IJCATR Volume 13 Issue 8

DevSecOps Aware in Healthcare: SBOM-Driven Supply-Chain Assurance (SLSA) with Policy-Based Cost Guardrails and Continuous Security Validation

Nagarjuna Nellutla
10.7753/IJCATR1308.1021
keywords : FinOps, DevSecOps, Healthcare Cloud, SBOM, Supply Chain Security, SLSA, Policy-as-Code, Compliance Automation, Cloud Cost Governance

PDF
Healthcare cloud systems must satisfy strict security and compliance controls while operating under constrained budgets. Traditional DevSecOps pipelines improve delivery velocity but often treat cost governance and supply-chain assurance as separate concerns, leaving gaps in artifact traceability, dependency risk visibility, and budget enforcement. This paper proposes a FinOps-aware DevSecOps pipeline for healthcare workloads that integrates software bill of materials (SBOM) generation, SLSA-aligned supply-chain assurance checkpoints, and policy-as-code gates that jointly enforce security, compliance, and cost guardrails from build to deployment. The approach emphasizes auditable evidence, artifact integrity, and continuous validation to reduce release risk and cost drift without undermining delivery performance.
@artical{n1382024ijcatr13081021,
Title = "DevSecOps Aware in Healthcare: SBOM-Driven Supply-Chain Assurance (SLSA) with Policy-Based Cost Guardrails and Continuous Security Validation",
Journal ="International Journal of Computer Applications Technology and Research (IJCATR)",
Volume = "13",
Issue ="8",
Pages ="244 - 250",
Year = "2024",
Authors ="Nagarjuna Nellutla"}