
International Research Journal of Engineering and Technology (IRJET) e-ISSN: 2395-0056
Volume: 13 Issue: 04 | Apr 2026 www.irjet.net p-ISSN: 2395-0072
![]()

International Research Journal of Engineering and Technology (IRJET) e-ISSN: 2395-0056
Volume: 13 Issue: 04 | Apr 2026 www.irjet.net p-ISSN: 2395-0072
Bulupiy Galati Joel
Computer Science Faculty, Dept. Network & Security, Université Protestante au Congo, Democratic Republic of The Congo ***
Abstract – The rapidevolutionofsoftwaredevelopmenthas intensified cybersecurity challenges across web application, embedded systems, distributed architectures, Internet of Things (IoT) andartificialintelligence solution. Intraditional approaches, security is often treated as a final stage in the Software Development Life Cycle (SDLC), resulting in increasedvulnerabilityrisks,higherremediationcosts,delayed deployments, and potential regulatory penalties. This paper advocates a Security-Firstapproach,whichintegratessecurity practices form the initial phases of the SDLC rather than as a reactive measure. It examines major SDLC methodologies, evaluation their characteristics,usecases,securityintegration potential and optimal application contexts. Drawing on influential standards such as the NIST Secure Software Development Framework (SSDF) and Secure SDLC (SSDLC), the study highlights the benefits of proactive security integration. Results indicate that adopting a Security-First mindset significantly reduces risks while preserving system performances and availability.
Key Words: Software Development Life Cycle (SDLC), Security-First, DevSecOps, Secure SDLC, NIST SSDF, Threat Modeling, CIA Triad
Over the past three decades, software development has advanced at an extraordinary pace. This rapid growth requiresa methodical andproactiveapproachtosecuring the entire information system while ensuring proper functionalityandavailability.
Inlightofemergingdailythreats,it isessential toadopt a Security-First methodology. This approach promotes incorporating security layers from the beginning of the software development process, rather than threating security as a final security or corrective measure after a technicalfailureoranattack.
Practically,manytraditionalSDLCmodelsdonotintegrate securityindetailedandsystematicmanner.Toaddressthis gap, the NIST Secure Software Development Framework (SSDF)isrecommendedasarobustmethodforembedding securitypracticesacrosseveryphaseoftheSDLC[1]
To implement this strategy effectively the Secure SDLC (SSDLC) is employed. Unlike classical methods that defer security and testing to the end of the cycle, SSDLC incorporates security principles, architectural decisions, tools,andproceduresfrom theoutset[2]. Building secure
foundationsfromthestartsisvitalforpreventingincidents, this approach applies to diverse projects, including web applications, embedded software, disturbed systems, network programming, Internet of Things (IOT), and artificialintelligencesystems.
SeveralSDLCmethodologiesexist.Thissectionanalyseseach accordingtofourcriteria:characteristics,usecases,security integration and recommended application contexts. The comparisonissummarizedinthetablebelow.
Table -1: ComparisonofSDLCMethodologieswith Security-FirstIntegration
Methodo logy Characte ristics Use Cases Security Integration (SecurityFirst/DevS ecOPs) Whento use
Waterfal l Linear and sequenti al;each phase mustbe complete dbefore thenext.
Iterative
Progressi ve develop ment thought repeated cycles.
Projects with stable require; netsand welldefined scope.
Projects requirin guser feedback and moderat e require ment evolutio n.
Agile
Combine incremen taland iterative approach eswith short sprints.
Dynamic s projects, start-ups, mobile and web applicati ons with changing
Security typically addedlate; difficultto retrofit changes
Security integrated ineach iteration (threat modelling andtesting percycle)
Simple projects with minimal changes.
Medium -sized projects with gradual changes.
Highly effective with DevSecOps ;security incorporat edinevery sprint Fastpaced environ ments needing rapid delivery

International Research Journal of Engineering and Technology (IRJET) e-ISSN: 2395-0056
Volume: 13 Issue: 04 | Apr 2026 www.irjet.net p-ISSN: 2395-0072
V-Model Waterfall extensio nwith parallel verificati onand validatio n
RAD (Rapid Applicati on
requirem ents
Safetycritical, suitable for finance, aerospac e
Develop ment) Rapid prototypi ngwith intensive use feedback Small projects orMVPs needing quick producti on deploym ent
Spiral Iterative with strong risk analysis ineach planning from planning, risk, engineeri ngto evaluatio n
DevOps Integrati onof Develop mentand Operatio nswith CI/CD and automati on[5]
Highriskand complex projects, like embedde d systems, military
Security testing plannedin parallel witheach developme ntphase Projects requirin g rigorous validatio nand stable require ments
Basic security controls included fromearly prototypes [3]

Smallscale projects with tight deadline sand strong user involve ment
Early threat modeling andrisk mitigation inevery spiral[4] Projects with high technica lor security risks
Security must also be addressed through standards and norms,notonlyasatechnical concern,acommonmistake madebymanyorganizationsduringsoftwaredevelopment. Enterprisesshouldintegratesecurityacrossalldimensions suchastechnical,organizationalandnormativefromproject initiation[6][7].
ThisleadstotheadoptionofSSDLCwhichembedsnecessary security requirements into every phase of development process, from design troughdeployment and maintenance [8].
No software or information system in the world, regardlessofitssophistication,is100%immunetoattacks. ThisrealityhaspopularizedtheZeroTrustconcept,whichis based on the principle of « Never Trust, always verify.” It assumesthatthreatsmayexistbothinsideandoutsidethe traditionalsecurityperimeter[9].
Appropriate security layers must be implemented to ensurebetterperformanceandhighavailabilitywithatarget of99.9%uptime.However,excessivesecuritymechanisms canoverburdenthesoftware,increaseresourceconsumption, complicatemaintenanceandcontrol,andultimatelyhinder itsproperfunctioninganduseexperience.
Cloudnative applicati ons, microser vices, and frequent deploym ent
Increme ntal Develop ment by functiona lmodules delivered sequentia lly Large projects divisible into delivera ble modules
Excellent for DevSecOps : automated security scanning, continuous monitoring
Security testing appliedto each module
Cloud environ ments requirin gspeed, reliabilit y,and continuo us security
Large systems where partial early delivery is needed
ASecurity-Firstapproach,guidedbyframeworkssuchasthe NIST SSDF, seeks an optimal balance: proactive security integration from the earliest stages while eliminating unnecessarycomplexconfigurations[10].

This figure illustrates the concept effectively. Security controls are applied at each stage and component of the system,withverificationrequiredbeforemovingfromone stagetoanother.Eachzoneisseparatedbycontrolgates.

International Research Journal of Engineering and Technology (IRJET) e-ISSN: 2395-0056
Volume: 13 Issue: 04 | Apr 2026 www.irjet.net p-ISSN: 2395-0072
In the SDLC, even when emphasizing a Security-First approach,itisessentialtoensuretheavailabilityoftheentire information system, including during attacks. The system mustremainresilient.Therefore,rigorousriskmanagement and the handling of potential failures are strongly recommendedthroughthedevelopmentcycle.
Technologically Security rests on the CIA Triad (Confidentiality,Integrity,Availability):
Confidentiality: Protects data from unauthorised access. Achieving a high protection level, close to 99.9%,strengthensuserconfidenceinthesecurity of their personal data. This requirement is supported by international standards such as ISO 270001, which defines requirements for an InformationSecurityManagementSystemandPCI DSS (Payment Card Industry Data Security Standard), particularly relevant for systems handling payment card data and baking transactions.
Integrity: Ensures the accuracy, truthfulness, and non-alterationofdatathroughoutitslifecycleinthe system. It prevents unauthorised of fraudulent modifications.
Availability:Guaranteesthatauthorizeduserscan accessinformationandserviceswhenneeded,even understressorinthepresenceofattacks.
Amajorrisktopreventis the Man-in-the-Middle (MITM) attack. In this technique, as attacker secretly position themselves between two parties without their knowledge. Actingasaproxy,theattackercanintercept,eavesdroponor modifycommunicationsinRealtime.Thiscanleadtomassive dataleaksoralterationofexchanges,directlycompromising heconfidentialityandintegrityofdataflowingthroughthe system[11].

Asshowninthefigure,wehavethreeactorsinvolvedand behavingasexpectedinthetablebelow:
Table -2: ActorsactionsinMITMAttack
User Send requests to the server to retrieve, create,ormodifyinformation
Server Stores and processes information may triggereventsbasedinconfigurations
Man-in-theMiddle Uninvitedactorwhousesidentityspoofing tosteadormanipulatesdatatransiting
To encounter these threats, the Security-First approach recommends integration appropriate controls, such as encryption and authentication from the design phase and acrossalllayersoftheSDLC.

Asillustratedinthefiguresecurityisenforcedonbothside trough certificate verification by each action before proceedingwithdeeperoperations.Thisprovidesadditional protectingfordataintransit[12].
3. Security-First Implementation in the Traditional SDLC Phases
ThetraditionalSDLCconsistsofsevenwell-definedphases.A Security-Firstapproach,informedbytheNISTSSDFandthe foundationalprinciplesoutlinedbyGaryMcGraw’s,requires that security activities be embedded in each phase rather than added as an afterthought. The following paragraphs describe each phase and the corresponding Security-First practices.

International Research Journal of Engineering and Technology (IRJET) e-ISSN: 2395-0056
Volume: 13 Issue: 04 | Apr 2026 www.irjet.net p-ISSN: 2395-0072

1. Planning: conduct initial risk assessments and define high-level security requirements in alignmentwithbusinessobjectivesandcompliance obligations such as ISO 27001. Identify potential threatsandallocateresourcesforsecurityactivities fromtheoutset.
2. Requirements Analysis: specify both functional andnon-functionalsecurityrequirementsusingthe CIATriad.Performpreliminarythreatmodelingto capture needs early and ensure they are documentedaspartoftherequirementsbaseline.
3. Design: apply secure architecture principles and conduct detailed threat modeling, by using methodologieslikeSTRIDE (Spoofing,Tampering, Repudiation, Information Disclosure, Elevation of Privilege).Designforleastprivilege,securedefaults, anddefence-in-depthtoeliminatevulnerabilitiesat thearchitecturallevel[13].
4. Development: follow secure coding standards, performstaticapplicationsecuritytesting(SAST), and conduct peer code reviews with a security focus.Automatedtoolsareusedtodetectcommon vulnerabilitiesbeforetheyreachlaterstages.
5. Testing: integrate dynamic application security testing(DAST),penetrationtesting,andfuzztesting. Verifythatsecuritycontrolsfunctioncorrectlyand do not introduce unacceptable performance degradation.
6. Deployment: implement secure configuration management,infrastructure-as-codescanning,and hardenedCI/CDpipelines.Conductafinalsecurity reviewandapplyallnecessaryhardeningmeasures beforerelease.
7. Maintenance & Support: establish continuous monitoring, vulnerability management, timely pathing, and incident response capabilities. Risks are regularly reassessed and security controls
updated as the system evolves or new threats emerge.
Thisstructuredintegration,supportedbytheNISTSSDFand McGraw’stouchpointframework,shiftssecurityleftinthe developmentprocess[14],reduceslong-termremediation costs,andsignificantlyenhancesoverallsystemresilience.
AdoptionofaSecurity-Firstapproachshiftssecurityfroma reactive constraint to a proactive strength integrated into the development process. By combining suitable SDLC methodologies with frameworks like NIST SSDF and respecting the CIA Triad, organization scan significantly reduces risks while maintaining performance and availability.Weareaimingtoimprovefutureworktoinclude AI-drivensecurityinDevSecOpspipelines,andalsoNetwork Security.
[1] S.Murugiah,S.KarenandD.Donna,"SecureSoftware Development Framework (SSDF)," NIST Special Publication800-218,2022.
[2] A.Mustyala,"Security-FirstDevOps:BestPracticesfor Safeguarding Continuous Delivery Pipelines," ISAR Journal ofMultidisciplinaryResearch andStudies, vol.1, no.4,p.3,2023.
[3] G. Aradhyula, “The security-first agile playbook: Embedding DevSecOps into program management,” WorldJournalofAdvanced EngineeringTechnologyand Sciences, vol.16,no.03,p.17,2025.
[4] OWASP,“DevGuideOwasp,”Owasp,[Online].Available: https://devguide.owasp.org/en/02-foundations/02secure-development/.[Accessed28032026].
[5] J. Twist, "Zuplo," 05 March 2025. [Online]. Available: https://zuplo.com/learning-center/mitm-attackprevention-guide.[Accessed28March2026].
[6] G. McGraw, Software Security: Building Security In, Addison-Wesley,2006.
[7] N. Davis, Secure Software Development Life Cycle Processes: A Technology Scouting Report, Carnegie MellonUniversitySoftwareEngineeringInstitute,2005.
[8] JFrog, "JFrog," JFrog, [Online]. Available: https://jfrog.com/learn/devsecops/ssdlc-secure-

International Research Journal of Engineering and Technology (IRJET) e-ISSN: 2395-0056
Volume: 13 Issue: 04 | Apr 2026 www.irjet.net p-ISSN: 2395-0072
software-development-lifecycle/.[Accessed28March 2026].
[9] OWASP,"OWASP," OWASP, 2022.[Online].Available: https://owasp.org/www-project-samm/.[Accessed28 March2026].
[10] P. Belagatti, "The New Stack," 29 10 2021. [Online]. Available:https://thenewstack.io/zero-trust-securityand-the-software-development-lifecycle.[Accessed28 March2026].
[11] Microsoft, “Microsoft,” [Online]. Available: https://www.microsoft.com/enus/securityengineering/sdl/practices. [Accessed 28 March2026].
[12] M.Birchall,“UsNorton,”Norton,26032020.[Online] Available:https://us.norton.com/blog/wifi/what-is-aman-in-the-middle-attack.[Accessed28March2026].
[13] L.Microsof,"LearnMicrosoft,"Microsoft,19032026. [Online]. Available: https://learn.microsoft.com/enus/azure/well-architected/security/securedevelopment-lifecycle.[Accessed28March2026].
[14] D.Puzas,"NewRelic,"NewRelic,23052025.[Online]. Available:https://newrelic.com/blog/security/how-toleverage-security-in-your-software-developmentlifecycle.[Accessed28March2026].
BIOGRAPHIES

Software Engineer, Bachelor’s DegreeinSoftwareEngineering from Université Protestante au Congo
ResearcherinComputerScience Master’sStudentspecializingin Cybersecurity, Network and Systems