NRI Secure Technologies, Ltd. (hereinafter, NRI Secure) announces the addition of the 'DevSecOps Maturity Assessment and Roadmap Development Service' (hereinafter, this service) to its 'DevSecOps Implementation Support Services' lineup, effective today.

Growing Importance of DevSecOps Amid Accelerated Development and AI Adoption

In recent years, the importance of 'DevSecOps'—integrating security measures early into the development process—has increased due to accelerated software development and expanded cloud adoption. However, as project scales grow, challenges arise in prioritizing security measures and formulating execution plans due to the increasing number of stakeholders, processes, and systems involved. Furthermore, the widespread use of generative AI in software development has introduced new concerns, such as code validity verification and license management.

Main Service Processes and Features

To address these challenges, NRI Secure leverages the expertise of security consultants and the latest threat intelligence to analyze and visualize the current state of development processes, organizational structures, operational models, and technologies in use, thereby assessing DevSecOps maturity. Based on this analysis, the service clearly identifies the priority of necessary security measures and presents them as an actionable roadmap. This enables easier sharing of the importance of DevSecOps and required countermeasures with executive leadership, supporting consensus-building from development teams to top management.

Figure: Challenges in DevSecOps Implementation and Key Support Provided by This Service

The main service delivery process is as follows:

1. Interviews on Development Projects

To understand the DevSecOps maturity level within enterprises and organizations, the service references the framework 'DevSecOps Maturity Model (DSOMM)' provided by OWASP [ii], consolidating information on development processes, organizational structures, and operational status.

2. Analysis and Visualization of Current DevSecOps Maturity

Based on interview results, the service analyzes DevSecOps maturity and visualizes the current achievement status. It evaluates whether existing security measures are effectively functioning within the development process, taking into account risks such as vulnerability introduction and license management in AI-assisted development.

3. Creation of a Security Countermeasure Roadmap

Security consultants prioritize measures based on risk, impact, and effectiveness, presenting a clear roadmap outlining necessary actions and their implementation sequence.

4. Presentation and Reporting of Evaluation Results and Roadmap

Through the creation of detailed reports and executive summaries, as well as presentation meetings, the service supports improved understanding within development departments and enables swift decision-making by executive leadership.

Additionally, during the execution phase following roadmap development, the service can be combined with other offerings from the 'DevSecOps Implementation Support Services' to provide continuous support for implementing measures and institutionalizing DevSecOps practices.

For more details on this service, please visit:

https://www.nri-secure.co.jp/service/consulting/devsecops

NRI Secure will continue to provide a wide range of products and services to support information security initiatives for enterprises and organizations, contributing to the realization of safe and secure information systems and society on a global scale.

[i] DevSecOps: A development methodology that integrates security (Security) into 'DevOps,' where development (Development) and operations (Operations) collaborate. It aims to maintain development speed while ensuring security. For more information on DevSecOps and maturity assessment methods, please refer to the following blog: https://www.nri-secure.co.jp/blog/devsecops-road-map

[ii] OWASP DevSecOps Maturity Model (DSOMM): A framework (maturity model) designed to evaluate and improve the extent to which security measures are integrated and automated within the software development lifecycle. For details, please visit: https://owasp.org/www-project-devsecops-maturity-model/

[Reference]

Upcoming Seminar Announcement

NRI Secure Technologies, Ltd. will host the 'Seminar on Solving Challenges in DevSecOps Practice,' which explains challenges and solutions related to DevSecOps adoption and operations.

Organizer: NRI Secure Technologies, Ltd.

Date and Time: July 22, 2026 (Wed), 13:00–14:00

Format: Online

Participation Fee: Free

Speakers: Takayoshi Ueno, Ryu Amano – Security Consultants, NRI Secure Technologies, Ltd.

* Seminar content is subject to change without prior notice. For details, please visit: https://www.nri-secure.co.jp/seminar/2026/0722devsecops

FACT BOX

  • Source: PR TIMES
  • Category: New Product
  • Organizations: OWASP