BlogsGitLabCustom Compliance Frameworks

Custom Compliance Frameworks

Custom Compliance Frameworks

35
posts
2019–2025

GitLab is adopting and adapting an open-source compliance framework (Adobe's CCF) to build an efficient and aggregated security control program. This approach aims to streamline interactions with internal teams by creating unified control statements that satisfy multiple industry frameworks (ISO, SOC, PCI) simultaneously, reducing redundant information requests and accelerating the establishment of a comprehensive compliance program. This post details the implementation of compliance as code, emphasizing the integration of compliance standards into the CI/CD pipeline, leveraging containers for compliant 'Golden Images', and establishing a System of Record (SOR) to track compliance. It also highlights the growing importance of software supply chain security as an overarching theme for compliance and security.

2025

Introducing Custom Compliance Frameworks in GitLab

4/17/2025

Introduces Custom Compliance Frameworks and 50 out-of-the-box (OOTB) controls for compliance standards. Enables mapping of multiple, overlapping controls into a unified framework. Enforces compliance automatically within CI/CD pipelines. Simplifies compliance adoption by providing pre-defined controls for standards like ISO 27001, CIS Benchmarks, and SOC 2. Removes 'Standards' from Compliance Center and renames existing controls to 'compliance checks' and 'controls'. Available in GitLab Ultimate.

Tutorial: Advanced use case for GitLab Pipeline Execution Policies

1/22/2025

This post details a practical implementation of GitLab's Pipeline Execution Policies to enforce specific CI/CD stages and jobs. It provides a concrete example of using a shell script to query pipeline jobs via the GitLab API and then using injected YAML to define approved stages and jobs. The tutorial demonstrates how to configure a policy to inject this YAML, ensuring that only approved jobs and stages are executed, thereby enforcing security and compliance guardrails.

GitLab supports banks in navigating regulatory challenges

1/9/2025

This post details how GitLab's existing Custom Compliance Frameworks and security features can be leveraged by financial institutions to navigate upcoming regulatory challenges like the European Cyber Resilience Act (CRA), Digital Operational Resilience Act (DORA), and the European Data Act. It highlights the application of GitLab's security scanning tools (SAST, DAST, Secret Detection, etc.), policy enforcement, software supply chain security (SCA, SBOM), and issue tracking to meet these regulatory requirements. The post emphasizes GitLab Dedicated as a solution for highly regulated industries and discusses the implications of legacy systems and the need for increased investment in technology, risk management, data governance, and cybersecurity.

Streamline the path to CMMC Level 2 compliance with GitLab

1/7/2025

This post details how GitLab's existing features, such as Role-Based Access Control (RBAC), audit events, SAML SSO, multi-factor authentication, and various security scanning tools (SAST, DAST, Container Scanning, Dependency Scanning), can be leveraged to meet CMMC Level 2 requirements. It specifically maps GitLab capabilities to CMMC controls for Access Control, Audit and Accountability, Configuration Management, Identification and Authentication, Risk Assessment, and System and Information Integrity. It also highlights the integration of GitLab Duo with Amazon Q for enhanced vulnerability detection and remediation.

2024

GitLab moves from compliance pipelines to security policies

10/1/2024

Introduces 'pipeline execution policies' as a replacement for 'compliance pipelines'. Details the deprecation timeline for compliance pipelines and the migration process to the new policy type. Explains the 'override' and 'inject' modes for pipeline execution policies and their configuration options.

How to choose the right security scanning approach

8/26/2024

This post details how GitLab CI/CD enables different roles (Developer, AppSec Engineer, Platform Engineer) to incorporate security scanning. It explains the use of pipeline includes (templates and components) for adding security scanners like Secret Detection, SAST, Dependency Scanning, and Container Scanning. It also introduces the concept of Compliance Frameworks as a mechanism to enforce security scanning across projects, addressing the limitations of project-level includes for regulated industries. The post contrasts the ease of use, customization, and enforcement capabilities of pipeline includes versus compliance frameworks.

How GitLab helps meet NIS2 requirements

8/20/2024

This post details how GitLab's existing features, particularly within the Secure, Create, Verify, Package, Deploy, Monitor, and Govern stages, can be leveraged to meet the requirements of the NIS2 Directive. It highlights specific features like SAST, IaC Scanning, DAST, Container Scanning, Dependency Scanning, License Compliance, SBOM generation, Protected Branches, Merge Request Approvals, Push Rules, Signed Commits, Protected Runners, Alerts, Incidents, SCIM, SSO, Custom Roles, MR Approval Policies, GitLab Duo's Vulnerability Explanation, Streaming Audit Events, Git Abuse Rate Limiting, and Vulnerability Reports as mechanisms to address NIS2's mandates on supply chain security, risk management, and vulnerability handling. It also points to MFA and SSO for authentication requirements.

FinServ: How to implement GitLab's separation of duties features

8/13/2024

This post details how to implement GitLab's separation of duties (SoD) features, particularly for the financial services industry. It elaborates on using merge request approval policies (preventing author approval, requiring password, preventing committers from approving), compliance frameworks and controls (automating preventive measures, managing risks, enforcing regulatory compliance), permissions and roles (principle of least privilege, custom roles, protected environments for deployer roles), and protected features (branches, Git tags, environments, packages). It also highlights the role of audit events and the Compliance Center for monitoring and auditing these implementations.

How GitLab supports the FedRAMP authorization journey

8/7/2024

This post details how GitLab can support organizations in their FedRAMP authorization journey. It outlines the key steps of the FedRAMP certification process, highlights GitLab's role in supporting FedRAMP requirements, and provides best practices for configuration and compliance. Specific GitLab features discussed include security scanning tools (container, dependency, SAST, IaC, secret detection, DAST, API fuzzing, coverage-guided fuzzing), access control and authentication configurations, audit event streaming to SIEM solutions, incident response tools, configuration management via CI/CD and MRs, FIPS compliance support, and a NIST 800-53 R5 security and privacy controls management project template. It also touches upon the importance of using FedRAMP-authorized identity providers.

Online retailer bol tackles growing compliance needs with GitLab

6/12/2024

This post details how bol.com leverages GitLab Ultimate's custom compliance frameworks and automated pipelines to meet growing regulatory requirements (GDPR, ISO, EU AI Act). It highlights the significant developer hour savings achieved by automating compliance checks, enabling teams to focus on innovation and security. The adoption of GitLab Ultimate for compulsory compliance pipelines is presented as a key strategy for maintaining trust and adapting to new regulations.

Building GitLab with GitLab: Expanding our security certification portfolio

4/4/2024

This post details how GitLab's Security Compliance team used its own platform for Agile planning (Epics, issues, labels, recurring issues, issue boards) and security features (Merge request approval settings, Protected branch settings, Code owners, SAST/DAST, Audit events) to achieve TISAX and SOC 2 Type 2 certifications. It highlights the use of these features for implementing security controls, scaling compliance efforts, and delivering results faster.

2023

How GitLab can support your ISO 27001 compliance journey

9/6/2023

This post details how GitLab's platform features can be leveraged to support ISO 27001 compliance. It maps specific ISO 27001 controls (Organizational, Technological) to GitLab features such as user roles and permissions, SAML SSO, SCIM, Epics, issues, tasks, labels, scoped labels, issue boards, infrastructure-as-code scanning, compliance frameworks, compliance pipelines, Compliance Center, audit events, audit event streaming, SAST, DAST, code quality scanning, container scanning, dependency scanning, secret detection, and policies. It highlights how these features enable secure coding, configuration management, logging, monitoring, and secure development lifecycle practices.

Meet regulatory standards with GitLab security and compliance

8/17/2023

This post details how GitLab's compliance and security policy management features can be used to meet regulatory standards. It covers common IT compliance standards (HIPAA, GDPR, NIST SSDF, PCI DSS, ISO 27000), global and regional regulations, and industry-specific standards. It also explains compliance management with GitLab, including compliance frameworks and pipelines, security policy management (scan execution policies, scan result policies, license approval policies), and audit management (preparing for audits, using audit logs, audit events streaming). Best practices for compliance management are also provided.

DevSecOps platforms give SMBs security muscle

1/10/2023

This post explains how SMBs can leverage DevSecOps platforms like GitLab to enhance their security posture. It highlights four key benefits: finding vulnerabilities early through integrated security testing (DAST, SAST, dependency scanning), easing work with automation for consistency and reduced human error, ensuring compliance through automated checks within the workflow, and establishing security imperatives with a single, integrated platform. The post emphasizes that a DevSecOps platform provides a solid security foundation for SMBs, reducing the need for external consultants and stringing together multiple tools.

2022

Achieve SLSA Level 2 compliance with GitLab

11/30/2022

This post introduces GitLab's support for SLSA Levels 1 and 2 by enabling the generation of artifact metadata directly from the GitLab Runner. By setting `RUNNER_GENERATE_ARTIFACTS_METADATA: true` in `.gitlab-ci.yml`, users can produce a `data.txt` file and an accompanying `.json` metadata file that details the build process, including input parameters, SHA hashes of the file and repository, and provenance information. This allows for the verification of artifact origin and integrity. Future plans include integrating code signing and enhancing upstream dependency validation for higher SLSA levels.

Introducing the infrastructure bill of materials

9/22/2022

Introduces the concept of an Infrastructure Bill of Materials (IBoM) to extend software supply chain security to cloud infrastructure. Details the partnership with Firefly to discover cloud assets, generate IaC, and integrate infrastructure management into the DevOps workflow via GitOps, including drift detection and automated merge requests for infrastructure changes.

What you need to know about DevOps audits

8/31/2022

This post explains how DevOps processes, through automation and continuous integration, inherently support auditability. It highlights that features like signed code commits and mandatory code reviews provide auditable trails for auditors to verify the integrity of the software development lifecycle. The post also mentions that GitLab's platform provides tools to track these activities, aiding teams in meeting regulatory controls and processes.

The importance of compliance in DevOps

8/15/2022

This post details how compliance standards can be integrated into the CI/CD pipeline to automate checks and provide an audit trail. It also discusses leveraging containers to create compliant 'Golden Images' and the importance of establishing a System of Record (SOR) for tracking compliance. The post emphasizes software supply chain security as a key theme for compliance and security moving forward.

Top 5 compliance features to leverage in GitLab

7/13/2022

This post outlines five key compliance features within GitLab: Multi-Factor Authentication (MFA), privileged access review, protected branches, merge request approval settings, and audit events. It details how each feature contributes to security and compliance, providing links to relevant documentation and compliance standards. For MFA, it emphasizes enforcement and provides illustrative controls. For privileged access, it breaks down the access security structure (roles) and offers best practices for restricting access and deprovisioning. Protected branches are explained with best practices for securing default branches and monitoring changes. Merge request approvals are detailed with various settings to enforce segregation of duties and prevent unauthorized merges. Finally, audit events are highlighted as a monitoring control for changes to protected branch settings.

Managing risk with GitLab's plan of actions & milestones

7/7/2022

This post details how GitLab can be used to manage the Plan of Actions and Milestones (POA&M) process for risk management, particularly in the context of NIST RMF. It explains how GitLab's security scanners identify vulnerabilities, how Vulnerability Reports can be used for triage and management, and how vulnerabilities can be converted into GitLab Issues for tracking remediation with due dates and milestones. It also highlights the use of Epics, Labels, and Issue Boards for managing these work items and the benefits of having a single system for continuous monitoring and mitigation.

GitLab's Commitment to Enhanced AppSec in Modern DevOps

6/21/2022

This post details enhancements to GitLab's application security features in GitLab 15, building upon the existing Custom Compliance Frameworks. New features include a global rule registry for policy customization, a browser-based DAST scanner for modern APIs and SPAs, expanded Semgrep support for SAST, and new vulnerability management capabilities. It also highlights the migration of SAST, Container Scanning, and Secret Detection to the Free tier. For Ultimate users, it introduces DAST, Operational Container Scanning, Dependency Scanning, IaC Scanning, Coverage-Guided Fuzzing, and Web-API Fuzzing. Enhancements to the developer lifecycle include a security widget in merge requests and the ability to create confidential issues for collaboration. The security team benefits from improved Vulnerability Reports, Security Dashboards, and the enforcement of separation of duties via Compliance Frameworks and Security Policies.

How to ensure separation of duties and enforce compliance with GitLab

4/4/2022

This post details the implementation of GitLab's Security Policies (Scan Execution Policies, Merge Request Approval Policies, and Pipeline Execution Policies) to enforce separation of duties and continuous compliance. It explains how to configure these policies via the Policy Editor, including requiring security scans (e.g., SAST) before a pipeline runs, enforcing security team approval for merge requests with vulnerabilities, and enforcing specific CI/CD jobs. It also highlights the use of Audit Events and the Compliance Center's Standards Adherence report for monitoring.

Comply with NIST's secure software supply chain framework with GitLab

3/29/2022

This post details how GitLab addresses the specific practices within the NIST SSDF: Prepare the organization (policy management, role-based permissions, security dashboards, zero-trust), Protect software (SCM, commit signatures, code reviews, hardened containers, MR approvals, SBOM, offline scanning), Produce well-secured software (credential management, vulnerability reports, integrated security scanning, continuous compliance enforcement), and Respond to vulnerabilities (CVE updates, vulnerability disclosure, Auto DevOps, vulnerability reports, integrated learning tools, on-demand scanning).

GitLab strengthens supply chain with compliance features

2/9/2022

This post details the introduction of Infrastructure as Code (IaC) scanning for configuration files (YAML, Kubernetes, CloudFormation, Terraform), the switch to Trivy for container scanning, and beta testing for production container scanning and cluster image scanning. It also highlights the use of Peach Tech and Fuzzit technology for API security and beta testing of DAST for APIs. New security governance features include continuous compliance with compliant workflow automation and a policy editor for fine-grained risk management rules. The post also announces the consolidation of security findings into a unified vulnerability management dashboard and the replacement of some open-source SAST scanners with Semgrep. Future plans include production container scanning, a DAST API scanner, API Discovery, compliance checks in MRs, group-level governance, full software supply chain security, inline security training, and intelligent code security.

2021

GitLab is setting the standard for DevSecOps

6/1/2021

This post details GitLab's evolution in DevSecOps, emphasizing the integration of security testing into the CI pipeline, unified tooling for security and development teams, and improved remediation workflows. It highlights new features like compliant pipeline configurations using Compliance Frameworks, Security Alert Dashboard, bulk vulnerability status updates, Admin Mode, Semgrep integration for custom SAST rules, custom CA certificates, email alerts for key expirations, SAML enforcement for Git activity, on-demand DAST, and a new browser-based DAST crawler. It also mentions acquisitions of Peach Tech and Fuzz It for fuzzing capabilities and ML technology to innovate app sec. The post also touches on Professional Services for security training, migration, and advisory services, and positions GitLab to help meet challenges posed by the U.S. Executive Order on Improving the Nation's Cybersecurity.

2020

Managing Compliance with GitLab

10/1/2020

This post introduces GitLab's approach to compliance management, highlighting advanced auditing features and merge request approvals based on compliance tags. It aims to simplify compliance by providing a user-friendly experience. A video is provided to demonstrate configuration.

How to build a compliance program with ease

7/2/2020

This post details how GitLab can be used to build and manage compliance programs. It highlights features like granular user roles and permissions for segregation of duties, application security scanning integrated into pipelines, custom project templates for tracking adherence to frameworks (e.g., HIPAA, SOX), and the use of Audit Events for traceability. It also mentions the compliance dashboard for consolidated compliance signals and future enhancements. The post emphasizes GitLab's ability to automate compliance processes and reduce administrative overhead by consolidating tools and evidence in a single application.

DevSecOps basics: 9 tips for shifting left

6/23/2020

This post introduces the concept of 'shifting left' in DevSecOps, emphasizing the importance of integrating security earlier in the Software Development Lifecycle (SDLC). It highlights the challenges of traditional security practices, such as late-stage testing and friction between development and security teams. The post advocates for collaboration, automation, and providing developers with tools like SAST and DAST reports. It offers nine tips for efficient DevSecOps, including measuring vulnerability impact, automating scans, integrating security into developer workflows, and streamlining toolchains. It also touches upon the cultural aspect of DevSecOps, suggesting a security champions program and clear objectives.

How we manage open source security software

4/10/2020

This post discusses GitLab's approach to managing open source security software, focusing on the "supply chain" of external packages used within the GitLab product. It highlights the importance of dedicated security personnel for analyzing internal and external code flaws, managing bug submissions, and proactively identifying vulnerabilities in open source dependencies. The article emphasizes GitLab's transparent and open-core model as a benefit for security disclosure and discusses the role of DevSecOps in rapid development with a security focus. Key takeaways for improving open source security include having dedicated, empowered security staff, strong upper management buy-in, fostering a culture that avoids shame and punishment for security issues, and making security a "muscle memory" practice.

Why implementing security as code is important for DevSecOps

3/12/2020

This post introduces the concept of 'security as code' as a key practice for DevSecOps. It defines security as code as integrating security policies, tests, and scans into DevOps tools and workflows. It highlights six capabilities to prioritize: automating security scans and tests within the pipeline, building a continuous feedback loop, evaluating and monitoring automated security policies, automating complex manual tests, testing new code in staging environments, and creating logs for review dashboards. It positions security as code as a best practice for the larger goal of integrating security throughout the SDLC.

Make tracking agreements simple with our new Compliance Dashboard

3/11/2020

Introduced the Compliance Dashboard in GitLab 12.8, providing an aggregate view of approved merge requests across groups. This iteration allows administrators to see who approved a merge request, when, and which project it belongs to, aiding in audit trails and compliance verification. Future iterations will include merge request approval settings, security scanning data, test results, and pipeline results within the dashboard.

2019

How to ensure security at the speed of DevOps

10/31/2019

This post outlines six strategies to integrate security into the DevOps lifecycle, emphasizing small, frequent changes, developer education, failing fast, prioritizing risks based on severity and likelihood of exploitation, automating security processes, and continuous testing. It advocates for a security-first mindset and the use of integrated tools like GitLab to achieve this.

5 Security testing principles every developer should know

9/16/2019

This post outlines five principles for integrating security testing into the development lifecycle: evangelizing security efforts, testing early and often (mentioning SAST, DAST, and dependency scanning), verifying changes with code reviews (requiring approvers in merge requests), maintaining a log of deployments and dependencies, and diversifying security testing portfolios (mentioning SCA, SAST, and bug bounty programs). It emphasizes the shift towards a DevSecOps model where developers are responsible for security.

Why building compliance as code in DevOps will benefit your entire company

8/19/2019

This post introduces the concept of 'compliance as code' and its benefits within the DevOps lifecycle. It details how compliance requirements can be defined and enforced through code, enabling automated adjustments to meet pre-defined standards. The post outlines implementation strategies including peer reviews, static application security testing (SAST), and regulated access controls. It also discusses how GitLab utilizes an aggregate compliance framework (Adobe's CCF) to manage its own compliance program, mitigating overlapping requests and streamlining the process.

How GitLab went about choosing the right compliance framework

5/7/2019

This post details GitLab's decision to adopt an "umbrella framework" approach to information security compliance, specifically by adapting Adobe's open-source CCF. This strategy aims to aggregate security controls to efficiently meet the requirements of multiple industry frameworks (ISO, SOC, PCI) rather than treating each independently. The post highlights the benefits of this approach, such as reducing redundant requests to internal teams and accelerating the development of a comprehensive compliance program.