科研速览 · Science Skim继续刷下去 · Keep skimming →
◆ International Journal of Computer Applications Technology and Research2026-02-22· Computer science

DevSecOps Aware in Healthcare: SBOM-Driven Supply-Chain Assurance (SLSA) with Policy-Based Cost Guardrails and Continuous Security Validation

Nagarjuna Nellutla

原始摘要(英文原文)· Original abstract
Healthcare cloud systems must satisfy strict security and compliance controls while operating under constrained budgets.Traditional DevSecOps pipelines improve delivery velocity but often treat cost governance and supply-chain assurance as separate concerns, leaving gaps in artifact traceability, dependency risk visibility, and budget enforcement.This paper proposes a FinOps-aware DevSecOps pipeline for healthcare workloads that integrates software bill of materials (SBOM) generation, SLSA-aligned supplychain assurance checkpoints, and policy-as-code gates that jointly enforce security, compliance, and cost guardrails from build to deployment.The approach emphasizes auditable evidence, artifact integrity, and continuous validation to reduce release risk and cost drift without undermining delivery performance.
读原文 · Read the paper ↗

AI 追问PRO

登录后使用 AI 追问

讨论区

登录后参与讨论

相关论文 · Related

DevSecOps Aware in Healthcare: SBOM-Driven Supply-Chain Assurance (SLSA) with Policy-Based Cost Guardrails and Continuous Security Validation — 科研速览 Science Skim