How GitLab built a security control framework from scratch
Blog post from GitLab
GitLab's Security Compliance team discovered that traditional security control frameworks lacked the necessary customization for their multi-product, cloud-native environment, leading them to create the GitLab Control Framework (GCF). Initially using the Secure Controls Framework and later NIST SP 800-53, GitLab found these frameworks insufficient due to their generality and over-restrictiveness, which led to unnecessary controls and operational inefficiencies. By designing the GCF, GitLab tailored security controls to fit its unique operational and product-specific needs, creating 18 custom control domains that align with their security program's organization and operation. This custom framework enhances GitLab's compliance program by providing a more efficient, scalable, and context-driven approach to security controls, reducing the number of controls and audit requests while supporting multiple certifications like SOC 2 and ISO 27001 simultaneously. The GCF allows GitLab to adapt quickly to new certifications and regulatory changes, maintaining a single, coherent system that offers significant qualitative and quantitative improvements in compliance management.
No tracked trend matches for this post yet.
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.