Custom Compliance Frameworks
Comply with NIST's secure software supply chain framework with GitLab

Comply with NIST's secure software supply chain framework with GitLab

3/29/2022 · Sandra Gittlen

What this post added

This post details how GitLab addresses the specific practices within the NIST SSDF: Prepare the organization (policy management, role-based permissions, security dashboards, zero-trust), Protect software (SCM, commit signatures, code reviews, hardened containers, MR approvals, SBOM, offline scanning), Produce well-secured software (credential management, vulnerability reports, integrated security scanning, continuous compliance enforcement), and Respond to vulnerabilities (CVE updates, vulnerability disclosure, Auto DevOps, vulnerability reports, integrated learning tools, on-demand scanning).

Read the original post ↗