Print as pdf if you want a pdf! If you want a nicer printout, click off the browser's automatically added header and footer.
Blekinge Institute of Technology
Department of Software Engineering
Revision: 2
Reg.no: BTH-4.1.14-0712-2026
DevSecOps - Development, security and operations
DevSecOps - Development, security and operations
6 credits (6 högskolepoäng)
Course code: PA2601
Main field of study: Software Engineering
Disciplinary domain: Technology
Education level: Second-cycle
Specialization: A1N - Second cycle, has only first-cycle course/s as entry requirements
Language of instruction: English
Applies from: 2026-08-25
Approved: 2026-08-25
This course is established by Dean 2023-05-08. The course syllabus is approved by Head of Department of Software Engineering 2026-08-25 and applies from 2026-08-25.
Admission to the course requires Bachelor of Science in Engineering or Bachelor of Science in a technical field, or at least 60 credits in technology, computer science, software engineering, or equivalent. At least 20 credits should consist of courses in Computer Science, Software Engineering or equivalent and include courses in programming, 5 credits, algorithms and data structures, 5 credits, databases, 5 credits and a project course or software engineering course, 5 credits. English 6.
The purpose of the course is to provide students with an understanding of how security can be integrated into continuous software engineering processes. Students will learn methods and techniques for tailoring established security practices to the context of agile software development and DevOps.
The course aims to develop students’ ability to analyze security-related challenges in software development and operation, select and justify appropriate security practices, and evaluate how evaluate how security can be integrated into software development, delivery, and operation processes in different organizational contexts.
The course covers principles, practices, tools, roles, and organizational aspects for integrating security into software development and operations (DevSecOps). It addresses security challenges across software development, delivery, and operations processes, as well as methods for identifying, analyzing, and managing security-related risks. Particular emphasis is placed on selecting, adapting, and evaluating security practices in relation to technical and organizational contexts.
The following learning outcomes are examined in the course:
On completion of the course, the student will be able to:
On completion of the course, the student will be able to:
On completion of the course, the student will be able to:
The course is based on a combination of self-study, sessions, and project work. Students are expected to prepare before scheduled sessions by studying shared course material (e.g., assigned literature, videos). The sessions provide opportunities to discuss and analyze concepts, methods, and practices related to DevSecOps and secure software development. The learning activities emphasize the analysis of realistic software development contexts and the discussion of security challenges, trade-offs, and improvement strategies.
Through project work, students apply these concepts and methods to industry-inspired case studies in groups. The project provides opportunities to analyze security-related challenges, propose and justify suitable security improvements, and evaluate their impact in relation to technical and organizational conditions. The project work includes discussion of proposed solutions.
Modes of examinations of the course
| Code | Module | Credit | Grade |
| 2705 | Project Assignment | 3 credits | AF |
| 2715 | On-Campus Examination | 3 credits | AF |
The course will be graded A Excellent, B Very good, C Good, D Satisfactory, E Sufficient, FX Failed result, a little more work required, F Fail.
The examiner may carry out oral follow-up of written examinations.
To get a passing grade for the course, all modules must be approved. The final grade of the course is the average of the grades of the modules.
The information before the start of the course states the assessment criteria and make explicit in which modes of examination that the learning outcomes are assessed.
An examiner can, after consulting the Disability Advisor at BTH, decide on a customized examination form for a student with a long-term disability to be provided with an examination equivalent to one given to a student who is not disabled.
The course evaluation should be carried out in line with BTH:s course evaluation template and process.
The course can form part of a degree but not together with another course the content of which completely or partly corresponds with the contents of this course.
Bird, J.: DevOpsSec: Securing Software through Continuous Delivery. O’Reilly Media, Inc. (2016). ISBN: 978-1-491-95899-5
Bell, L., Brunton-Spall, M., Smith, R., Bird, J.: Agile Application Security: Enabling Security in a Continuous Delivery Pipeline. O’Reilly Media, Inc. (2017). ISBN: 978-1-491-93884-3
Suehring, S.: Learning DevSecOps: A Practical Guide to Processes and Tools. O’Reilly Media, Inc. (2024). ISBN: 978-1-098-14486-9