
7/10/2019 · Jeff Burrows
What this post added
This post details the implementation of the GitLab Control Framework (GCF) by adapting the Adobe CCF. Key technical steps include converting CCF controls from PDF to CSV, making control statements specific to GitLab's compliance needs while preserving foundational mappings to regulatory requirements (e.g., PCI DSS), prefixing control domains for numbering (e.g., AM.1.01), prioritizing controls mapped to SOC2 (resulting in 63 controls), and building out additional content for each control including context, scope, ownership, implementation guidance, reference links, evidence examples, and framework mapping. The post also outlines the final steps of identifying responsible teams (RACI) and performing gap analyses for each control. Future plans include developing scripts to convert controls into GitLab issues and a CSV-to-JSON tool.