Risks of using Low-Code platforms in ITSM environments: A systematic review
Main Article Content
Abstract
Low-Code platforms have experienced rapid adoption in organizations seeking to streamline IT service management (ITSM). However, this integration introduces critical vulnerabilities, especially when interacting with legacy systems through insecure APIs and weak access controls. This research presents a systematic literature review using the PRISMA methodology to identify and classify the main security and compliance risks inherent in the use of Low-Code platforms in regulated ITSM environments. Twenty-five articles were selected from a total of 52 records identified in databases such as Scopus, Dialnet, SciELO, Redalyc, Google Scholar, and ResearchGate, published between 2018 and 2025. The results show that insufficient access controls, exposed APIs, shadow IT and SQL injection represent the most frequent risks, with exposure rates exceeding 60% in hybrid integrations. It was also identified that compliance with GDPR and ISO 27001 is critically compromised when Low-Code platforms interact with legacy systems without formalized security architectures.
Article Details

This work is licensed under a Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 International License.
When an author creates an article and publishes it in a journal, the copyright passes to the journal as part of the publishing agreement. Therefore, the journal becomes the owner of the rights to reproduce, distribute and sell the article. The author retains some rights, such as the right to be recognized as the creator of the article and the right to use the article for his or her own scholarly or research purposes, unless otherwise agreed in the publication agreement.
How to Cite
References
[1] M. Botto-Tobar and C. Neil, “Evaluando la calidad de las aplicaciones Low-Code: Un mapeo sistemático de la literatura,” Revista Conectividad, vol. 5, no. 1, pp. 93–108, 2024. https://doi.org/10.37431/conectividad.v5i1.97
[2] P. L. Huamán Coronel and C. G. Medina Sotelo, “Transformación digital en la administración pública: desafíos para una gobernanza activa en el Perú,” Comuni@cción, vol. 13, no. 2, pp. 93–105, 2022. https://doi.org/10.33595/2226-1478.13.2.594
[3] M. E. Caciano-Arroyo, A. F. Vasquez-Cabrera, and A. C. Mendoza-de-los-Santos, “Integración de inteligencia artificial en la gobernanza de TI: Una revisión sistemática,” AiBi Revista de Investigación, Administración e Ingeniería, vol. 13, no. 2, 2025. https://doi.org/10.15649/2346030X.4532
[4] V. E. Ojeda Muñoz and S. Casas, “Caso de estudio comparativo de plataformas Low-Code,” Informes Científicos Técnicos – UNPA, vol. 16, no. 1, pp. 186–208, 2024. https://doi.org/10.22305/ict-unpa.v16.n1.1105
[5] A. L. López Naranjo, G. G. Uquillas Granizo, I. M. Jácome Lara, and F. P. Pérez Salas, “La transformación digital en la administración pública: evolución y tendencias de investigación,” Perspectivas Sociales y Administrativas, vol. 3, no. 1, pp. 17–36, 2025. https://doi.org/10.61347/psa.v3i1.74
[6] R. E. Suárez Toala and L. V. Venegas Loor, “Evaluación de la madurez tecnológica en la Universidad Estatal del Sur de Manabí,” Pentaciencias, vol. 5, no. 5, pp. 66–85, 2023. https://doi.org/10.59169/pentaciencias.v5i5.722
[7] S. E. Díaz Alvarado, “Gestión del riesgo tecnológico en la modernización de sistemas legacy: Estrategias para una transición eficiente,” Ciencia Latina, vol. 9, no. 6, pp. 3449–3468, 2025. https://doi.org/10.37811/cl_rcm.v9i6.21454
[8] E. M. Guevara Vega, J. R. Delgado Deza, and A. C. Mendoza de los Santos, “Importancia de la gestión de seguridad de la información en instituciones educativas con ITIL e ISO 27001,” Revista de investigación de sistemas e informática, vol. 15, no. 1, pp. 113–123, 2022. https://doi.org/10.15381/risi.v15i1.23362
[9] J. Marreros, D. Acosta, and A. Mendoza, “Mecanismos de seguridad de la información en una organización: una revisión sistemática,” Revista Científica Ciencias Ingenieriles, vol. 4, no. 1, pp. 79–90, 2024. https://doi.org/10.54943/ricci.v4i1.384
[10] P. R. Flores Cedeño and C. R. López Paz, “Gobernanza de las tecnologías de la información en el desarrollo corporativo,” Zenodo, 2024. https://doi.org/10.5281/zenodo.11374432
[11] E. M. Cornejo-Jiménez and D. O. Guevara-Aulestia, “Análisis de vulnerabilidades en la infraestructura de red: Una revisión sistemática,” 593 Digital Publisher CEIT, vol. 9, no. 5, pp. 527–542, 2024. https://doi.org/10.33386/593dp.2024.5.2620
[12] X. E. Orellana-Cabrera and M. D. Álvarez-Galarza, “Marco de trabajo de gobierno de TI orientado a la ciberseguridad para el sector bancario bajo COBIT 2019,” Polo del Conocimiento, vol. 7, no. 3, pp. 706–723, 2022. [Online]. Available: https://dialnet.unirioja.es/servlet/articulo?codigo=8399852
[13] A. Flores-Vargas and M. Llerena, “Análisis de protocolos Transport Layer Security y Secure Socket Layer como mecanismos de seguridad y competitividad en las organizaciones digitales,” Technological Innovations Journal, vol. 3, no. 4, pp. 25–37, 2024. https://doi.org/10.35622/j.ti.2024.04.002
[14] Banco Interamericano de Desarrollo and Organización de los Estados Americanos, Reporte Ciberseguridad 2020: riesgos, avances y el camino a seguir en América Latina y el Caribe, Washington, DC: Banco Interamericano de Desarrollo , 2020. https://doi.org/10.18235/0002513
[15] R. C. León-Arroba and G. M. López-Sevilla, “Propuesta de arquitectura de seguridad por diseño para protección de datos personales en entidades públicas,” MQRInvestigar, vol. 8, no. 4, pp. 4192–4218, 2024.https://doi.org/10.56048/MQR20225.8.4.2024.4192-4218
[16] J. León-Acurio, J. Mora-Aristega, M. Huilcapi-Masacon, A. Tamayo-Herrera, and C. Armijos-Maya, “COBIT como modelo para auditorías y control de los sistemas de información,” Polo del conocimiento, vol. 3, no. 4, pp. 17–36, 2018. https://doi.org/10.23857/pc.v3i4.439
[17] G. Sedrakyan, M.-E. Iacob, and J. van Hillegersberg, “Towards LowDevSecOps Framework for Low-Code Development: Integrating Process-Oriented Recommendations for Security Risk Management,” in Proceedings of the 27th ACM/IEEE International Conference on Model Driven Engineering Languages and Systems (MODELS), Linz, Austria, 2024. https://doi.org/10.1145/3652620.3688335
[18] M. Lourenço, T. Gasiba, and M. Pinto-Albuquerque, “You are doing in wrong: On Vulnerabilities in Low Code Development Platforms,” in Proceedings of the Eighth International Conference on Cyber-Technologies and Cyber-Systems (CYBER 2023), Porto, Portugal, 2023, pp. 12–18. [Online]. Available: http://hdl.handle.net/10071/29454
[19] F. M. Ozman, “A systematic literature review on current developments of low code-no code solutions in the IT sector,” World Journal of Advanced Engineering Technology and Sciences, vol. 14, no. 3, pp. 162–169, 2025. https://doi.org/10.30574/wjaets.2025.14.3.0072
[20] K. Rokis and M. Kirikova, “Exploring Low-Code Development: A Comprehensive Literature Review,” Complex Systems Informatics and Modeling Quarterly, no. 36, pp. 68–86, 2023. https://doi.org/10.7250/csimq.2023-36.04
[21] Z. Shi, J. Dong, and Y. Gan, “Democratizing Digital Transformation: A Multisector Study of Low-Code Adoption Patterns, Limitations, and Emerging Paradigms,” Applied Sciences, vol. 15, no. 12, Art. no. 6481, 2025. https://doi.org/10.3390/app15126481
[22] J. T. Sodano and J. F. DeFranco, “Citizen Development, Low-Code/No-Code Platforms, and the Evolution of Generative AI in Software Development,” Computer, vol. 58, no. 5, pp. 101–104, 2025. https://doi.org/10.1109/MC.2025.3547073
[23] B. Binzer and T. J. Winkler, “Democratizing Software Development: A Systematic Multivocal Literature Review and Research Agenda on Citizen Development,” in Proceedings of the 13th International Conference on Software Business (ICSOB 2022), Lecture Notes in Business Information Processing, vol. 463. Cham, Switzerland: Springer, 2022, pp. 244–259. https://doi.org/10.1007/978-3-031-20706-8_17
[24] B. Bodicherla, “The Rise of Low-Code/No-Code Development: Democratizing Application Development,” International Journal of Scientific Research in Computer Science, Engineering and Information Technology, vol. 11, no. 2, pp. 171–178, 2025. https://doi.org/10.32628/CSEIT251112398
[25] K. Shridhar and S. Bose, “Analysis of Low Code-No Code Development Platforms in comparison with Traditional Development Methodologies,” International Journal for Research in Applied Science and Engineering Technology, vol. 9, no. 12, pp. 508–513, 2021.https://doi.org/10.22214/ijraset.2021.39328