51473/rcmos.v1i8.2021.1243

Shilpi, S. (2025). Workflow-aware resilience in enterprise wire-payment systems: A practical framework for minimizing risk and downtime in production support. Journal of International Crisis and Risk Communication Research. https://doi.org/10.63278/jicrcr.vi.3253

Shin, D., Kim, J., Pawana, I. W. A. J., & Lee, S. (2025). Enhancing cloud-native DevSecOps: A Zero Trust approach for the financial sector. Computer Standards & Interfaces, 90, 103975. https://doi.org/10.1016/j.csi.2025.103975

Singh, P. (2022). Designing observable microservices for financial applications with built-in compliance. International Journal of Multidisciplinary Research and Growth Evaluation, 3(1), 1–8. https://doi.org/10.54660/.ijmrge.2022.3.1.1163-1168

Tabbassum, A., Malik, V., Singh, J., & Khan, R. (2024). Integrating site reliability engineering principles with DevSecOps for enhanced security posture. In Proceedings of the IEEE International Conference on Information Systems and Advanced Applications (pp. 1–6). IEEE. https://doi.org/10.1109/ICISAA62385.2024.10828869

Vijayaraghavan, S. K. J. (2025). Autonomous banking release pipelines: Balancing innovation and compliance in financial software delivery. European Journal of Computer Science and Information Technology, 13(1), 31–42. https://doi.org/10.37745/ejcsit.2013/vol13n13134142

Downloads

Published

2025-11-30

How to Cite

Dewi Sari, C., & Jarti , N. (2025). Framework Keandalan Sistem Informasi dengan Pendekatan DevSecOps pada Lembaga Keuangan. Jurnal Sistem Informasi Dan Teknologi Era, 1(2), 55–63. Retrieved from https://ejournal.globalcendekia.or.id/index.php/sitera/article/view/178