Framework Keandalan Sistem Informasi dengan Pendekatan DevSecOps pada Lembaga Keuangan
Keywords:
sistem informasi, Framework, DevSecOps, Lembaga KeuanganAbstract
Keandalan sistem informasi merupakan prasyarat utama bagi lembaga keuangan dalam menjaga stabilitas operasional, keamanan data, dan kepercayaan publik di tengah percepatan transformasi digital. Kompleksitas arsitektur berbasis cloud, otomatisasi layanan, serta integrasi sistem yang semakin luas meningkatkan eksposur risiko keamanan dan gangguan layanan. Pendekatan pengelolaan sistem informasi yang terfragmentasi antara pengembangan, operasional, dan keamanan terbukti tidak lagi memadai. Penelitian ini bertujuan untuk mengembangkan framework keandalan sistem informasi dengan pendekatan DevSecOps yang kontekstual bagi lembaga keuangan. Penelitian menggunakan pendekatan kualitatif dengan desain pengembangan kerangka konseptual berbasis studi literatur sistematis terhadap publikasi ilmiah bereputasi yang membahas DevSecOps, keandalan sistem, resiliensi digital, dan sistem keuangan. Data dianalisis melalui analisis tematik dan sintesis konseptual untuk mengidentifikasi dimensi utama keandalan sistem serta relasinya dengan praktik DevSecOps. Hasil penelitian menunjukkan bahwa keandalan sistem informasi tidak hanya ditentukan oleh kontrol keamanan teknis, tetapi oleh integrasi berkelanjutan antara DevSecOps, prinsip Zero Trust, observabilitas, dan Site Reliability Engineering. Integrasi tersebut membentuk mekanisme pencegahan, deteksi, respons, dan pemulihan yang saling memperkuat. Penelitian ini menghasilkan framework keandalan sistem informasi berbasis DevSecOps yang menempatkan keamanan, resiliensi, dan kepatuhan sebagai bagian struktural dari siklus hidup sistem. Framework ini diharapkan menjadi acuan strategis dan operasional bagi lembaga keuangan dalam membangun sistem informasi yang andal, adaptif, dan berkelanjutan
References
Alonso, J., Piliszek, R., Cankar, M., & Truscan, D. (2023). Embracing infrastructure as code through the DevSecOps philosophy: Concepts, challenges, and a reference framework. IEEE Software, 40(1), 68–76. https://doi.org/10.1109/MS.2022.3212194
Aradhyula, G. (2025). The security-first agile playbook: Embedding DevSecOps into program management practices. World Journal of Advanced Engineering Technology and Sciences, 16(3), 1313–1322. https://doi.org/10.30574/wjaets.2025.16.3.1313
Arivuchudar, R. (2022). Continuous security in DevOps: Implementing DevSecOps for FinTech. International Journal for Multidisciplinary Research, 4(2), 12061. https://doi.org/10.36948/ijfmr.2022.v04i02.12061
Brighente, A., Burato, E., & Conti, M. (2025). Are you sure that is secure? Assessing organizations security readiness via a DevSecOps maturity model. In Proceedings of the IEEE European Symposium on Security and Privacy Workshops (pp. 1–10). IEEE. https://doi.org/10.1109/EuroSPW67616.2025.00068
Coston, I., Hezel, K. D., Plotnizky, E., & Glick, R. (2025). Enhancing secure software development with AZTRM-D: An AI-integrated approach combining DevSecOps, risk management, and Zero Trust. Applied Sciences, 15(15), 8163. https://doi.org/10.3390/app15158163
Daah, C., Qureshi, A., & Awan, I. (2023). Zero Trust model implementation considerations in financial institutions: A proposed framework. In Proceedings of the International Conference on Future Cloud Computing and Data Analytics (pp. 1–8). IEEE. https://doi.org/10.1109/FiCloud58648.2023.00019
Dasanayake, S. D. L. V., Senanayake, J., & Wijayanayake, W. M. J. I. (2025). DevSecOps for continuous security in trading software application development: A systematic literature review. Journal of Desk Research Review and Analysis, 2(2), 1–15. https://doi.org/10.4038/jdrra.v2i2.52
David, P., Kushwaha, M. K., & Suseela, G. (2024). DevSecOps in finance: Strengthening the security model of applications. In Proceedings of the IEEE International Conference on Distributed Computing and Electrical Circuits and Systems (pp. 1–6). IEEE. https://doi.org/10.1109/ICDECS59733.2023.10502917
Enoiu, E. P., Truscan, D., Sadovykh, A., & Gallina, B. (2023). VeriDevOps software methodology: Security verification and validation for DevOps practices. ACM. https://doi.org/10.1145/3600160.3605054
Gupta, A. (2022). An integrated framework for DevSecOps adoption. International Journal of Computer Trends and Technology, 70(6), 102–108. https://doi.org/10.14445/22312803/IJCTT-V70I6P102
Halliday, N. (2023). A conceptual framework for financial network resilience integrating cybersecurity, risk management, and digital infrastructure stability. Journal of Digital Resilience and Risk Analysis, 3(2), 45–58. https://doi.org/10.62225/2583049x.2023.3.2.4887
Kamlakshya, T. (2023). Enhancing cybersecurity in digital banking transformation: A framework for secure payment ecosystems. World Journal of Advanced Engineering Technology and Sciences, 10(2), 309–318. https://doi.org/10.30574/wjaets.2023.10.2.0309
Kohli, S. (2025). Financial resilience: Cloud architecture and AI risk integration. Journal of International Crisis and Risk Communication Research. https://doi.org/10.63278/jicrcr.vi.3254
Kushwaha, M. K., David, P., & Suseela, G. (2024). Automation and DevSecOps: Streamlining security measures in financial systems. IEEE CONECCT Proceedings, 1–6. https://doi.org/10.1109/CONECCT62155.2024.10677271
Mahida, A. (2024). Integrating observability with DevOps practices in financial services technologies: A study on enhancing software development and operational resilience. International Journal of Advanced Computer Science and Applications, 15(1), 45–54. https://doi.org/10.14569/IJACSA.2024.0150701
Mishra, A. (2025). DevSecOps-driven security framework for CI/CD pipeline risk mitigation. International Journal of Computing and Engineering. https://doi.org/10.47941/ijce.3047
Osundare, O. S., & Ige, A. B. (2024). Developing a robust security framework for inter-bank data transfer systems in the financial service sector. International Journal of Scholarly Research in Science and Technology, 5(1), 29–37. https://doi.org/10.56781/ijsrst.2024.5.1.0029
Palamakula, S. N. (2025). AI-augmented DevSecOps toolchains for compliance-critical cloud applications in healthcare and finance. International Journal of Leading Research Publication, 6(7), 1686–1695. https://doi.org/10.70528/ijlrp.v6.i7.1686
Popentiu-Vladicescu, F., & Albeanu, G. (2022). Increasing system-of-systems dependability by DevSecOps. In Proceedings of the International Conference on Emerging Technologies for Computing, Communication and Control (pp. 1–6). IEEE. https://doi.org/10.1109/ICETECC56662.2022.10069468
Ramaj, X. (2022). A DevSecOps-enabled framework for risk management of critical infrastructures. In Proceedings of the International Conference on Software Engineering Companion (pp. 1–6). ACM. https://doi.org/10.1145/3510454.3517053
Santos, E. B. L. P. dos. (2021). Arquiteturas resilientes para infraestruturas críticas: Uma abordagem híbrida com engenharia de software, IA e monitoramento contínuo. RCMOS, 1(8), 1–12. https://doi.org/10.51473/rcmos.v1i8.2021.1243
Shilpi, S. (2025). Workflow-aware resilience in enterprise wire-payment systems: A practical framework for minimizing risk and downtime in production support. Journal of International Crisis and Risk Communication Research. https://doi.org/10.63278/jicrcr.vi.3253
Shin, D., Kim, J., Pawana, I. W. A. J., & Lee, S. (2025). Enhancing cloud-native DevSecOps: A Zero Trust approach for the financial sector. Computer Standards & Interfaces, 90, 103975. https://doi.org/10.1016/j.csi.2025.103975
Singh, P. (2022). Designing observable microservices for financial applications with built-in compliance. International Journal of Multidisciplinary Research and Growth Evaluation, 3(1), 1–8. https://doi.org/10.54660/.ijmrge.2022.3.1.1163-1168
Tabbassum, A., Malik, V., Singh, J., & Khan, R. (2024). Integrating site reliability engineering principles with DevSecOps for enhanced security posture. In Proceedings of the IEEE International Conference on Information Systems and Advanced Applications (pp. 1–6). IEEE. https://doi.org/10.1109/ICISAA62385.2024.10828869
Vijayaraghavan, S. K. J. (2025). Autonomous banking release pipelines: Balancing innovation and compliance in financial software delivery. European Journal of Computer Science and Information Technology, 13(1), 31–42. https://doi.org/10.37745/ejcsit.2013/vol13n13134142
Downloads
Published
How to Cite
Issue
Section
License
Copyright (c) 2026 Citra Dewi Sari, Nanda Jarti

This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License.


