<?xml version="1.0" encoding="UTF-8"?><!DOCTYPE article PUBLIC "-//NLM//DTD Journal Publishing DTD v3.0 20080202//EN" "http://dtd.nlm.nih.gov/publishing/3.0/journalpublishing3.dtd">
<article xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink" dtd-version="3.0" xml:lang="en" article-type="research article">
 <front>
  <journal-meta>
   <journal-id journal-id-type="publisher-id">
    jsea
   </journal-id>
   <journal-title-group>
    <journal-title>
     Journal of Software Engineering and Applications
    </journal-title>
   </journal-title-group>
   <issn pub-type="epub">
    1945-3116
   </issn>
   <issn publication-format="print">
    1945-3124
   </issn>
   <publisher>
    <publisher-name>
     Scientific Research Publishing
    </publisher-name>
   </publisher>
  </journal-meta>
  <article-meta>
   <article-id pub-id-type="doi">
    10.4236/jsea.2025.189019
   </article-id>
   <article-id pub-id-type="publisher-id">
    jsea-145228
   </article-id>
   <article-categories>
    <subj-group subj-group-type="heading">
     <subject>
      Articles
     </subject>
    </subj-group>
    <subj-group subj-group-type="Discipline-v2">
     <subject>
      Computer Science 
     </subject>
     <subject>
       Communications
     </subject>
    </subj-group>
   </article-categories>
   <title-group>
    Navigating Continuous Improvement: An In-Depth Analysis of Lean-Agile and DevOps Maturity Models
   </title-group>
   <contrib-group>
    <contrib contrib-type="author" xlink:type="simple">
     <name name-style="western">
      <surname>
       Utham Kumar Anugula
      </surname>
      <given-names>
       Sethupathy
      </given-names>
     </name>
    </contrib>
   </contrib-group> 
   <aff id="affnull">
    <addr-line>
     aIndependent Researcher, Atlanta, GA, USA
    </addr-line> 
   </aff> 
   <pub-date pub-type="epub">
    <day>
     28
    </day> 
    <month>
     08
    </month>
    <year>
     2025
    </year>
   </pub-date> 
   <volume>
    18
   </volume> 
   <issue>
    09
   </issue>
   <fpage>
    317
   </fpage>
   <lpage>
    335
   </lpage>
   <history>
    <date date-type="received">
     <day>
      28,
     </day>
     <month>
      April
     </month>
     <year>
      2025
     </year>
    </date>
    <date date-type="published">
     <day>
      25,
     </day>
     <month>
      April
     </month>
     <year>
      2025
     </year> 
    </date> 
    <date date-type="accepted">
     <day>
      25,
     </day>
     <month>
      August
     </month>
     <year>
      2025
     </year> 
    </date>
   </history>
   <permissions>
    <copyright-statement>
     © Copyright 2014 by authors and Scientific Research Publishing Inc. 
    </copyright-statement>
    <copyright-year>
     2014
    </copyright-year>
    <license>
     <license-p>
      This work is licensed under the Creative Commons Attribution International License (CC BY). http://creativecommons.org/licenses/by/4.0/
     </license-p>
    </license>
   </permissions>
   <abstract>
    <b>Introduction</b>: DevOps maturity models help organizations benchmark their engineering capabilities, yet the empirical grounding of most models remains fragmented in scholarly literature. 
    <b>Methods</b>: We conducted a mixed-methods study consisting of (i) a systematic literature review (SLR) of 78 peer-reviewed papers from IEEE, ACM, SpringerLink, and ScienceDirect (2013-2024) and (ii) multiple embedded case studies of three large enterprises (finance, media, telecom) following Yin’s five-step protocol. Quantitative project-metric data (n = 2443 deploys) were triangulated with 26 semi-structured interviews. 
    <b>Results</b>: The SLR synthesized 27 core capability dimensions across existing maturity models and identified four evidence-backed outcome clusters (deployment frequency, change failure rate, MTTR, lead-time). The proposed Lean-Agile DevOps Maturity Framework integrates these dimensions into six domains and five levels. Case studies confirm a significant correlation between maturity score and deployment frequency (ρ = 0.67, p &lt; 0.01) and a 31% reduction in MTTR when moving from “Intermediate” to “Advanced”. 
    <b>Discussion</b>: Our framework extends prior models by adding Security Integration and Architecture&amp;Design as first-class domains, addressing gaps reported by earlier studies. We outline threats to validity, replication artifacts, and future research opportunities for automated maturity telemetry.
   </abstract>
   <kwd-group> 
    <kwd>
     DevOps Maturity Model
    </kwd> 
    <kwd>
      Lean-Agile
    </kwd> 
    <kwd>
      Continuous Delivery
    </kwd> 
    <kwd>
      DevSecOps
    </kwd> 
    <kwd>
      Software Metrics
    </kwd> 
    <kwd>
      Case Study Research
    </kwd>
   </kwd-group>
  </article-meta>
 </front>
 <body>
  <sec id="s1">
   <title>1. Introduction</title>
   <p>Accelerating release cadence while preserving reliability and security has become a strategic imperative for modern enterprises. DevOps—understood as the fusion of Lean product thinking, Agile planning, and continuous delivery automation—has emerged as the dominant organizational paradigm for meeting this demand <xref ref-type="bibr" rid="scirp.145228-1">
     [1]
    </xref>. Yet organizations still struggle to understand where they stand on the DevOps journey and which capability gaps most impede flow. Maturity models seek to answer these questions by supplying staged road maps, checklists, and benchmarking metrics <xref ref-type="bibr" rid="scirp.145228-2">
     [2]
    </xref>.</p>
   <sec id="s1_1">
    <title>1.1. Problem Statement</title>
    <p>Despite their popularity in industry white-papers, existing DevOps maturity models exhibit three persistent weaknesses:</p>
    <p>Consequently, leaders lack a rigorous, evidence-based instrument to benchmark progress and justify investment.</p>
   </sec>
   <sec id="s1_2">
    <title>1.2. Research Objectives</title>
    <p>This study addresses the above gaps through a mixed-methods investigation that unifies systematic literature evidence with multi-industry field data. We pursue three research questions (RQs):</p>
   </sec>
   <sec id="s1_3">
    <title>1.3. Proposed Solution and Scope</title>
    <p>Building on 78 peer-reviewed sources published between 2013 and 2024, we synthesize 27 capability dimensions into a Lean-Agile DevOps Maturity Framework (LADMF) comprising six domains—Deployment Automation, Telemetry &amp; Observability, Testing Maturity, Build &amp; Release Management, Security Integration, and Architecture &amp; Design—each articulated over five maturity levels. The framework is empirically validated through embedded case studies at a global bank, a streaming-media company, and a telecom operator, collectively encompassing 2443 production deploys and 26 practitioner interviews.</p>
   </sec>
   <sec id="s1_4">
    <title>1.4. Key Contributions</title>
    <p>This paper makes four contributions:</p>
   </sec>
   <sec id="s1_5">
    <title>1.5. Paper Structure</title>
    <p>Section 2 reviews related work and positions LADMF against ten seminal models. Section 3 details the research methodology, including the SLR protocol, case-study design, and statistical analyses. Section 4 presents the LADMF in full, while Section 5 reports SLR and case-study results. Section 6 discusses practical implications, threats to validity, and avenues for automated maturity telemetry. Section 7 concludes with lessons learned and future research directions.</p>
    <sec id="s1">
     <title>2. Related Work</title>
     <p>A decade of scholarship on DevOps maturity reveals an increasingly diverse but still fragmented body of models. This section (i) summarizes the search and screening process that underpins our systematic literature review (full protocol in § 3), (ii) synthesizes the capability dimensions most frequently cited by prior work, and (iii) positions the proposed Lean-Agile DevOps Maturity Framework (LADMF) against ten seminal models from both academia and industry.</p>
     <p>Foundational works and early empirical mappings of DevOps capability constructs establish the baseline we build on <xref ref-type="bibr" rid="scirp.145228-1">
       [1]
      </xref>-<xref ref-type="bibr" rid="scirp.145228-8">
       [8]
      </xref>, and the case-study research canon provides the methodological scaffolding for our multi-site design <xref ref-type="bibr" rid="scirp.145228-9">
       [9]
      </xref>. Domain-specific empirical analyses extend to delivery-pipeline practices and organizational change <xref ref-type="bibr" rid="scirp.145228-10">
       [10]
      </xref>-<xref ref-type="bibr" rid="scirp.145228-12">
       [12]
      </xref>, with subsequent surveys and frameworks refining maturity dimensions and validation approaches <xref ref-type="bibr" rid="scirp.145228-13">
       [13]
      </xref>-<xref ref-type="bibr" rid="scirp.145228-15">
       [15]
      </xref>. Recent scholarship broadens coverage to DevSecOps and architecturally agile delivery—including policy-as-code enforcement, threat modelling integration, and evolutionary architectures—thereby addressing gaps noted in earlier models <xref ref-type="bibr" rid="scirp.145228-16">
       [16]
      </xref>-<xref ref-type="bibr" rid="scirp.145228-25">
       [25]
      </xref>. Methodological and practice-oriented contributions on immutable infrastructure, GitOps controllers, compliance-as-code, and automated architecture fitness functions further operationalize maturity assessment <xref ref-type="bibr" rid="scirp.145228-26">
       [26]
      </xref>-<xref ref-type="bibr" rid="scirp.145228-33">
       [33]
      </xref>. Finally, studies on DevOps metrics and ROI, reliability engineering practices, and team-level psychological safety extend the evidence base against which we benchmark outcomes in this paper <xref ref-type="bibr" rid="scirp.145228-34">
       [34]
      </xref>-<xref ref-type="bibr" rid="scirp.145228-40">
       [40]
      </xref>.</p>
    </sec>
    <sec id="s2_6">
     <title>2.1. Corpus Identification</title>
     <p>Applying the search string (“DevOps” AND “maturity model”) OR (“continuous delivery” AND “capability model”) to IEEE Xplore, ACM DL, Scopus and SpringerLink returned 1428 records (2013-2024). After duplicate removal and title-abstract screening, 142 papers remained. Quality appraisal using Kitchenham’s checklist excluded studies scoring &lt; 3/5, yielding 78 peer-reviewed articles for full-text analysis.</p>
    </sec>
    <sec id="s2_7">
     <title>2.2. Evolution of DevOps Maturity Models</title>
     <p>Early models (2013-2016) were primarily descriptive checklists derived from single company experience reports. Mid-period studies (2017-2020) introduced multi-domain structures—e.g. CALMS and CAMS—to capture culture and measurement aspects. Recent work (2021-2024) shows a shift toward data-driven validation yet still concentrates on the four canonical domains of culture, automation, measurement, and sharing. Security integration and architectural agility appear in only 15% and 18% of studies respectively, confirming the gap noted by Erich et al. <xref ref-type="bibr" rid="scirp.145228-7">
       [7]
      </xref> and Lwakatare et al. <xref ref-type="bibr" rid="scirp.145228-8">
       [8]
      </xref> and the case-study research canon provides the methodological scaffolding for our multi-site design <xref ref-type="bibr" rid="scirp.145228-9">
       [9]
      </xref>.</p>
    </sec>
    <sec id="s2_8">
     <title>2.3. Recurring Capability Dimensions</title>
     <p>Coding of the 78 papers produced a catalogue of 27 discrete capability dimensions. The five most cited were Continuous Integration (79%), Automated Testing (74%), Continuous Deployment (68%), Telemetry (64%) and Change-Failure Recovery (59%). Less than one-fifth of papers explicitly addressed Threat-Modelling, Static-Code Analysis, or Modular Architecture, underscoring the limited treatment of security and design agility.</p>
    </sec>
    <sec id="s2_9">
     <title>2.4. Comparative Analysis of Representative Models</title>
     <p>
      <xref ref-type="table" rid="table1">
       Table 1
      </xref> contrasts ten frequently referenced maturity models against five criteria: level granularity, domain coverage, empirical validation, inclusion of security, inclusion of architecture, and use of quantified delivery metrics.</p>
    </sec>
    <sec id="s2_10">
     <title>2.5. Identified Research Gaps</title>
     <p>Three themes emerge:</p>
     <table-wrap id="table1">
      <label>
       <xref ref-type="table" rid="table1">
        Table 1
       </xref></label>
      <caption>
       <title>
        <xref ref-type="bibr" rid="scirp.145228-"></xref>Table 1. Comparison of representative DevOps maturity models.</title>
      </caption>
      <table class="MsoTableGrid custom-table" border="0" cellspacing="0" cellpadding="0"> 
       <tr> 
        <td class="custom-bottom-td custom-top-td aleft" width="4.42%"><p style="text-align:left">#</p></td> 
        <td class="custom-bottom-td custom-top-td aleft" width="27.94%"><p style="text-align:left">Model / Source</p></td> 
        <td class="custom-bottom-td custom-top-td aleft" width="7.36%"><p style="text-align:left">Levels</p></td> 
        <td class="custom-bottom-td custom-top-td aleft" width="8.82%"><p style="text-align:left">Domains</p></td> 
        <td class="custom-bottom-td custom-top-td aleft" width="17.65%"><p style="text-align:left">Validation Method</p></td> 
        <td class="custom-bottom-td custom-top-td aleft" width="11.27%"><p style="text-align:left">Security Domain</p></td> 
        <td class="custom-bottom-td custom-top-td aleft" width="11.28%"><p style="text-align:left">Architecture Domain</p></td> 
        <td class="custom-bottom-td custom-top-td aleft" width="11.28%"><p style="text-align:left">Metrics Reported</p></td> 
       </tr> 
       <tr> 
        <td class="custom-top-td aleft" width="4.42%"><p style="text-align:left">1</p></td> 
        <td class="custom-top-td aleft" width="27.94%"><p style="text-align:left">CALMS-MM (Humble 2015)</p></td> 
        <td class="custom-top-td aleft" width="7.36%"><p style="text-align:left">4</p></td> 
        <td class="custom-top-td aleft" width="8.82%"><p style="text-align:left">5</p></td> 
        <td class="custom-top-td aleft" width="17.65%"><p style="text-align:left">None</p></td> 
        <td class="custom-top-td aleft" width="11.27%"><p style="text-align:left">✗</p></td> 
        <td class="custom-top-td aleft" width="11.28%"><p style="text-align:left">✗</p></td> 
        <td class="custom-top-td aleft" width="11.28%"><p style="text-align:left">✗</p></td> 
       </tr> 
       <tr> 
        <td class="aleft" width="4.42%"><p style="text-align:left">2</p></td> 
        <td class="aleft" width="27.94%"><p style="text-align:left">DO-MM (Erich 2022)</p></td> 
        <td class="aleft" width="7.36%"><p style="text-align:left">5</p></td> 
        <td class="aleft" width="8.82%"><p style="text-align:left">4</p></td> 
        <td class="aleft" width="17.65%"><p style="text-align:left">Survey (n = 60)</p></td> 
        <td class="aleft" width="11.27%"><p style="text-align:left">✗</p></td> 
        <td class="aleft" width="11.28%"><p style="text-align:left">✗</p></td> 
        <td class="aleft" width="11.28%"><p style="text-align:left">✗</p></td> 
       </tr> 
       <tr> 
        <td class="aleft" width="4.42%"><p style="text-align:left">3</p></td> 
        <td class="aleft" width="27.94%"><p style="text-align:left">BIMM-DevOps (Smeds 2020)</p></td> 
        <td class="aleft" width="7.36%"><p style="text-align:left">4</p></td> 
        <td class="aleft" width="8.82%"><p style="text-align:left">6</p></td> 
        <td class="aleft" width="17.65%"><p style="text-align:left">Single case</p></td> 
        <td class="aleft" width="11.27%"><p style="text-align:left">✗</p></td> 
        <td class="aleft" width="11.28%"><p style="text-align:left">✗</p></td> 
        <td class="aleft" width="11.28%"><p style="text-align:left">CFR</p></td> 
       </tr> 
       <tr> 
        <td class="aleft" width="4.42%"><p style="text-align:left">4</p></td> 
        <td class="aleft" width="27.94%"><p style="text-align:left">SAFe DevOps Radar (Scaled Agile 2021)</p></td> 
        <td class="aleft" width="7.36%"><p style="text-align:left">3</p></td> 
        <td class="aleft" width="8.82%"><p style="text-align:left">4</p></td> 
        <td class="aleft" width="17.65%"><p style="text-align:left">None</p></td> 
        <td class="aleft" width="11.27%"><p style="text-align:left">✗</p></td> 
        <td class="aleft" width="11.28%"><p style="text-align:left">✗</p></td> 
        <td class="aleft" width="11.28%"><p style="text-align:left">✗</p></td> 
       </tr> 
       <tr> 
        <td class="aleft" width="4.42%"><p style="text-align:left">5</p></td> 
        <td class="aleft" width="27.94%"><p style="text-align:left">CNCF Maturity Model (CNCF 2023)</p></td> 
        <td class="aleft" width="7.36%"><p style="text-align:left">3</p></td> 
        <td class="aleft" width="8.82%"><p style="text-align:left">5</p></td> 
        <td class="aleft" width="17.65%"><p style="text-align:left">Expert review</p></td> 
        <td class="aleft" width="11.27%"><p style="text-align:left">✗</p></td> 
        <td class="aleft" width="11.28%"><p style="text-align:left">✗</p></td> 
        <td class="aleft" width="11.28%"><p style="text-align:left">✗</p></td> 
       </tr> 
       <tr> 
        <td class="aleft" width="4.42%"><p style="text-align:left">6</p></td> 
        <td class="aleft" width="27.94%"><p style="text-align:left">ODMM (OpenDevOps 2023)</p></td> 
        <td class="aleft" width="7.36%"><p style="text-align:left">5</p></td> 
        <td class="aleft" width="8.82%"><p style="text-align:left">5</p></td> 
        <td class="aleft" width="17.65%"><p style="text-align:left">Delphi panel</p></td> 
        <td class="aleft" width="11.27%"><p style="text-align:left">✓</p></td> 
        <td class="aleft" width="11.28%"><p style="text-align:left">✗</p></td> 
        <td class="aleft" width="11.28%"><p style="text-align:left">Lead-time</p></td> 
       </tr> 
       <tr> 
        <td class="aleft" width="4.42%"><p style="text-align:left">7</p></td> 
        <td class="aleft" width="27.94%"><p style="text-align:left">DevSecOps-MM (Rodriguez 2024)</p></td> 
        <td class="aleft" width="7.36%"><p style="text-align:left">4</p></td> 
        <td class="aleft" width="8.82%"><p style="text-align:left">6</p></td> 
        <td class="aleft" width="17.65%"><p style="text-align:left">Two-case study</p></td> 
        <td class="aleft" width="11.27%"><p style="text-align:left">✓</p></td> 
        <td class="aleft" width="11.28%"><p style="text-align:left">✗</p></td> 
        <td class="aleft" width="11.28%"><p style="text-align:left">MTTR</p></td> 
       </tr> 
       <tr> 
        <td class="aleft" width="4.42%"><p style="text-align:left">8</p></td> 
        <td class="aleft" width="27.94%"><p style="text-align:left">ADS-MM (Fitzgerald 2024)</p></td> 
        <td class="aleft" width="7.36%"><p style="text-align:left">5</p></td> 
        <td class="aleft" width="8.82%"><p style="text-align:left">6</p></td> 
        <td class="aleft" width="17.65%"><p style="text-align:left">Multi-survey</p></td> 
        <td class="aleft" width="11.27%"><p style="text-align:left">✗</p></td> 
        <td class="aleft" width="11.28%"><p style="text-align:left">✓</p></td> 
        <td class="aleft" width="11.28%"><p style="text-align:left">CFR</p></td> 
       </tr> 
       <tr> 
        <td class="aleft" width="4.42%"><p style="text-align:left">9</p></td> 
        <td class="aleft" width="27.94%"><p style="text-align:left">LD-MM (Leite 2024)</p></td> 
        <td class="aleft" width="7.36%"><p style="text-align:left">4</p></td> 
        <td class="aleft" width="8.82%"><p style="text-align:left">4</p></td> 
        <td class="aleft" width="17.65%"><p style="text-align:left">None</p></td> 
        <td class="aleft" width="11.27%"><p style="text-align:left">✗</p></td> 
        <td class="aleft" width="11.28%"><p style="text-align:left">✗</p></td> 
        <td class="aleft" width="11.28%"><p style="text-align:left">✗</p></td> 
       </tr> 
       <tr> 
        <td class="custom-bottom-td aleft" width="4.42%"><p style="text-align:left">10</p></td> 
        <td class="custom-bottom-td aleft" width="27.94%"><p style="text-align:left">LADMF (this work)</p></td> 
        <td class="custom-bottom-td aleft" width="7.36%"><p style="text-align:left">5</p></td> 
        <td class="custom-bottom-td aleft" width="8.82%"><p style="text-align:left">6</p></td> 
        <td class="custom-bottom-td aleft" width="17.65%"><p style="text-align:left">SLR + 3 cases</p></td> 
        <td class="custom-bottom-td aleft" width="11.27%"><p style="text-align:left">✓</p></td> 
        <td class="custom-bottom-td aleft" width="11.28%"><p style="text-align:left">✓</p></td> 
        <td class="custom-bottom-td aleft" width="11.28%"><p style="text-align:left">4 KPIs</p></td> 
       </tr> 
      </table>
     </table-wrap>
    </sec>
   </sec>
   <sec id="s3">
    <title>3. Research Methodology</title>
    <p>This study employs a convergent mixed-methods design that integrates a systematic literature review (SLR) with a multiple-embedded case study. The two strands were executed in parallel and merged during interpretation to maximize triangulation (<xref ref-type="fig" rid="fig1">
      Figure 1
     </xref>).</p>
    <fig id="fig1" position="float">
     <label>Figure 1</label>
     <caption>
      <title>
       <xref ref-type="bibr" rid="scirp.145228-"></xref>Figure 1. Mixed-methods design overview.</title>
     </caption>
     <graphic mimetype="image" position="float" xlink:type="simple" xlink:href="https://html.scirp.org/file/9303409-rId15.jpeg?20250828024632" />
    </fig>
    <sec id="s3_1">
     <title>3.1. Systematic Literature Review Protocol</title>
     <p>
      <xref ref-type="table" rid="table2">
       Table 2
      </xref> summarizes LADMF domain definitions and rationale.</p>
     <table-wrap id="table2">
      <label>
       <xref ref-type="table" rid="table2">
        Table 2
       </xref></label>
      <caption>
       <title>
        <xref ref-type="bibr" rid="scirp.145228-"></xref>Table 2. A systematic literature review protocol.</title>
      </caption>
      <table class="MsoTableGrid custom-table" border="0" cellspacing="0" cellpadding="0"> 
       <tr> 
        <td class="custom-bottom-td custom-top-td aleft" width="20.95%"><p style="text-align:left">Item</p></td> 
        <td class="custom-bottom-td custom-top-td aleft" width="79.05%"><p style="text-align:left">Description</p></td> 
       </tr> 
       <tr> 
        <td class="custom-top-td aleft" width="20.95%"><p style="text-align:left">Databases</p></td> 
        <td class="custom-top-td aleft" width="79.05%"><p style="text-align:left">IEEE Xplore, ACM DL, Scopus, SpringerLink</p></td> 
       </tr> 
       <tr> 
        <td class="aleft" width="20.95%"><p style="text-align:left">Search String</p></td> 
        <td class="aleft" width="79.05%"><p style="text-align:left">(“DevOps” AND “maturity model”) OR (“continuous delivery” AND “capability model”)</p></td> 
       </tr> 
       <tr> 
        <td class="aleft" width="20.95%"><p style="text-align:left">Period Covered</p></td> 
        <td class="aleft" width="79.05%"><p style="text-align:left">January 2013 - December 2024</p></td> 
       </tr> 
       <tr> 
        <td class="aleft" width="20.95%"><p style="text-align:left">Screening Process</p></td> 
        <td class="aleft" width="79.05%"><p style="text-align:left">1428 records → 142 full texts → 78 included (Kitchenham quality score ≥ 3/5)</p></td> 
       </tr> 
       <tr> 
        <td class="aleft" width="20.95%"><p style="text-align:left">Extraction Fields</p></td> 
        <td class="aleft" width="79.05%"><p style="text-align:left">Publication metadata; maturity levels; capability dimensions; validation method; outcome metrics</p></td> 
       </tr> 
       <tr> 
        <td class="custom-bottom-td aleft" width="20.95%"><p style="text-align:left">Synthesis Method</p></td> 
        <td class="custom-bottom-td aleft" width="79.05%"><p style="text-align:left">Thematic coding (three researchers, κ = 0.82); frequency counts; cross-tabulation vs. validation type</p></td> 
       </tr> 
      </table>
     </table-wrap>
    </sec>
    <sec id="s3_2">
     <title>3.2. Multiple-Embedded Case Study Design</title>
     <p>We followed Yin’s five-step protocol to maximize construct, internal, and external validity. Cases were chosen using maximum-variation purposeful sampling to span industry context and baseline DevOps maturity.</p>
     <p>Inclusion:</p>
     <p>Exclusion:</p>
     <p>We studied three large enterprises—F-Bank (finance), StreamMedia (digital media), Telecom (telecommunications), each comprising several value-stream teams (~150 developers in total). Baseline LADMF levels varied intentionally: Beginner (StreamMedia), Intermediate (F-Bank), and Advanced (Telecom). This distribution reduces the risk that findings reflect only high-maturity organizations.</p>
     <p>Units were value-stream teams. Data sources combined: (i) deployment and incident telemetry, (ii) pipeline configurations, (iii) 26 semi-structured interviews, and (iv) documentary artifacts (runbooks, architecture diagrams).</p>
     <p>Two researchers scored the LADMF rubric independently using artifact evidence; disagreements were resolved by discussion (Cohen’s κ = 0.82). Interview participants were recruited across roles (dev, SRE, QA, security, product) to avoid single-perspective bias.</p>
     <p>A formal control group (non-DevOps organizations) was not included. Instead, we contextualized site KPIs against widely used industry benchmarks (DORA quartiles) to provide an external reference distribution rather than a causal counterfactual. We treat causal claims cautiously (see § 6.4). <xref ref-type="table" rid="table3">
       Table 3
      </xref> maps research questions (RQs) to data sources.</p>
     <table-wrap id="table3">
      <label>
       <xref ref-type="table" rid="table3">
        Table 3
       </xref></label>
      <caption>
       <title>
        <xref ref-type="bibr" rid="scirp.145228-"></xref>Table 3. A case selection criteria and baseline maturity.</title>
      </caption>
      <table class="MsoTableGrid custom-table" border="0" cellspacing="0" cellpadding="0"> 
       <tr> 
        <td class="custom-bottom-td custom-top-td aleft" width="41.75%"><p style="text-align:left">RQ</p></td> 
        <td class="custom-bottom-td custom-top-td aleft" width="32.60%"><p style="text-align:left">Data source(s)</p></td> 
        <td class="custom-bottom-td custom-top-td aleft" width="25.64%"><p style="text-align:left">Analysis technique</p></td> 
       </tr> 
       <tr> 
        <td class="custom-top-td aleft" width="41.75%"><p style="text-align:left">RQ1—Which capability dimensions dominate published DevOps maturity models?</p></td> 
        <td class="custom-top-td aleft" width="32.60%"><p style="text-align:left">SLR extraction sheets</p></td> 
        <td class="custom-top-td aleft" width="25.64%"><p style="text-align:left">Thematic frequency analysis</p></td> 
       </tr> 
       <tr> 
        <td class="aleft" width="41.75%"><p style="text-align:left">RQ2—Does maturity correlate with delivery performance (deployment frequency, lead time, CFR, MTTR)?</p></td> 
        <td class="aleft" width="32.60%"><p style="text-align:left">CI/CD deploy logs, incident database</p></td> 
        <td class="aleft" width="25.64%"><p style="text-align:left">Spearman ρ; Mann-Whitney U; effect size r</p></td> 
       </tr> 
       <tr> 
        <td class="custom-bottom-td aleft" width="41.75%"><p style="text-align:left">RQ3—What factors enable or inhibit progression across maturity levels?</p></td> 
        <td class="custom-bottom-td aleft" width="32.60%"><p style="text-align:left">Semi-structured interviews; post-incident reviews; pipeline/policy artifacts</p></td> 
        <td class="custom-bottom-td aleft" width="25.64%"><p style="text-align:left">Grounded coding; axial theme mapping</p></td> 
       </tr> 
      </table>
     </table-wrap>
    </sec>
    <sec id="s3_3">
     <title>3.3. Data Collection Procedures</title>
     <p>Quantitative telemetry was exported from each site’s CI/CD analytics platform and normalized to DORA KPI definitions (deployment frequency, lead time, change failure rate, MTTR).</p>
     <p>Qualitative data came from semi-structured interviews covering culture, process, tooling, and governance; all sessions were transcribed and member checked. Documentary artifacts (runbooks, architecture diagrams) supplied contextual detail.</p>
    </sec>
    <sec id="s3_4">
     <title>3.4. Data Analysis &amp; Integration</title>
    </sec>
    <sec id="s3_5">
     <title>3.5. Ethical and Validity Considerations</title>
     <p>All participants provided informed consent; organizational names are pseudonymized. Threats to validity are mitigated as follows: construct validity via multiple data sources; internal validity via pattern matching; external validity via industry variation; reliability via audit trail and shared artifacts.</p>
    </sec>
   </sec>
   <sec id="s4">
    <title>4. Lean-Agile DevOps Maturity Framework (LADMF)</title>
    <p>This section presents the Lean-Agile DevOps Maturity Framework (LADMF) that emerged from the systematic review (§ 3.1) and was iteratively refined through three case-study sites (§ 3.2). LADMF integrates 27 capability dimensions into six domains, each articulated over five maturity levels. A radar-style visual (<xref ref-type="fig" rid="fig2">
      Figure 2
     </xref>) and three supporting tables (<xref ref-type="table" rid="tableTables 4-6">
      Tables 4-6
     </xref>) provide a complete specification suitable for assessment, benchmarking, and longitudinal tracking.</p>
    <fig id="fig2" position="float">
     <label>Figure 2</label>
     <caption>
      <title>
       <xref ref-type="bibr" rid="scirp.145228-"></xref>Figure 2. LADMF Radar (Six axes—Deployment Automation, Telemetry &amp; Observability, Testing Maturity, Build &amp; Release Management, Security Integration, Architecture &amp; Design—plotted across five concentric rings labelled Novice, Beginner, Intermediate, Advanced, Expert).</title>
     </caption>
     <graphic mimetype="image" position="float" xlink:type="simple" xlink:href="https://html.scirp.org/file/9303409-rId16.jpeg?20250828024635" />
    </fig>
    <sec id="s4_1">
     <title>4.1. Domain Definitions</title>
     <p>
      <xref ref-type="table" rid="table4">
       Table 4
      </xref> summarizes each domain’s scope and rationale, grounded in SLR frequency counts and interview coding.</p>
     <table-wrap id="table4">
      <label>
       <xref ref-type="table" rid="table4">
        Table 4
       </xref></label>
      <caption>
       <title>
        <xref ref-type="bibr" rid="scirp.145228-"></xref>Table 4. Domain definitions and rationale.</title>
      </caption>
      <table class="MsoTableGrid custom-table" border="0" cellspacing="0" cellpadding="0"> 
       <tr> 
        <td class="custom-bottom-td custom-top-td acenter" width="18.81%"><p style="text-align:center">Domain</p></td> 
        <td class="custom-bottom-td custom-top-td acenter" width="49.46%"><p style="text-align:center">Definition</p></td> 
        <td class="custom-bottom-td custom-top-td acenter" width="17.77%"><p style="text-align:center">Representative SLR Coverage*</p></td> 
        <td class="custom-bottom-td custom-top-td acenter" width="13.96%"><p style="text-align:center">Key References</p></td> 
       </tr> 
       <tr> 
        <td class="custom-top-td acenter" width="18.81%"><p style="text-align:center">Deployment Automation</p></td> 
        <td class="custom-top-td acenter" width="49.46%"><p style="text-align:center">Ability to script, version-control, and orchestrate deployment workflows from build to production</p></td> 
        <td class="custom-top-td acenter" width="17.77%"><p style="text-align:center">68%</p></td> 
        <td class="custom-top-td acenter" width="13.96%"><p style="text-align:center">
          <xref ref-type="bibr" rid="scirp.145228-1">
           [1]
          </xref> <xref ref-type="bibr" rid="scirp.145228-10">
           [10]
          </xref></p></td> 
       </tr> 
       <tr> 
        <td class="acenter" width="18.81%"><p style="text-align:center">Build &amp; Release Management</p></td> 
        <td class="acenter" width="49.46%"><p style="text-align:center">Artifact versioning, release orchestration, rollback strategies, change-failure recovery</p></td> 
        <td class="acenter" width="17.77%"><p style="text-align:center">59%</p></td> 
        <td class="acenter" width="13.96%"><p style="text-align:center">
          <xref ref-type="bibr" rid="scirp.145228-2">
           [2]
          </xref> <xref ref-type="bibr" rid="scirp.145228-11">
           [11]
          </xref></p></td> 
       </tr> 
       <tr> 
        <td class="acenter" width="18.81%"><p style="text-align:center">Telemetry &amp; Observability</p></td> 
        <td class="acenter" width="49.46%"><p style="text-align:center">Capture and analyze logs, metrics, traces; enable real-time feedback loops</p></td> 
        <td class="acenter" width="17.77%"><p style="text-align:center">64%</p></td> 
        <td class="acenter" width="13.96%"><p style="text-align:center">
          <xref ref-type="bibr" rid="scirp.145228-3">
           [3]
          </xref> <xref ref-type="bibr" rid="scirp.145228-12">
           [12]
          </xref></p></td> 
       </tr> 
       <tr> 
        <td class="acenter" width="18.81%"><p style="text-align:center">Architecture &amp; Design</p></td> 
        <td class="acenter" width="49.46%"><p style="text-align:center">Modular, evolved architecture enabling independent deploy ability and resilience</p></td> 
        <td class="acenter" width="17.77%"><p style="text-align:center">18%</p></td> 
        <td class="acenter" width="13.96%"><p style="text-align:center">
          <xref ref-type="bibr" rid="scirp.145228-4">
           [4]
          </xref> <xref ref-type="bibr" rid="scirp.145228-13">
           [13]
          </xref></p></td> 
       </tr> 
       <tr> 
        <td class="acenter" width="18.81%"><p style="text-align:center">Security Integration</p></td> 
        <td class="acenter" width="49.46%"><p style="text-align:center">Shift-left practices, threat-modelling, static analysis, policy-as-code, secure supply chain</p></td> 
        <td class="acenter" width="17.77%"><p style="text-align:center">15%</p></td> 
        <td class="acenter" width="13.96%"><p style="text-align:center">
          <xref ref-type="bibr" rid="scirp.145228-5">
           [5]
          </xref> <xref ref-type="bibr" rid="scirp.145228-14">
           [14]
          </xref></p></td> 
       </tr> 
       <tr> 
        <td class="custom-bottom-td acenter" width="18.81%"><p style="text-align:center">Testing Maturity</p></td> 
        <td class="custom-bottom-td acenter" width="49.46%"><p style="text-align:center">Breadth and depth of automated tests across units, integration, performance, security</p></td> 
        <td class="custom-bottom-td acenter" width="17.77%"><p style="text-align:center">74%</p></td> 
        <td class="custom-bottom-td acenter" width="13.96%"><p style="text-align:center">
          <xref ref-type="bibr" rid="scirp.145228-6">
           [6]
          </xref> <xref ref-type="bibr" rid="scirp.145228-15">
           [15]
          </xref></p></td> 
       </tr> 
      </table>
     </table-wrap>
     <p>*Percentage of 78 SLR papers that explicitly covered the domain.</p>
    </sec>
    <sec id="s4_2">
     <title>4.2. Maturity Levels</title>
     <p>
      <xref ref-type="table" rid="table5">
       Table 5
      </xref> offers level descriptors that are tool-agnostic yet concrete enough for scoring. Each descriptor aligns with evidence patterns observed in the case sites and with DORA-style KPIs used in § 5.</p>
     <table-wrap id="table5">
      <label>
       <xref ref-type="table" rid="table5">
        Table 5
       </xref></label>
      <caption>
       <title>
        <xref ref-type="bibr" rid="scirp.145228-"></xref>Table 5. Level descriptors (all domains).</title>
      </caption>
      <table class="MsoTableGrid custom-table" border="0" cellspacing="0" cellpadding="0"> 
       <tr> 
        <td class="custom-bottom-td custom-top-td acenter" width="20.35%"><p style="text-align:center">Level</p></td> 
        <td class="custom-bottom-td custom-top-td acenter" width="51.88%"><p style="text-align:center">Descriptor (Generic)</p></td> 
        <td class="custom-bottom-td custom-top-td acenter" width="27.77%"><p style="text-align:center">Target Delivery KPIs*</p></td> 
       </tr> 
       <tr> 
        <td class="custom-top-td acenter" width="20.35%"><p style="text-align:center">Novice (1)</p></td> 
        <td class="custom-top-td acenter" width="51.88%"><p style="text-align:center">Manual, ad-hoc processes; knowledge siloed; no telemetry; security bolted on</p></td> 
        <td class="custom-top-td acenter" width="27.77%"><p style="text-align:center">Deploy ≤ monthly; CFR &gt; 25%; MTTR &gt; 24 h</p></td> 
       </tr> 
       <tr> 
        <td class="acenter" width="20.35%"><p style="text-align:center">Beginner (2)</p></td> 
        <td class="acenter" width="51.88%"><p style="text-align:center">Basic CI; scripted builds; isolated test automation; manual approvals dominate</p></td> 
        <td class="acenter" width="27.77%"><p style="text-align:center">Deploy ≤ weekly; CFR ≈ 15%</p></td> 
       </tr> 
       <tr> 
        <td class="acenter" width="20.35%"><p style="text-align:center">Intermediate (3)</p></td> 
        <td class="acenter" width="51.88%"><p style="text-align:center">Fully automated CI/CD; infrastructure-as-code; integrated observability dashboards</p></td> 
        <td class="acenter" width="27.77%"><p style="text-align:center">Lead time ≤ 1 day; MTTR ≤ 4 h; CFR &lt; 10%</p></td> 
       </tr> 
       <tr> 
        <td class="acenter" width="20.35%"><p style="text-align:center">Advanced (4)</p></td> 
        <td class="acenter" width="51.88%"><p style="text-align:center">Policy-driven pipelines, canary releases; shift-left security; modular services</p></td> 
        <td class="acenter" width="27.77%"><p style="text-align:center">Deploy daily; MTTR ≤ 1 h; CFR &lt; 8%</p></td> 
       </tr> 
       <tr> 
        <td class="custom-bottom-td acenter" width="20.35%"><p style="text-align:center">Expert (5)</p></td> 
        <td class="custom-bottom-td acenter" width="51.88%"><p style="text-align:center">Self-healing, zero-touch deploys; automated architecture fitness tests; continuous compliance</p></td> 
        <td class="custom-bottom-td acenter" width="27.77%"><p style="text-align:center">Deploy on demand; MTTR ≤ 15 min; CFR &lt; 5%</p></td> 
       </tr> 
      </table>
     </table-wrap>
     <p>*KPIs: deployment frequency, lead time for changes, mean-time-to-recover (MTTR), change-failure rate (CFR).</p>
    </sec>
    <sec id="s4_3">
     <title>4.3. Scoring Rubric and Example Metrics</title>
     <p>To operationalize LADMF, we created a rubric that assigns 0 - 5 points per capability dimension. Scores aggregate upward to domain totals (0 - 25) and an overall maturity index (0 - 150). <xref ref-type="table" rid="table6">
       Table 6
      </xref> illustrates the rubric for the Deployment Automation domain; analogous rubrics for the remaining domains are included in <xref ref-type="bibr" rid="scirp.145228-#Appendix">
       Appendix A
      </xref>.</p>
     <table-wrap id="table6">
      <label>
       <xref ref-type="table" rid="table6">
        Table 6
       </xref></label>
      <caption>
       <title>
        <xref ref-type="bibr" rid="scirp.145228-"></xref>Table 6. Deployment automation scoring rubric.</title>
      </caption>
      <table class="MsoTableGrid custom-table" border="0" cellspacing="0" cellpadding="0"> 
       <tr> 
        <td class="custom-bottom-td custom-top-td acenter" width="13.24%"><p style="text-align:center">Capability Dimension</p></td> 
        <td class="custom-bottom-td custom-top-td acenter" width="11.76%"><p style="text-align:center">Novice (0 pt)</p></td> 
        <td class="custom-bottom-td custom-top-td acenter" width="14.99%"><p style="text-align:center">Beginner (1 pt)</p></td> 
        <td class="custom-bottom-td custom-top-td acenter" width="15.00%"><p style="text-align:center">Intermediate (2 pt)</p></td> 
        <td class="custom-bottom-td custom-top-td acenter" width="15.00%"><p style="text-align:center">Advanced (3 pt)</p></td> 
        <td class="custom-bottom-td custom-top-td acenter" width="15.00%"><p style="text-align:center">Expert (4 pt)</p></td> 
        <td class="custom-bottom-td custom-top-td acenter" width="15.00%"><p style="text-align:center">Metric Evidence</p></td> 
       </tr> 
       <tr> 
        <td class="custom-top-td acenter" width="13.24%"><p style="text-align:center">Build Scripting</p></td> 
        <td class="custom-top-td acenter" width="11.76%"><p style="text-align:center">Manual commands</p></td> 
        <td class="custom-top-td acenter" width="14.99%"><p style="text-align:center">Basic shell scripts</p></td> 
        <td class="custom-top-td acenter" width="15.00%"><p style="text-align:center">Declarative build files (e.g., Maven)</p></td> 
        <td class="custom-top-td acenter" width="15.00%"><p style="text-align:center">Reusable pipeline templates</p></td> 
        <td class="custom-top-td acenter" width="15.00%"><p style="text-align:center">Pipeline-as-code libraries</p></td> 
        <td class="custom-top-td acenter" width="15.00%"><p style="text-align:center">% automated builds</p></td> 
       </tr> 
       <tr> 
        <td class="acenter" width="13.24%"><p style="text-align:center">Infrastructure-as-Code</p></td> 
        <td class="acenter" width="11.76%"><p style="text-align:center">None</p></td> 
        <td class="acenter" width="14.99%"><p style="text-align:center">Partial (dev only)</p></td> 
        <td class="acenter" width="15.00%"><p style="text-align:center">Full (prod + non-prod)</p></td> 
        <td class="acenter" width="15.00%"><p style="text-align:center">Immutable infra patterns</p></td> 
        <td class="acenter" width="15.00%"><p style="text-align:center">Self-service infra modules</p></td> 
        <td class="acenter" width="15.00%"><p style="text-align:center">IaC coverage ratio</p></td> 
       </tr> 
       <tr> 
        <td class="acenter" width="13.24%"><p style="text-align:center">Orchestration Engine</p></td> 
        <td class="acenter" width="11.76%"><p style="text-align:center">None</p></td> 
        <td class="acenter" width="14.99%"><p style="text-align:center">Single-stage Jenkins job</p></td> 
        <td class="acenter" width="15.00%"><p style="text-align:center">Multi-stage pipelines</p></td> 
        <td class="acenter" width="15.00%"><p style="text-align:center">Canary / Blue-Green flows</p></td> 
        <td class="acenter" width="15.00%"><p style="text-align:center">GitOps controllers</p></td> 
        <td class="acenter" width="15.00%"><p style="text-align:center">Avg. deploy steps automated</p></td> 
       </tr> 
       <tr> 
        <td class="acenter" width="13.24%"><p style="text-align:center">Policy Controls</p></td> 
        <td class="acenter" width="11.76%"><p style="text-align:center">None</p></td> 
        <td class="acenter" width="14.99%"><p style="text-align:center">Manual checklist</p></td> 
        <td class="acenter" width="15.00%"><p style="text-align:center">Basic policy gates (lint, unit tests)</p></td> 
        <td class="acenter" width="15.00%"><p style="text-align:center">OPA/Governance as code</p></td> 
        <td class="acenter" width="15.00%"><p style="text-align:center">Dynamic, risk-based gates</p></td> 
        <td class="acenter" width="15.00%"><p style="text-align:center">% deployments gate-checked</p></td> 
       </tr> 
       <tr> 
        <td class="custom-bottom-td acenter" width="13.24%"><p style="text-align:center">Rollback Strategy</p></td> 
        <td class="custom-bottom-td acenter" width="11.76%"><p style="text-align:center">Restore from backup</p></td> 
        <td class="custom-bottom-td acenter" width="14.99%"><p style="text-align:center">Manual scripts</p></td> 
        <td class="custom-bottom-td acenter" width="15.00%"><p style="text-align:center">Automated rollback</p></td> 
        <td class="custom-bottom-td acenter" width="15.00%"><p style="text-align:center">Automated + config versioning</p></td> 
        <td class="custom-bottom-td acenter" width="15.00%"><p style="text-align:center">Automated ver. pinning + DB migrations</p></td> 
        <td class="custom-bottom-td acenter" width="15.00%"><p style="text-align:center">MTTR after failed deploy</p></td> 
       </tr> 
      </table>
     </table-wrap>
    </sec>
    <sec id="s4_4">
     <title>4.4. Application Workflow</title>
     <p>Assessment proceeds as follows:</p>
     <p>The three case sites applied this workflow; § 5.2 quantifies observed KPI improvements and § 6 discusses qualitative enablers and inhibitors.</p>
    </sec>
   </sec>
   <sec id="s5">
    <title>5. Results</title>
    <p>This section presents empirical findings from both strands of the mixed-methods design: the systematic literature review (SLR) (§ 5.1) and the multiple-embedded case study (§ 5.2 - 5.3). All raw data and analysis scripts are archived in the replication package.</p>
    <sec id="s5_1">
     <title>5.1. SLR Findings</title>
     <p>A PRISMA flow diagram of the screening stages is provided in <xref ref-type="fig" rid="fig3">
       Figure 3
      </xref> below.</p>
     <fig id="fig3" position="float">
      <label>Figure 3</label>
      <caption>
       <title>
        <xref ref-type="bibr" rid="scirp.145228-"></xref>Figure 3. PRISMA Flow Diagram of the SLR.</title>
      </caption>
      <graphic mimetype="image" position="float" xlink:type="simple" xlink:href="https://html.scirp.org/file/9303409-rId17.jpeg?20250828024637" />
     </fig>
    </sec>
    <sec id="s5_2">
     <title>5.2. Capability-Dimension Frequency</title>
     <p>The most frequent capability dimensions are listed in <xref ref-type="table" rid="table7">
       Table 7
      </xref>.</p>
     <table-wrap id="table7">
      <label>
       <xref ref-type="table" rid="table7">
        Table 7
       </xref></label>
      <caption>
       <title>
        <xref ref-type="bibr" rid="scirp.145228-"></xref>Table 7. Top 15 capability dimensions in 78 peer-reviewed DevOps maturity papers.</title>
      </caption>
      <table class="MsoTableGrid custom-table" border="0" cellspacing="0" cellpadding="0"> 
       <tr> 
        <td class="custom-bottom-td custom-top-td acenter" width="14.29%"><p style="text-align:center">Capability Dimension</p></td> 
        <td class="custom-bottom-td custom-top-td acenter" width="12.19%"><p style="text-align:center">Novice (0 pt)</p></td> 
        <td class="custom-bottom-td custom-top-td acenter" width="14.70%"><p style="text-align:center">Beginner (1 pt)</p></td> 
        <td class="custom-bottom-td custom-top-td acenter" width="15.97%"><p style="text-align:center">Intermediate (2 pt)</p></td> 
        <td class="custom-bottom-td custom-top-td acenter" width="14.29%"><p style="text-align:center">Advanced (3 pt)</p></td> 
        <td class="custom-bottom-td custom-top-td acenter" width="14.29%"><p style="text-align:center">Expert (4 pt)</p></td> 
        <td class="custom-bottom-td custom-top-td acenter" width="14.29%"><p style="text-align:center">Metric Evidence</p></td> 
       </tr> 
       <tr> 
        <td class="custom-top-td acenter" width="14.29%"><p style="text-align:center">Build Scripting</p></td> 
        <td class="custom-top-td acenter" width="12.19%"><p style="text-align:center">Manual commands</p></td> 
        <td class="custom-top-td acenter" width="14.70%"><p style="text-align:center">Basic shell scripts</p></td> 
        <td class="custom-top-td acenter" width="15.97%"><p style="text-align:center">Declarative build files (e.g., Maven)</p></td> 
        <td class="custom-top-td acenter" width="14.29%"><p style="text-align:center">Reusable pipeline templates</p></td> 
        <td class="custom-top-td acenter" width="14.29%"><p style="text-align:center">Pipeline-as-code libraries</p></td> 
        <td class="custom-top-td acenter" width="14.29%"><p style="text-align:center">% automated builds</p></td> 
       </tr> 
       <tr> 
        <td class="acenter" width="14.29%"><p style="text-align:center">Infrastructure-as-Code</p></td> 
        <td class="acenter" width="12.19%"><p style="text-align:center">None</p></td> 
        <td class="acenter" width="14.70%"><p style="text-align:center">Partial (dev only)</p></td> 
        <td class="acenter" width="15.97%"><p style="text-align:center">Full (prod + non-prod)</p></td> 
        <td class="acenter" width="14.29%"><p style="text-align:center">Immutable infra patterns</p></td> 
        <td class="acenter" width="14.29%"><p style="text-align:center">Self-service infra modules</p></td> 
        <td class="acenter" width="14.29%"><p style="text-align:center">IaC coverage ratio</p></td> 
       </tr> 
       <tr> 
        <td class="acenter" width="14.29%"><p style="text-align:center">Orchestration Engine</p></td> 
        <td class="acenter" width="12.19%"><p style="text-align:center">None</p></td> 
        <td class="acenter" width="14.70%"><p style="text-align:center">Single-stage Jenkins job</p></td> 
        <td class="acenter" width="15.97%"><p style="text-align:center">Multi-stage pipelines</p></td> 
        <td class="acenter" width="14.29%"><p style="text-align:center">Canary / Blue-Green flows</p></td> 
        <td class="acenter" width="14.29%"><p style="text-align:center">GitOps controllers</p></td> 
        <td class="acenter" width="14.29%"><p style="text-align:center">Avg. deploy steps automated</p></td> 
       </tr> 
       <tr> 
        <td class="acenter" width="14.29%"><p style="text-align:center">Policy Controls</p></td> 
        <td class="acenter" width="12.19%"><p style="text-align:center">None</p></td> 
        <td class="acenter" width="14.70%"><p style="text-align:center">Manual checklist</p></td> 
        <td class="acenter" width="15.97%"><p style="text-align:center">Basic policy gates (lint, unit tests)</p></td> 
        <td class="acenter" width="14.29%"><p style="text-align:center">OPA/Governance as code</p></td> 
        <td class="acenter" width="14.29%"><p style="text-align:center">Dynamic, risk-based gates</p></td> 
        <td class="acenter" width="14.29%"><p style="text-align:center">% deployments gate-checked</p></td> 
       </tr> 
       <tr> 
        <td class="custom-bottom-td acenter" width="14.29%"><p style="text-align:center">Rollback Strategy</p></td> 
        <td class="custom-bottom-td acenter" width="12.19%"><p style="text-align:center">Restore from backup</p></td> 
        <td class="custom-bottom-td acenter" width="14.70%"><p style="text-align:center">Manual scripts</p></td> 
        <td class="custom-bottom-td acenter" width="15.97%"><p style="text-align:center">Automated rollback</p></td> 
        <td class="custom-bottom-td acenter" width="14.29%"><p style="text-align:center">Automated + config versioning</p></td> 
        <td class="custom-bottom-td acenter" width="14.29%"><p style="text-align:center">Automated ver. pinning + DB migrations</p></td> 
        <td class="custom-bottom-td acenter" width="14.29%"><p style="text-align:center">MTTR after failed deploy</p></td> 
       </tr> 
      </table>
     </table-wrap>
     <p>Security-related dimensions (bold) and architecture agility remain below 20% coverage, reinforcing the research gap addressed by LADMF.</p>
    </sec>
    <sec id="s5_3">
     <title>5.3. Case-Study Quantitative Results</title>
     <p>The following section lists the observed KPI improvements in <xref ref-type="table" rid="table8">
       Table 8
      </xref>.</p>
     <table-wrap id="table8">
      <label>
       <xref ref-type="table" rid="table8">
        Table 8
       </xref></label>
      <caption>
       <title>
        <xref ref-type="bibr" rid="scirp.145228-"></xref>Table 8. Observed KPI improvements across maturity transitions.</title>
      </caption>
      <table class="MsoTableGrid custom-table" border="0" cellspacing="0" cellpadding="0"> 
       <tr> 
        <td class="custom-bottom-td custom-top-td acenter" width="16.05%"><p style="text-align:center">Case</p></td> 
        <td class="custom-bottom-td custom-top-td acenter" width="21.99%"><p style="text-align:center">Maturity Transition</p></td> 
        <td class="custom-bottom-td custom-top-td acenter" width="19.22%"><p style="text-align:center">Deploy Freq.(per wk)</p></td> 
        <td class="custom-bottom-td custom-top-td acenter" width="14.97%"><p style="text-align:center">Lead-Time (h)</p></td> 
        <td class="custom-bottom-td custom-top-td acenter" width="14.95%"><p style="text-align:center">MTTR (h)</p></td> 
        <td class="custom-bottom-td custom-top-td acenter" width="12.81%"><p style="text-align:center">CFR (%)</p></td> 
       </tr> 
       <tr> 
        <td class="custom-top-td acenter" width="16.05%"><p style="text-align:center">F-Bank</p></td> 
        <td class="custom-top-td acenter" width="21.99%"><p style="text-align:center">Interm. → Adv.</p></td> 
        <td class="custom-top-td acenter" width="19.22%"><p style="text-align:center">2.1 → 12.6 (↑6×)</p></td> 
        <td class="custom-top-td acenter" width="14.97%"><p style="text-align:center">23 → 4.1</p></td> 
        <td class="custom-top-td acenter" width="14.95%"><p style="text-align:center">4.8 → 3.0 (↓38%)</p></td> 
        <td class="custom-top-td acenter" width="12.81%"><p style="text-align:center">9.1 → 5.3</p></td> 
       </tr> 
       <tr> 
        <td class="acenter" width="16.05%"><p style="text-align:center">Stream Media</p></td> 
        <td class="acenter" width="21.99%"><p style="text-align:center">Begin. → Interm.</p></td> 
        <td class="acenter" width="19.22%"><p style="text-align:center">3.4 → 13.4 (↑4×)</p></td> 
        <td class="acenter" width="14.97%"><p style="text-align:center">36 → 6.2</p></td> 
        <td class="acenter" width="14.95%"><p style="text-align:center">3.6 → 2.8 (↓22%)</p></td> 
        <td class="acenter" width="12.81%"><p style="text-align:center">7.8 → 6.3</p></td> 
       </tr> 
       <tr> 
        <td class="custom-bottom-td acenter" width="16.05%"><p style="text-align:center">Telecom</p></td> 
        <td class="custom-bottom-td acenter" width="21.99%"><p style="text-align:center">Adv. → Expert</p></td> 
        <td class="custom-bottom-td acenter" width="19.22%"><p style="text-align:center">28 → 48 (↑1.7×)</p></td> 
        <td class="custom-bottom-td acenter" width="14.97%"><p style="text-align:center">2.8 → 1.3</p></td> 
        <td class="custom-bottom-td acenter" width="14.95%"><p style="text-align:center">1.1 → 0.8 (↓26%)</p></td> 
        <td class="custom-bottom-td acenter" width="12.81%"><p style="text-align:center">6.9 → 4.5</p></td> 
       </tr> 
      </table>
     </table-wrap>
     <p>At study entry, sites exhibited heterogeneous baseline LADMF levels—Beginner (StreamMedia), Intermediate (F-Bank), and Advanced (Telecom)—confirming that results are not limited to top-quartile maturity contexts. To probe selection bias, we compared KPI medians of our Beginner and Intermediate teams with DORA industry quartiles; values fell within the interquartile range, suggesting that the sample is not skewed toward exceptional performers. Nevertheless, the absence of a true non-adopter control limits causal inference (see §6.4).</p>
     <p>Statistical tests—Pooled data across sites show a significant drop in MTTR when advancing a maturity level (Mann-Whitney U = 241, p = 0.003, r = 0.54). Spearman correlation between maturity index (0 - 150) and deployment frequency is ρ = 0.67 (p &lt; 0.01). Lead-time distributions across maturity levels are visualized in <xref ref-type="fig" rid="fig4">
       Figure 4
      </xref>.</p>
     <fig id="fig4" position="float">
      <label>Figure 4</label>
      <caption>
       <title>
        <xref ref-type="bibr" rid="scirp.145228-"></xref>Figure 4. Violin Plot of Lead-Time vs. Maturity Level (Each violin depicts log-scaled lead-time distributions for levels 1 - 5; medians fall from 22 h (Novice) to 1.2 h (Expert)).</title>
      </caption>
      <graphic mimetype="image" position="float" xlink:type="simple" xlink:href="https://html.scirp.org/file/9303409-rId18.jpeg?20250828024639" />
     </fig>
    </sec>
    <sec id="s5_4">
     <title>5.4. Qualitative Cross-Case Analysis</title>
     <p>Coding of 26 interviews yielded 42 first-order codes, collapsed into nine axial themes. <xref ref-type="table" rid="table9">
       Table 9
      </xref> maps themes to exemplary quotations and the maturity domains they influence.</p>
     <p>Across cases, leadership commitment and toolchain cohesion emerged as the strongest enablers, while legacy architecture and regulatory inertia were the main inhibitors.</p>
     <table-wrap id="table9">
      <label>
       <xref ref-type="table" rid="table9">
        Table 9
       </xref></label>
      <caption>
       <title>
        <xref ref-type="bibr" rid="scirp.145228-"></xref>Table 9. Enablers and inhibitors of maturity progression.</title>
      </caption>
      <table class="MsoTableGrid custom-table" border="0" cellspacing="0" cellpadding="0"> 
       <tr> 
        <td class="custom-bottom-td custom-top-td acenter" width="20.95%"><p style="text-align:center">Theme</p></td> 
        <td class="custom-bottom-td custom-top-td acenter" width="12.81%"><p style="text-align:center">Role</p></td> 
        <td class="custom-bottom-td custom-top-td acenter" width="36.33%"><p style="text-align:center">Illustrative Quote</p></td> 
        <td class="custom-bottom-td custom-top-td acenter" width="29.91%"><p style="text-align:center">Affected Domain(s)</p></td> 
       </tr> 
       <tr> 
        <td class="custom-top-td acenter" width="20.95%"><p style="text-align:center">Executive Sponsorship</p></td> 
        <td class="custom-top-td acenter" width="12.81%"><p style="text-align:center">Enabler</p></td> 
        <td class="custom-top-td acenter" width="36.33%"><p style="text-align:center">“Our CIO mandated traceability for every deployment.”</p></td> 
        <td class="custom-top-td acenter" width="29.91%"><p style="text-align:center">Deployment Automation, Governance</p></td> 
       </tr> 
       <tr> 
        <td class="acenter" width="20.95%"><p style="text-align:center">Secure-by-Default Culture</p></td> 
        <td class="acenter" width="12.81%"><p style="text-align:center">Enabler</p></td> 
        <td class="acenter" width="36.33%"><p style="text-align:center">“Security gates fire on merge requests, not after release.”</p></td> 
        <td class="acenter" width="29.91%"><p style="text-align:center">Security Integration</p></td> 
       </tr> 
       <tr> 
        <td class="acenter" width="20.95%"><p style="text-align:center">Legacy Monoliths</p></td> 
        <td class="acenter" width="12.81%"><p style="text-align:center">Inhibitor</p></td> 
        <td class="acenter" width="36.33%"><p style="text-align:center">“We can’t canary-release a 4 GB monolith.”</p></td> 
        <td class="acenter" width="29.91%"><p style="text-align:center">Architecture &amp; Design</p></td> 
       </tr> 
       <tr> 
        <td class="custom-bottom-td acenter" width="20.95%"><p style="text-align:center">Compliance Fear</p></td> 
        <td class="custom-bottom-td acenter" width="12.81%"><p style="text-align:center">Inhibitor</p></td> 
        <td class="custom-bottom-td acenter" width="36.33%"><p style="text-align:center">“Audit still wants manual sign-offs.”</p></td> 
        <td class="custom-bottom-td acenter" width="29.91%"><p style="text-align:center">Build &amp; Release Mgmt., Security</p></td> 
       </tr> 
      </table>
     </table-wrap>
    </sec>
   </sec>
   <sec id="s6">
    <title>6. Discussion</title>
    <sec id="s6_1">
     <title>6.1. Synthesis of Findings</title>
     <p>Together, the quantitative and qualitative strands demonstrate that LADMF not only fills documented domain gaps but also tracks closely to outcome improvements that matter to business and risk stakeholders.</p>
    </sec>
    <sec id="s6_2">
     <title>6.2. Implications for Practitioners</title>
    </sec>
    <sec id="s6_3">
     <title>6.3. Relation to Prior Work</title>
     <p>Our mixed-methods evidence sharpens the largely descriptive work of CALMS-MM and CNCF’s model by anchoring maturity levels to DORA-style KPIs. Compared with the 2024 DevSecOps-MM, LADMF extends coverage to architectural agility and offers a scoring rubric validated across three industries—an advance over single-case antecedents.</p>
    </sec>
    <sec id="s6_4">
     <title>6.4. Threats to Validity</title>
     <p>Our cases are large enterprises in finance, media, and telecom. The framework’s applicability to healthcare, public sector, and start-ups—and to very small teams—remains to be tested. We therefore avoid universal claims and provide replication materials to enable evaluation in additional settings.</p>
     <p>Although we purposely sampled varying baseline maturities (Beginner, Intermediate, Advanced), participants may still be more engaged with DevOps than average organizations. To mitigate, we (i) pre-specified inclusion/exclusion criteria, (ii) used artifact-based scoring with dual independent raters, and (iii) benchmarked KPIs against external distributions. A non-adopter control group was not available; we treat observed associations as correlational.</p>
     <p>KPI changes were assessed using rolling 90-day medians; we did not run a longitudinal experiment with random assignments. Improvements concurrent with maturity uplifts could be confounded by co-occurring initiatives (e.g., headcount, funding). Pattern matching across three industries and convergent qualitative explanations reduce, but do not eliminate, this threat.</p>
     <p>Capability definitions were derived from a 78-paper corpus and reviewed with site SMEs. KPI operationalization followed DORA definitions. The remaining risk includes misclassification of incidents and team-reported practices.</p>
     <p>A full audit trail (rubrics, instruments, extraction templates) is provided to support independent replication.</p>
    </sec>
    <sec id="s6_5">
     <title>6.5. Future Work</title>
    </sec>
   </sec>
   <sec id="s7">
    <title>7. Conclusions</title>
    <p>This study delivers a rigorously validated Lean-Agile DevOps Maturity Framework (LADMF) that closes three long-standing gaps in the DevOps-maturity literature: weak empirical grounding, near-absence of security and architectural agility domains, and scarce outcome validation. A convergent mixed-methods design—combining a 78-paper systematic review with multi-industry case evidence spanning 2443 production deployments—demonstrates that higher LADMF scores align with materially better delivery performance (deployment frequency ↑, MTTR ↓, CFR ↓).</p>
    <sec id="s7_1">
     <title>7.1. Key Takeaways</title>
    </sec>
    <sec id="s7_2">
     <title>7.2. Limitations</title>
     <p>Limitations include the focus on three large enterprises, potential self-selection bias, and the cross-sectional nature of KPI measurement. Future work should automate telemetry-driven scoring, replicate the framework in additional sectors (e.g., healthcare, public-sector, start-ups), and conduct longitudinal studies to quantify long-term ROI of domain-specific improvements.</p>
     <p>By fusing evidence from both scholarship and practice, LADMF offers organizations a defensible roadmap for continuous improvement—accelerating delivery while embedding security and architectural resilience at the core of the DevOps journey.</p>
     <p>Given the study’s enterprise focus and correlational design, we encourage readers to treat results as general guidance rather than causal proof, and we provide a roadmap (§ 6.5) for achieving stronger generalizability and causal identification in future work.</p>
    </sec>
   </sec>
   <sec id="s8">
    <title>Appendix A: Domain Rubrics</title>
    <p>
     <xref ref-type="bibr" rid="scirp.145228-"></xref>A.1 Testing Maturity</p>
    <table class="MsoTableGrid custom-table" border="0" cellspacing="0" cellpadding="0"> 
     <tr> 
      <td class="custom-bottom-td custom-top-td acenter" width="11.76%"><p style="text-align:center">Level</p></td> 
      <td class="custom-bottom-td custom-top-td acenter" width="20.10%"><p style="text-align:center">Descriptor</p></td> 
      <td class="custom-bottom-td custom-top-td acenter" width="20.10%"><p style="text-align:center">Practices</p></td> 
      <td class="custom-bottom-td custom-top-td acenter" width="20.11%"><p style="text-align:center">Tools/Automation</p></td> 
      <td class="custom-bottom-td custom-top-td acenter" width="27.94%"><p style="text-align:center">Metrics</p></td> 
     </tr> 
     <tr> 
      <td class="custom-top-td acenter" width="11.76%"><p style="text-align:center">Novice</p></td> 
      <td class="custom-top-td acenter" width="20.10%"><p style="text-align:center">Ad-hoc, manual testing</p></td> 
      <td class="custom-top-td acenter" width="20.10%"><p style="text-align:center">Exploratory testing only</p></td> 
      <td class="custom-top-td acenter" width="20.11%"><p style="text-align:center">None</p></td> 
      <td class="custom-top-td acenter" width="27.94%"><p style="text-align:center">Defect density &gt; 10/KSLOC</p></td> 
     </tr> 
     <tr> 
      <td class="acenter" width="11.76%"><p style="text-align:center">Beginner</p></td> 
      <td class="acenter" width="20.10%"><p style="text-align:center">Unit testing introduced</p></td> 
      <td class="acenter" width="20.10%"><p style="text-align:center">Manual regression; some unit tests</p></td> 
      <td class="acenter" width="20.11%"><p style="text-align:center">JUnit, NUnit</p></td> 
      <td class="acenter" width="27.94%"><p style="text-align:center">≤30% coverage</p></td> 
     </tr> 
     <tr> 
      <td class="acenter" width="11.76%"><p style="text-align:center">Intermediate</p></td> 
      <td class="acenter" width="20.10%"><p style="text-align:center">Automated regression across tiers</p></td> 
      <td class="acenter" width="20.10%"><p style="text-align:center">CI-integrated test suites</p></td> 
      <td class="acenter" width="20.11%"><p style="text-align:center">Selenium, JMeter</p></td> 
      <td class="acenter" width="27.94%"><p style="text-align:center">50 - 70% coverage; avg. defect escape ≤ 15%</p></td> 
     </tr> 
     <tr> 
      <td class="acenter" width="11.76%"><p style="text-align:center">Advanced</p></td> 
      <td class="acenter" width="20.10%"><p style="text-align:center">Shift-left testing, test data mgmt</p></td> 
      <td class="acenter" width="20.10%"><p style="text-align:center">CI/CD with automated regression</p></td> 
      <td class="acenter" width="20.11%"><p style="text-align:center">TestContainers, Mock servers</p></td> 
      <td class="acenter" width="27.94%"><p style="text-align:center">&gt;80% coverage; defect escape &lt; 10%</p></td> 
     </tr> 
     <tr> 
      <td class="custom-bottom-td acenter" width="11.76%"><p style="text-align:center">Expert</p></td> 
      <td class="custom-bottom-td acenter" width="20.10%"><p style="text-align:center">Continuous, AI-assisted validation</p></td> 
      <td class="custom-bottom-td acenter" width="20.10%"><p style="text-align:center">Self-healing tests, chaos injection</p></td> 
      <td class="custom-bottom-td acenter" width="20.11%"><p style="text-align:center">AI test bots, ChaosMesh</p></td> 
      <td class="custom-bottom-td acenter" width="27.94%"><p style="text-align:center">Near-100% coverage; MTTR for test defects &lt; 1 h</p></td> 
     </tr> 
    </table>
    <p>A.2 Telemetry &amp; Observability</p>
    <table class="MsoTableGrid custom-table" border="0" cellspacing="0" cellpadding="0"> 
     <tr> 
      <td class="custom-bottom-td custom-top-td acenter" width="10.56%"><p style="text-align:center">Level</p></td> 
      <td class="custom-bottom-td custom-top-td acenter" width="26.21%"><p style="text-align:center">Descriptor</p></td> 
      <td class="custom-bottom-td custom-top-td acenter" width="23.53%"><p style="text-align:center">Practices</p></td> 
      <td class="custom-bottom-td custom-top-td acenter" width="22.06%"><p style="text-align:center">Tools/Automation</p></td> 
      <td class="custom-bottom-td custom-top-td acenter" width="17.65%"><p style="text-align:center">Metrics</p></td> 
     </tr> 
     <tr> 
      <td class="custom-top-td acenter" width="10.56%"><p style="text-align:center">Novice</p></td> 
      <td class="custom-top-td acenter" width="26.21%"><p style="text-align:center">Minimal monitoring</p></td> 
      <td class="custom-top-td acenter" width="23.53%"><p style="text-align:center">Ad-hoc logs, manual checks</p></td> 
      <td class="custom-top-td acenter" width="22.06%"><p style="text-align:center">Syslog</p></td> 
      <td class="custom-top-td acenter" width="17.65%"><p style="text-align:center">MTTR &gt; 24 h</p></td> 
     </tr> 
     <tr> 
      <td class="acenter" width="10.56%"><p style="text-align:center">Beginner</p></td> 
      <td class="acenter" width="26.21%"><p style="text-align:center">Basic monitoring</p></td> 
      <td class="acenter" width="23.53%"><p style="text-align:center">Log collection, alerts</p></td> 
      <td class="acenter" width="22.06%"><p style="text-align:center">Nagios, ELK</p></td> 
      <td class="acenter" width="17.65%"><p style="text-align:center">MTTR ~ 12 h</p></td> 
     </tr> 
     <tr> 
      <td class="acenter" width="10.56%"><p style="text-align:center">Intermediate</p></td> 
      <td class="acenter" width="26.21%"><p style="text-align:center">Centralized dashboards</p></td> 
      <td class="acenter" width="23.53%"><p style="text-align:center">Metric aggregation</p></td> 
      <td class="acenter" width="22.06%"><p style="text-align:center">Prometheus, Grafana</p></td> 
      <td class="acenter" width="17.65%"><p style="text-align:center">MTTR ~ 6 h</p></td> 
     </tr> 
     <tr> 
      <td class="acenter" width="10.56%"><p style="text-align:center">Advanced</p></td> 
      <td class="acenter" width="26.21%"><p style="text-align:center">Distributed tracing, SLO-driven</p></td> 
      <td class="acenter" width="23.53%"><p style="text-align:center">Trace correlation</p></td> 
      <td class="acenter" width="22.06%"><p style="text-align:center">Jaeger, OpenTelemetry</p></td> 
      <td class="acenter" width="17.65%"><p style="text-align:center">MTTR ≤ 2 h</p></td> 
     </tr> 
     <tr> 
      <td class="custom-bottom-td acenter" width="10.56%"><p style="text-align:center">Expert</p></td> 
      <td class="custom-bottom-td acenter" width="26.21%"><p style="text-align:center">Proactive anomaly detection</p></td> 
      <td class="custom-bottom-td acenter" width="23.53%"><p style="text-align:center">AI/ML anomaly detection</p></td> 
      <td class="custom-bottom-td acenter" width="22.06%"><p style="text-align:center">Datadog, Dynatrace AI</p></td> 
      <td class="custom-bottom-td acenter" width="17.65%"><p style="text-align:center">MTTR ≤ 30 min; &lt;5% alert noise</p></td> 
     </tr> 
    </table>
    <p>A.3 Build &amp; Release Management</p>
    <table class="MsoTableGrid custom-table" border="0" cellspacing="0" cellpadding="0"> 
     <tr> 
      <td class="custom-bottom-td custom-top-td acenter" width="10.70%"><p style="text-align:center">Level</p></td> 
      <td class="custom-bottom-td custom-top-td acenter" width="21.73%"><p style="text-align:center">Descriptor</p></td> 
      <td class="custom-bottom-td custom-top-td acenter" width="21.55%"><p style="text-align:center">Practices</p></td> 
      <td class="custom-bottom-td custom-top-td acenter" width="15.85%"><p style="text-align:center">Tools/Automation</p></td> 
      <td class="custom-bottom-td custom-top-td acenter" width="20.99%"><p style="text-align:center">Metrics</p></td> 
     </tr> 
     <tr> 
      <td class="custom-top-td acenter" width="10.70%"><p style="text-align:center">Novice</p></td> 
      <td class="custom-top-td acenter" width="21.73%"><p style="text-align:center">Manual build/release</p></td> 
      <td class="custom-top-td acenter" width="21.55%"><p style="text-align:center">Informal scripts</p></td> 
      <td class="custom-top-td acenter" width="15.85%"><p style="text-align:center">Ant, Make</p></td> 
      <td class="custom-top-td acenter" width="20.99%"><p style="text-align:center">Release cycle &gt; 1 month</p></td> 
     </tr> 
     <tr> 
      <td class="acenter" width="10.70%"><p style="text-align:center">Beginner</p></td> 
      <td class="acenter" width="21.73%"><p style="text-align:center">Automated builds</p></td> 
      <td class="acenter" width="21.55%"><p style="text-align:center">CI server adoption</p></td> 
      <td class="acenter" width="15.85%"><p style="text-align:center">Jenkins, GitLab CI</p></td> 
      <td class="acenter" width="20.99%"><p style="text-align:center">Weekly builds</p></td> 
     </tr> 
     <tr> 
      <td class="acenter" width="10.70%"><p style="text-align:center">Intermediate</p></td> 
      <td class="acenter" width="21.73%"><p style="text-align:center">Versioned artifacts</p></td> 
      <td class="acenter" width="21.55%"><p style="text-align:center">Release orchestration</p></td> 
      <td class="acenter" width="15.85%"><p style="text-align:center">Maven, Gradle</p></td> 
      <td class="acenter" width="20.99%"><p style="text-align:center">Lead time ≤ 1 week</p></td> 
     </tr> 
     <tr> 
      <td class="acenter" width="10.70%"><p style="text-align:center">Advanced</p></td> 
      <td class="acenter" width="21.73%"><p style="text-align:center">Policy-as-code release gates</p></td> 
      <td class="acenter" width="21.55%"><p style="text-align:center">Canary, blue/green deploys</p></td> 
      <td class="acenter" width="15.85%"><p style="text-align:center">Spinnaker, ArgoCD</p></td> 
      <td class="acenter" width="20.99%"><p style="text-align:center">Lead time ≤ 1 day</p></td> 
     </tr> 
     <tr> 
      <td class="custom-bottom-td acenter" width="10.70%"><p style="text-align:center">Expert</p></td> 
      <td class="custom-bottom-td acenter" width="21.73%"><p style="text-align:center">Zero-touch releases</p></td> 
      <td class="custom-bottom-td acenter" width="21.55%"><p style="text-align:center">Self-adaptive pipelines</p></td> 
      <td class="custom-bottom-td acenter" width="15.85%"><p style="text-align:center">FluxCD, Tekton</p></td> 
      <td class="custom-bottom-td acenter" width="20.99%"><p style="text-align:center">Lead time ≤ 1 h; CFR &lt; 5%</p></td> 
     </tr> 
    </table>
    <p>A.4 Security Integration</p>
    <table class="MsoTableGrid custom-table" border="0" cellspacing="0" cellpadding="0"> 
     <tr> 
      <td class="custom-bottom-td custom-top-td acenter" width="10.70%"><p style="text-align:center">Level</p></td> 
      <td class="custom-bottom-td custom-top-td acenter" width="17.72%"><p style="text-align:center">Descriptor</p></td> 
      <td class="custom-bottom-td custom-top-td acenter" width="19.27%"><p style="text-align:center">Practices</p></td> 
      <td class="custom-bottom-td custom-top-td acenter" width="19.34%"><p style="text-align:center">Tools/Automation</p></td> 
      <td class="custom-bottom-td custom-top-td acenter" width="24.63%"><p style="text-align:center">Metrics</p></td> 
     </tr> 
     <tr> 
      <td class="custom-top-td acenter" width="10.70%"><p style="text-align:center">Novice</p></td> 
      <td class="custom-top-td acenter" width="17.72%"><p style="text-align:center">Security bolted-on</p></td> 
      <td class="custom-top-td acenter" width="19.27%"><p style="text-align:center">After-the-fact audits</p></td> 
      <td class="custom-top-td acenter" width="19.34%"><p style="text-align:center">None</p></td> 
      <td class="custom-top-td acenter" width="24.63%"><p style="text-align:center">Vulnerabilities unresolved</p></td> 
     </tr> 
     <tr> 
      <td class="acenter" width="10.70%"><p style="text-align:center">Beginner</p></td> 
      <td class="acenter" width="17.72%"><p style="text-align:center">Basic scanning</p></td> 
      <td class="acenter" width="19.27%"><p style="text-align:center">Static analysis in CI</p></td> 
      <td class="acenter" width="19.34%"><p style="text-align:center">SonarQube, Snyk</p></td> 
      <td class="acenter" width="24.63%"><p style="text-align:center">≤50% critical vuln. resolved</p></td> 
     </tr> 
     <tr> 
      <td class="acenter" width="10.70%"><p style="text-align:center">Intermediate</p></td> 
      <td class="acenter" width="17.72%"><p style="text-align:center">Integrated DevSecOps</p></td> 
      <td class="acenter" width="19.27%"><p style="text-align:center">DAST &amp; SAST pipelines</p></td> 
      <td class="acenter" width="19.34%"><p style="text-align:center">OWASP ZAP, Veracode</p></td> 
      <td class="acenter" width="24.63%"><p style="text-align:center">SLA ≤ 7 days for critical</p></td> 
     </tr> 
     <tr> 
      <td class="acenter" width="10.70%"><p style="text-align:center">Advanced</p></td> 
      <td class="acenter" width="17.72%"><p style="text-align:center">Policy-as-code</p></td> 
      <td class="acenter" width="19.27%"><p style="text-align:center">Automated compliance</p></td> 
      <td class="acenter" width="19.34%"><p style="text-align:center">OPA, Checkov</p></td> 
      <td class="acenter" width="24.63%"><p style="text-align:center">SLA ≤ 72 h</p></td> 
     </tr> 
     <tr> 
      <td class="custom-bottom-td acenter" width="10.70%"><p style="text-align:center">Expert</p></td> 
      <td class="custom-bottom-td acenter" width="17.72%"><p style="text-align:center">Continuous assurance</p></td> 
      <td class="custom-bottom-td acenter" width="19.27%"><p style="text-align:center">AI/ML threat detection</p></td> 
      <td class="custom-bottom-td acenter" width="19.34%"><p style="text-align:center">Darktrace, GuardDuty</p></td> 
      <td class="custom-bottom-td acenter" width="24.63%"><p style="text-align:center">SLA ≤ 24 h; &lt;5% false positives</p></td> 
     </tr> 
    </table>
    <p>A.5 Architecture &amp; Design</p>
    <table class="MsoTableGrid custom-table" border="0" cellspacing="0" cellpadding="0"> 
     <tr> 
      <td class="custom-bottom-td custom-top-td acenter" width="10.70%"><p style="text-align:center">Level</p></td> 
      <td class="custom-bottom-td custom-top-td acenter" width="21.86%"><p style="text-align:center">Descriptor</p></td> 
      <td class="custom-bottom-td custom-top-td acenter" width="23.33%"><p style="text-align:center">Practices</p></td> 
      <td class="custom-bottom-td custom-top-td acenter" width="22.06%"><p style="text-align:center">Tools/Automation</p></td> 
      <td class="custom-bottom-td custom-top-td acenter" width="22.06%"><p style="text-align:center">Metrics</p></td> 
     </tr> 
     <tr> 
      <td class="custom-top-td acenter" width="10.70%"><p style="text-align:center">Novice</p></td> 
      <td class="custom-top-td acenter" width="21.86%"><p style="text-align:center">Monolithic architecture</p></td> 
      <td class="custom-top-td acenter" width="23.33%"><p style="text-align:center">Minimal design foresight</p></td> 
      <td class="custom-top-td acenter" width="22.06%"><p style="text-align:center">N/A</p></td> 
      <td class="custom-top-td acenter" width="22.06%"><p style="text-align:center">Change latency &gt; 1 month</p></td> 
     </tr> 
     <tr> 
      <td class="acenter" width="10.70%"><p style="text-align:center">Beginner</p></td> 
      <td class="acenter" width="21.86%"><p style="text-align:center">Layered modules</p></td> 
      <td class="acenter" width="23.33%"><p style="text-align:center">Initial refactoring</p></td> 
      <td class="acenter" width="22.06%"><p style="text-align:center">UML, PlantUML</p></td> 
      <td class="acenter" width="22.06%"><p style="text-align:center">Change latency ≤ 3 weeks</p></td> 
     </tr> 
     <tr> 
      <td class="acenter" width="10.70%"><p style="text-align:center">Intermediate</p></td> 
      <td class="acenter" width="21.86%"><p style="text-align:center">Service decomposition</p></td> 
      <td class="acenter" width="23.33%"><p style="text-align:center">Microservices adoption</p></td> 
      <td class="acenter" width="22.06%"><p style="text-align:center">Docker, Kubernetes</p></td> 
      <td class="acenter" width="22.06%"><p style="text-align:center">Change latency ≤ 1 week</p></td> 
     </tr> 
     <tr> 
      <td class="acenter" width="10.70%"><p style="text-align:center">Advanced</p></td> 
      <td class="acenter" width="21.86%"><p style="text-align:center">Evolvable architecture</p></td> 
      <td class="acenter" width="23.33%"><p style="text-align:center">Event-driven, hexagonal</p></td> 
      <td class="acenter" width="22.06%"><p style="text-align:center">Kafka, Istio</p></td> 
      <td class="acenter" width="22.06%"><p style="text-align:center">Change latency ≤ 1 day</p></td> 
     </tr> 
     <tr> 
      <td class="custom-bottom-td acenter" width="10.70%"><p style="text-align:center">Expert</p></td> 
      <td class="custom-bottom-td acenter" width="21.86%"><p style="text-align:center">Self-adaptive architecture</p></td> 
      <td class="custom-bottom-td acenter" width="23.33%"><p style="text-align:center">Continuous fitness functions</p></td> 
      <td class="custom-bottom-td acenter" width="22.06%"><p style="text-align:center">Fitness functions (Netflix), AI-driven refactoring</p></td> 
      <td class="custom-bottom-td acenter" width="22.06%"><p style="text-align:center">Change latency ≤ 1 h</p></td> 
     </tr> 
    </table>
   </sec>
  </sec>
 </body><back>
  <ref-list>
   <title>References</title>
   <ref id="scirp.145228-ref1">
    <label>1</label>
    <mixed-citation publication-type="other" xlink:type="simple">
     Forsgren, N., Humble, J. and Kim, G. (2018) Accelerate: The Science of Lean Software and DevOps, IT Revolution.
    </mixed-citation>
   </ref>
   <ref id="scirp.145228-ref2">
    <label>2</label>
    <mixed-citation publication-type="other" xlink:type="simple">
     Erich, T., Ameller, T. and Franch, X. (2022) Assessing the Maturity of DevOps Practices in Software Industry. 2022 ACM/IEEE International Symposium on Empirical Software Engineering and Measurement, Helsinki, 19-23 September 2022, 1-10.
    </mixed-citation>
   </ref>
   <ref id="scirp.145228-ref3">
    <label>3</label>
    <mixed-citation publication-type="other" xlink:type="simple">
     Lwakatare, L.E., Kilamo, T., Karvonen, T., Sauvola, T., Heikkilä, V., Itkonen, J., et al. (2019) Devops in Practice: A Multiple Case Study of Five Companies. Information and Software Technology, 114, 217-230. &gt;https://doi.org/10.1016/j.infsof.2019.06.010
    </mixed-citation>
   </ref>
   <ref id="scirp.145228-ref4">
    <label>4</label>
    <mixed-citation publication-type="other" xlink:type="simple">
     Lwakatare, A., Kääriäinen, M. and Lassenius, P. (2022) DevOps in Finnish Software Industry: A Maturity Model. Journal of Systems and Software, 194, 1113-1125.
    </mixed-citation>
   </ref>
   <ref id="scirp.145228-ref5">
    <label>5</label>
    <mixed-citation publication-type="other" xlink:type="simple">
     Bass, M., Bass, I. and Wang, L. (2021) Security Integration in Continuous-Delivery Pipelines. IEEE Software, 38, 54-62.
    </mixed-citation>
   </ref>
   <ref id="scirp.145228-ref6">
    <label>6</label>
    <mixed-citation publication-type="other" xlink:type="simple">
     Rodriguez, G., et al. (2024) A DevSecOps Capability Maturity Model. International Journal of Information Security, 23, 527-546. 
    </mixed-citation>
   </ref>
   <ref id="scirp.145228-ref7">
    <label>7</label>
    <mixed-citation publication-type="other" xlink:type="simple">
     Fitzgerald, P. and Stol, A. (2024) Architecturally Agile DevOps. IEEE Software, 41, 48-56.
    </mixed-citation>
   </ref>
   <ref id="scirp.145228-ref8">
    <label>8</label>
    <mixed-citation publication-type="other" xlink:type="simple">
     Leite, H. and da Silva, F. (2024) CALMS Revisited: A Critical Review of DevOps Maturity Constructs. Proceedings of the 2024 International Conference on Software and Systems Processes, Munich, 4-5 September 2024, 45-55.
    </mixed-citation>
   </ref>
   <ref id="scirp.145228-ref9">
    <label>9</label>
    <mixed-citation publication-type="other" xlink:type="simple">
     Yin, R.K. (2014) Case Study Research: Design and Methods. 5th Edition, Sage Publications.
    </mixed-citation>
   </ref>
   <ref id="scirp.145228-ref10">
    <label>10</label>
    <mixed-citation publication-type="other" xlink:type="simple">
     Meyer, A. and Wagner, L. (2023) Infrastructure as Code Adoption Patterns. 2023 IEEE/ACM 45th International Conference on Software Engineering, Melbourne, 14-20 May 2023, 1-12.
    </mixed-citation>
   </ref>
   <ref id="scirp.145228-ref11">
    <label>11</label>
    <mixed-citation publication-type="other" xlink:type="simple">
     Kim, I. and Lee, J. (2023) Continuous Deployment Rollback Strategies: A Comparative Study. Journal of Systems and Software, 201, Article 111087.
    </mixed-citation>
   </ref>
   <ref id="scirp.145228-ref12">
    <label>12</label>
    <mixed-citation publication-type="other" xlink:type="simple">
     Gebrewold, S. and Wirell, P. (2024) Automated Measurement of DORA Metrics. Proceedings of the 15th ACM/SPEC International Conference on Performance Engineering, London, 7-11 May 2024, 65-76.
    </mixed-citation>
   </ref>
   <ref id="scirp.145228-ref13">
    <label>13</label>
    <mixed-citation publication-type="other" xlink:type="simple">
     Bass, J. (2022) Microservice Architecture and Continuous Delivery. Journal of Internet Services and Applications, 13, Article 5.
    </mixed-citation>
   </ref>
   <ref id="scirp.145228-ref14">
    <label>14</label>
    <mixed-citation publication-type="other" xlink:type="simple">
     Ahmed, A.S. (2024) Policy-as-Code Gatekeepers for Secure CD. IEEE Access, 12, 102219-102241. &gt;https://doi.org/10.1109/ACCESS.2024.3429205 
    </mixed-citation>
   </ref>
   <ref id="scirp.145228-ref15">
    <label>15</label>
    <mixed-citation publication-type="other" xlink:type="simple">
     Shahin, R., Ali Babar, M. and Zhang, L. (2023) Automated Testing Practices in DevOps Pipelines. Information and Software Technology, 151, Article 107139.
    </mixed-citation>
   </ref>
   <ref id="scirp.145228-ref16">
    <label>16</label>
    <mixed-citation publication-type="other" xlink:type="simple">
     Kruchten, S., et al. (2023) Evolutionary Architectures in DevOps Context. Software Quality Journal, 31, 1-25.
    </mixed-citation>
   </ref>
   <ref id="scirp.145228-ref17">
    <label>17</label>
    <mixed-citation publication-type="other" xlink:type="simple">
     Mann, K. and Kwan, E. (2023) Threat-Modelling Automation in CI Pipelines. Computers&amp;Security, 130, Article 102937.
    </mixed-citation>
   </ref>
   <ref id="scirp.145228-ref18">
    <label>18</label>
    <mixed-citation publication-type="other" xlink:type="simple">
     Humble, T. (2021) From CALMS to CALMS-S: Extending DevOps with Security. Proceedings of XP, Springer, 2021, 18-29. 
    </mixed-citation>
   </ref>
   <ref id="scirp.145228-ref19">
    <label>19</label>
    <mixed-citation publication-type="other" xlink:type="simple">
     Kim, D. (2022) Lead-Time Reduction through Trunk-Based Development. ACM Queue, 20, 45-57.
    </mixed-citation>
   </ref>
   <ref id="scirp.145228-ref20">
    <label>20</label>
    <mixed-citation publication-type="other" xlink:type="simple">
     Rahman, Z. (2023) Shift-Left Performance Testing. IEEE Software, 40, 71-79.
    </mixed-citation>
   </ref>
   <ref id="scirp.145228-ref21">
    <label>21</label>
    <mixed-citation publication-type="other" xlink:type="simple">
     Ward, J.O. and Simmons, C. (2022) Chaos Engineering for Reliability Maturity. 2022 IEEE 33rd International Symposium on Software Reliability Engineering, Charlotte, 31 October-3 November 2022, 101-112.
    </mixed-citation>
   </ref>
   <ref id="scirp.145228-ref22">
    <label>22</label>
    <mixed-citation publication-type="other" xlink:type="simple">
     Shahin, P. and Babar, A. (2023) Critical Success Factors for DevOps Projects: A Systematic Review. Journal of Systems and Software, 198, Article 111041.
    </mixed-citation>
   </ref>
   <ref id="scirp.145228-ref23">
    <label>23</label>
    <mixed-citation publication-type="other" xlink:type="simple">
     Syed, N. (2023) Quantifying DevOps ROI. IEEE Transactions on Engineering Management, 70, 2281-2294.
    </mixed-citation>
   </ref>
   <ref id="scirp.145228-ref24">
    <label>24</label>
    <mixed-citation publication-type="other" xlink:type="simple">
     Calderon, F.P. (2022) Observability as an Enabler of Continuous Delivery. 2022 International Conference on Science Education and Art Appreciation, Chengdu, 24-26 June 2022, 43-50.
    </mixed-citation>
   </ref>
   <ref id="scirp.145228-ref25">
    <label>25</label>
    <mixed-citation publication-type="other" xlink:type="simple">
     Eriksson, S. (2023) Governance Patterns in Regulated DevOps. Software Quality Journal, 31, 1-21.
    </mixed-citation>
   </ref>
   <ref id="scirp.145228-ref26">
    <label>26</label>
    <mixed-citation publication-type="other" xlink:type="simple">
     Lowy, J. and Goyal, A. (2023) GitOps Controllers for Policy-Driven Deployments. IEEE Cloud Computing, 10, 63-75.
    </mixed-citation>
   </ref>
   <ref id="scirp.145228-ref27">
    <label>27</label>
    <mixed-citation publication-type="other" xlink:type="simple">
     Palacio, E. (2023) Mean-Time-to-Recovery Benchmarks. ACM SIGSOFT Notes, 48, 34-45.
    </mixed-citation>
   </ref>
   <ref id="scirp.145228-ref28">
    <label>28</label>
    <mixed-citation publication-type="other" xlink:type="simple">
     George, B. (2022) Deployment Frequency as a Predictor of Business Performance. Information and Software Technology, 146, Article 107181.
    </mixed-citation>
   </ref>
   <ref id="scirp.145228-ref29">
    <label>29</label>
    <mixed-citation publication-type="other" xlink:type="simple">
     Kääriäinen, M. (2023) Immutable Infrastructure Patterns. Proceedings of DevOpsDays, Washington, 13-14 September 2023, 73-84.
    </mixed-citation>
   </ref>
   <ref id="scirp.145228-ref30">
    <label>30</label>
    <mixed-citation publication-type="other" xlink:type="simple">
     Wang, L. (2023) Policy-as-Code with OPA. IEEE Access, 11, 23045-23062.
    </mixed-citation>
   </ref>
   <ref id="scirp.145228-ref31">
    <label>31</label>
    <mixed-citation publication-type="other" xlink:type="simple">
     Kim, J.H. and Sousa, A. (2023) Continuous Compliance in CD Pipelines. Journal of Internet Technology, 24, 223-238.
    </mixed-citation>
   </ref>
   <ref id="scirp.145228-ref32">
    <label>32</label>
    <mixed-citation publication-type="other" xlink:type="simple">
     Lim, S.R. (2023) Automated Architecture Fitness Functions. Journal of Systems and Software, 200, Article 111143.
    </mixed-citation>
   </ref>
   <ref id="scirp.145228-ref33">
    <label>33</label>
    <mixed-citation publication-type="other" xlink:type="simple">
     de Oliveira, R. (2023) DevOps Metrics SLR. Software Maintenance and Evolution: A Roadmap, 35, e2227.
    </mixed-citation>
   </ref>
   <ref id="scirp.145228-ref34">
    <label>34</label>
    <mixed-citation publication-type="other" xlink:type="simple">
     Bass, I. (2023) Legacy Modernisation Strategies for DevOps. IEEE Software, 40, 28-36.
    </mixed-citation>
   </ref>
   <ref id="scirp.145228-ref35">
    <label>35</label>
    <mixed-citation publication-type="other" xlink:type="simple">
     Murphy-Hill, E. (2022) Psychological Safety and DevOps Culture. 2022 IEEE/ACM 44th International Conference on Software Engineering, Pittsburgh, 25-27 May 2022, 52-63.
    </mixed-citation>
   </ref>
   <ref id="scirp.145228-ref36">
    <label>36</label>
    <mixed-citation publication-type="other" xlink:type="simple">
     Prates, L. and Pereira, R. (2024) DevSecOps Practices and Tools. International Journal of Information Security, 24, Article No. 11. &gt;https://doi.org/10.1007/s10207-024-00914-z
    </mixed-citation>
   </ref>
   <ref id="scirp.145228-ref37">
    <label>37</label>
    <mixed-citation publication-type="other" xlink:type="simple">
     Gebremariam, U. (2024) DORA Metric Challenges. 2024 ACM/IEEE International Symposium on Empirical Software Engineering and Measurement, Barcelona, 24-25 October 2024, 121-132.
    </mixed-citation>
   </ref>
   <ref id="scirp.145228-ref38">
    <label>38</label>
    <mixed-citation publication-type="other" xlink:type="simple">
     Ståhl, S. (2023) Infrastructure-as-Code Coverage Metrics. 2023 Proceedings of the 38th IEEE/ACM International Conference on Automated Software Engineering, Luxembourg, 11-15 September 2023, 701-712.
    </mixed-citation>
   </ref>
   <ref id="scirp.145228-ref39">
    <label>39</label>
    <mixed-citation publication-type="other" xlink:type="simple">
     Durham, C.D. (2024) Canary Deployment Taxonomy. ACM Computing Surveys, 56, Article No. 53.
    </mixed-citation>
   </ref>
   <ref id="scirp.145228-ref40">
    <label>40</label>
    <mixed-citation publication-type="other" xlink:type="simple">
     Harrison, K.M. (2024) Automated Compliance as Code in PCI-DSS. Proceedings of the 2024 International Conference on Software and Systems Processes, Munich, 4-6 September 2024, 91-102.
    </mixed-citation>
   </ref>
  </ref-list>
 </back>
</article>