Change search
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf
Securing Cloud-Native Applications (CNAs): A Case Study of Practices in a large IT Company
Blekinge Institute of Technology, Faculty of Computing, Department of Software Engineering.
Blekinge Institute of Technology, Faculty of Computing, Department of Software Engineering.
2025 (English)Independent thesis Advanced level (degree of Master (One Year)), 12 credits / 18 HE creditsStudent thesis
Abstract [en]

Background: Cloud-native applications (CNAs), built using microservices and deployed via container orchestration platforms like Kubernetes, have significantly transformed how software is developed, deployed, and scaled. This shift from traditional monolithic architectures introduces new complexities in the realm of security. Unlike conventional IT environments, CNAs require a fundamentally different approach to securing code, infrastructure, and runtime environments due to their distributed, dynamic nature.

Objectives: This thesis aims to explore the security practices employed in managing CNAs within a large IT organization. Specifically, it investigates how security responsibilities are shared across development, operations, and security teams using the 4Cs security framework — Code, Container, Cluster, and Cloud. The study further seeks to evaluate the effectiveness of modern DevSecOps practices, tools, and processes, while identifying ongoing security challenges faced by organizations operating in a cloud-native landscape.

Method: The research adopts a case study methodology grounded in software engineering practices. Data collection was carried out through semi-structured interviews with DevSecOps professionals and a systematic review of organizations’ archival documents. To contextualize and validate these findings, a supplementary review of grey literature and industry security standards, such as OWASP, CIS Benchmarks, and DISA STIGs, was conducted to highlight common practices, gaps, and divergences in industry implementations.

Results: The study reveals that while there is widespread adoption of automation, shift-left security, policy-as-code, and runtime monitoring, their effectiveness is often moderated by organizational culture and the level of ongoing training. Key challenges include balancing development speed with security rigor, managing alert fatigue, and responding to constantly evolving threats and misconfigurations. The research concludes with actionable recommendations that emphasize the importance of adaptive security strategies, continuous alignment with emerging standards, and the role of cross-functional collaboration in securing cloud-native environments.

Place, publisher, year, edition, pages
2025. , p. 68
Keywords [en]
Cloud Native Application, Security, Kubernetes, DevSecOps
National Category
Software Engineering
Identifiers
URN: urn:nbn:se:bth-28266OAI: oai:DiVA.org:bth-28266DiVA, id: diva2:1980200
Subject / course
PA2592 Research Methods and Master's Thesis (60 credits) in Software Engineering for Professionals
Educational program
PAASA Master's Programme in Software Engineering 60,0 hp
Supervisors
Examiners
Available from: 2025-07-03 Created: 2025-07-01 Last updated: 2025-09-30Bibliographically approved

Open Access in DiVA

fulltext(843 kB)632 downloads
File information
File name FULLTEXT01.pdfFile size 843 kBChecksum SHA-512
56c67bca7f48249593f042fadf561e165b44b1ac2dabb764796cbc9aa14cdfcc3ba23223d7fcb615cb155d36465b043e0b5bb05abeac87a67a449f0f54050f1b
Type fulltextMimetype application/pdf

By organisation
Department of Software Engineering
Software Engineering

Search outside of DiVA

GoogleGoogle Scholar
Total: 636 downloads
The number of downloads is the sum of all downloads of full texts. It may include eg previous versions that are now no longer available

urn-nbn

Altmetric score

urn-nbn
Total: 599 hits
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf