DevSecOps in Software Development in Indonesia
Keywords:
DevSecOps, Software Security, Digital Transformation, Indonesia, Cybersecurity ResilienceAbstract
The rapid expansion of digital transformation in Indonesia has heightened the urgency of building software systems that are secure by design, not just by inspection. Traditional approaches that position security as a postdevelopment gate are insufficient in an environment where national cybersecurity incidents grew 391% between 2019 and 2023, peaking at over 1.6 million events (BSSN, 2024). This paper investigates DevSecOps, an integrated framework that embeds security throughout the software development lifecycle as a strategic response to this challenge. Using an explanatory sequential mixed-methods design, we combine a systematic literature review with secondary quantitative data from national reports (BSSN, OJK, KOMINFO) and global benchmarks (Gartner, DORA, IBM Security). Findings show that Indonesian DevSecOps adoption lags global benchmarks by 11–23 percentage points across all sectors, and that mature DevSecOps practice reduces breach costs by 55% and mean time to detect incidents by 63%. The paper proposes the Indonesia DevSecOps Adoption Model (IDAM) a four-pillar framework spanning human capital, technical infrastructure, regulatory alignment, and organizational culture aligned with SDG 9 and SDG 16. DevSecOps adoption is framed not as a technical preference but as a development governance imperative for Indonesia’s digital future.
