Risks of using Low-Code platforms in ITSM environments: A systematic review

Main Article Content

Tania Ycela Chavez Alva
Anghela Tatiana Herrera Rodríguez
Alberto Carlos Mendoza de los Santos

Abstract

Low-Code platforms have experienced rapid adoption in organizations seeking to streamline IT service management (ITSM). However, this integration introduces critical vulnerabilities, especially when interacting with legacy systems through insecure APIs and weak access controls. This research presents a systematic literature review using the PRISMA methodology to identify and classify the main security and compliance risks inherent in the use of Low-Code platforms in regulated ITSM environments. Twenty-five articles were selected from a total of 52 records identified in databases such as Scopus, Dialnet, SciELO, Redalyc, Google Scholar, and ResearchGate, published between 2018 and 2025. The results show that insufficient access controls, exposed APIs, shadow IT and SQL injection represent the most frequent risks, with exposure rates exceeding 60% in hybrid integrations. It was also identified that compliance with GDPR and ISO 27001 is critically compromised when Low-Code platforms interact with legacy systems without formalized security architectures.

Article Details

How to Cite
Risks of using Low-Code platforms in ITSM environments: A systematic review. (2026). C&T Riqchary Science and Technology Research Magazine, 8(1), 63-70. https://doi.org/10.57166/riqchary/v8.n1.2026.8
Section
Artículos

How to Cite

Risks of using Low-Code platforms in ITSM environments: A systematic review. (2026). C&T Riqchary Science and Technology Research Magazine, 8(1), 63-70. https://doi.org/10.57166/riqchary/v8.n1.2026.8

References

[1] M. Botto-Tobar and C. Neil, “Evaluando la calidad de las aplicaciones Low-Code: Un mapeo sistemático de la literatura,” Revista Conectividad, vol. 5, no. 1, pp. 93–108, 2024. https://doi.org/10.37431/conectividad.v5i1.97

[2] P. L. Huamán Coronel and C. G. Medina Sotelo, “Transformación digital en la administración pública: desafíos para una gobernanza activa en el Perú,” Comuni@cción, vol. 13, no. 2, pp. 93–105, 2022. https://doi.org/10.33595/2226-1478.13.2.594

[3] M. E. Caciano-Arroyo, A. F. Vasquez-Cabrera, and A. C. Mendoza-de-los-Santos, “Integración de inteligencia artificial en la gobernanza de TI: Una revisión sistemática,” AiBi Revista de Investigación, Administración e Ingeniería, vol. 13, no. 2, 2025. https://doi.org/10.15649/2346030X.4532

[4] V. E. Ojeda Muñoz and S. Casas, “Caso de estudio comparativo de plataformas Low-Code,” Informes Científicos Técnicos – UNPA, vol. 16, no. 1, pp. 186–208, 2024. https://doi.org/10.22305/ict-unpa.v16.n1.1105

[5] A. L. López Naranjo, G. G. Uquillas Granizo, I. M. Jácome Lara, and F. P. Pérez Salas, “La transformación digital en la administración pública: evolución y tendencias de investigación,” Perspectivas Sociales y Administrativas, vol. 3, no. 1, pp. 17–36, 2025. https://doi.org/10.61347/psa.v3i1.74

[6] R. E. Suárez Toala and L. V. Venegas Loor, “Evaluación de la madurez tecnológica en la Universidad Estatal del Sur de Manabí,” Pentaciencias, vol. 5, no. 5, pp. 66–85, 2023. https://doi.org/10.59169/pentaciencias.v5i5.722

[7] S. E. Díaz Alvarado, “Gestión del riesgo tecnológico en la modernización de sistemas legacy: Estrategias para una transición eficiente,” Ciencia Latina, vol. 9, no. 6, pp. 3449–3468, 2025. https://doi.org/10.37811/cl_rcm.v9i6.21454

[8] E. M. Guevara Vega, J. R. Delgado Deza, and A. C. Mendoza de los Santos, “Importancia de la gestión de seguridad de la información en instituciones educativas con ITIL e ISO 27001,” Revista de investigación de sistemas e informática, vol. 15, no. 1, pp. 113–123, 2022. https://doi.org/10.15381/risi.v15i1.23362

[9] J. Marreros, D. Acosta, and A. Mendoza, “Mecanismos de seguridad de la información en una organización: una revisión sistemática,” Revista Científica Ciencias Ingenieriles, vol. 4, no. 1, pp. 79–90, 2024. https://doi.org/10.54943/ricci.v4i1.384

[10] P. R. Flores Cedeño and C. R. López Paz, “Gobernanza de las tecnologías de la información en el desarrollo corporativo,” Zenodo, 2024. https://doi.org/10.5281/zenodo.11374432

[11] E. M. Cornejo-Jiménez and D. O. Guevara-Aulestia, “Análisis de vulnerabilidades en la infraestructura de red: Una revisión sistemática,” 593 Digital Publisher CEIT, vol. 9, no. 5, pp. 527–542, 2024. https://doi.org/10.33386/593dp.2024.5.2620

[12] X. E. Orellana-Cabrera and M. D. Álvarez-Galarza, “Marco de trabajo de gobierno de TI orientado a la ciberseguridad para el sector bancario bajo COBIT 2019,” Polo del Conocimiento, vol. 7, no. 3, pp. 706–723, 2022. [Online]. Available: https://dialnet.unirioja.es/servlet/articulo?codigo=8399852

[13] A. Flores-Vargas and M. Llerena, “Análisis de protocolos Transport Layer Security y Secure Socket Layer como mecanismos de seguridad y competitividad en las organizaciones digitales,” Technological Innovations Journal, vol. 3, no. 4, pp. 25–37, 2024. https://doi.org/10.35622/j.ti.2024.04.002

[14] Banco Interamericano de Desarrollo and Organización de los Estados Americanos, Reporte Ciberseguridad 2020: riesgos, avances y el camino a seguir en América Latina y el Caribe, Washington, DC: Banco Interamericano de Desarrollo , 2020. https://doi.org/10.18235/0002513

[15] R. C. León-Arroba and G. M. López-Sevilla, “Propuesta de arquitectura de seguridad por diseño para protección de datos personales en entidades públicas,” MQRInvestigar, vol. 8, no. 4, pp. 4192–4218, 2024.https://doi.org/10.56048/MQR20225.8.4.2024.4192-4218

[16] J. León-Acurio, J. Mora-Aristega, M. Huilcapi-Masacon, A. Tamayo-Herrera, and C. Armijos-Maya, “COBIT como modelo para auditorías y control de los sistemas de información,” Polo del conocimiento, vol. 3, no. 4, pp. 17–36, 2018. https://doi.org/10.23857/pc.v3i4.439

[17] G. Sedrakyan, M.-E. Iacob, and J. van Hillegersberg, “Towards LowDevSecOps Framework for Low-Code Development: Integrating Process-Oriented Recommendations for Security Risk Management,” in Proceedings of the 27th ACM/IEEE International Conference on Model Driven Engineering Languages and Systems (MODELS), Linz, Austria, 2024. https://doi.org/10.1145/3652620.3688335

[18] M. Lourenço, T. Gasiba, and M. Pinto-Albuquerque, “You are doing in wrong: On Vulnerabilities in Low Code Development Platforms,” in Proceedings of the Eighth International Conference on Cyber-Technologies and Cyber-Systems (CYBER 2023), Porto, Portugal, 2023, pp. 12–18. [Online]. Available: http://hdl.handle.net/10071/29454

[19] F. M. Ozman, “A systematic literature review on current developments of low code-no code solutions in the IT sector,” World Journal of Advanced Engineering Technology and Sciences, vol. 14, no. 3, pp. 162–169, 2025. https://doi.org/10.30574/wjaets.2025.14.3.0072

[20] K. Rokis and M. Kirikova, “Exploring Low-Code Development: A Comprehensive Literature Review,” Complex Systems Informatics and Modeling Quarterly, no. 36, pp. 68–86, 2023. https://doi.org/10.7250/csimq.2023-36.04

[21] Z. Shi, J. Dong, and Y. Gan, “Democratizing Digital Transformation: A Multisector Study of Low-Code Adoption Patterns, Limitations, and Emerging Paradigms,” Applied Sciences, vol. 15, no. 12, Art. no. 6481, 2025. https://doi.org/10.3390/app15126481

[22] J. T. Sodano and J. F. DeFranco, “Citizen Development, Low-Code/No-Code Platforms, and the Evolution of Generative AI in Software Development,” Computer, vol. 58, no. 5, pp. 101–104, 2025. https://doi.org/10.1109/MC.2025.3547073

[23] B. Binzer and T. J. Winkler, “Democratizing Software Development: A Systematic Multivocal Literature Review and Research Agenda on Citizen Development,” in Proceedings of the 13th International Conference on Software Business (ICSOB 2022), Lecture Notes in Business Information Processing, vol. 463. Cham, Switzerland: Springer, 2022, pp. 244–259. https://doi.org/10.1007/978-3-031-20706-8_17

[24] B. Bodicherla, “The Rise of Low-Code/No-Code Development: Democratizing Application Development,” International Journal of Scientific Research in Computer Science, Engineering and Information Technology, vol. 11, no. 2, pp. 171–178, 2025. https://doi.org/10.32628/CSEIT251112398

[25] K. Shridhar and S. Bose, “Analysis of Low Code-No Code Development Platforms in comparison with Traditional Development Methodologies,” International Journal for Research in Applied Science and Engineering Technology, vol. 9, no. 12, pp. 508–513, 2021.https://doi.org/10.22214/ijraset.2021.39328

Most read articles by the same author(s)