How GitLab supports NSA and CISA CI/CD security guidance
Blog post from GitLab
In June, the NSA and CISA issued a joint cybersecurity information sheet (CSI) with recommendations for securing cloud-based DevSecOps environments, particularly focusing on CI/CD cloud deployments. These environments have become attractive targets for malicious actors due to risks like insecure code and pipeline execution, insufficient access controls, and exposure of secrets. GitLab, as an all-inclusive DevSecOps platform, supports the implementation of recommended mitigations by providing features for authentication, access control, secure code signing, two-person review rules, least-privilege access policies, and secure handling of secrets. GitLab also integrates security scanning tools within the CI/CD pipeline and offers functionalities such as secret detection, license compliance, and audit logging to enhance security. Additionally, it facilitates the management of software composition through features like dependency lists and supports resiliency through robust business continuity strategies. As a strategic partner, GitLab aligns with NSA and CISA's guidance to help organizations protect their CI/CD environments and expedite secure software development.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| Real-time | 5 | 2,396 | 582 | 180 | -6% |
| Secrets Management | 5 | 539 | 100 | 62 | -34% |
| Kubernetes | 1 | 1,182 | 172 | 77 | -20% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.