AI-Augmented DevSecOps for Protecting U.S. Enterprise Software Supply Chains and Critical Digital Services

Authors

  • Mir Fawad Master of Science in Information Technology, Washington University of Science and Technology (WUST), Alexandria, Virginia, USA
  • Mir Jawad Yaqoob Master of Science in Information Technology Washington University of Science and Technology (WUST) Alexandria, Virginia, USA
  • khawar Muhammad Saad Master of Science in Information Technology Washington University of Science and Technology (WUST) Alexandria, Virginia, USA

Keywords:

AI-augmented DevSecOps, SBOM, software provenance, cybersecurity governance, critical digital services

Abstract

Modern enterprise applications rely on extensive third-party code, automated build systems, cloud-native infrastructure and rapidly changing vulnerability intelligence. Security controls are then spread out across the development, the software supply-chain assurance and production operations making it hard to relate some process deficiency with the subsequent impact seen in operations. This paper proposes an AI-driven DevSecOps approach focusing on governance with connections between Secure Software Development, Software Provenance, Runtime Observability, AI for analysis, Deterministic Policy Enforcement, and Responsible Human Decision Making. The framework is developed in a design-science methodology, and structured as the following layers: mission and regulatory context; AI-augmented DevSecOps pipeline; cloud-native runtime; unified observability and threat intelligence; AI intelligence and decision support; and policy governance with human oversight. It has a core principle that AI can correlate evidence, assess risk, and inform action but cannot override the requirements of policy, or authorize high impact operational decisions. A healthcare software-supply-chain scenario is the basis for an example of - a controlled rollback enabled by software bills of materials, provenance records, runtime telemetry, vulnerability intelligence, AI reasoning, policy checks, and human approval. It provides an end-to-end conceptual architecture, a decision model driven by policy, and a standards-based foundation for implementation. Since the evaluation is scenario based, the framework should be viewed as a design artifact and it is necessary to prototype and empirically validate it across multiple sectors.

Downloads

Published

2023-08-14

How to Cite

Fawad , M., Jawad Yaqoob, M., & Muhammad Saad , khawar . (2023). AI-Augmented DevSecOps for Protecting U.S. Enterprise Software Supply Chains and Critical Digital Services. American Journal of Engineering , Mechanics and Architecture (2993-2637), 4(8), 27-40. https://www.grnjournal.us/index.php/AJEMA/article/view/9666