Turning the Adobe CCF into the GitLab Control Framework (it's all open source!)
Blog post from GitLab
GitLab's adaptation of the Adobe open-source compliance framework into the GitLab Control Framework (GCF) aims to streamline compliance processes by tailoring controls to meet GitLab's specific needs while maintaining alignment with industry standards. The initial step involved converting Adobe's CCF controls from PDF to CSV for easier modification, ensuring these changes did not disrupt foundational mappings to underlying requirements such as PCI DSS. GitLab prioritized SOC2 certification, focusing initially on 63 controls that aligned with SOC2's Common Criteria, and developed detailed documentation and guidance for each. The process included assigning responsibility within GitLab for each control and conducting a gap analysis to assess current compliance status. To assist smaller companies and GitLab customers in adopting this framework, GitLab has made available a public repository containing the adapted controls and is developing additional tools, such as scripts for turning compliance controls into GitLab project issues and a CSV-to-JSON converter. GitLab encourages feedback to further improve these resources and support broader industry compliance efforts.
No tracked trend matches for this post yet.
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.