Security Control Framework
GitLab Security in 2021: protect, enhance, certify and strengthen

GitLab Security in 2021: protect, enhance, certify and strengthen

12/17/2021 · Johnathan Hunt

What this post added

This post details GitLab's security efforts in 2021, focusing on improving assurance through expanded compliance certifications (SOC 2 Type 2/SOC 3, ISO/IEC 27001:2013), continuous control monitoring with the adoption of the Secure Control Framework (SCF) and ZenGRC, and enhanced customer assurance services via the Trust Center and Customer Assurance Package. It also highlights security operations improvements like endpoint detection and response (EDR) platform testing, incident response automation for phishing and access attestation, and Red Team activities including supply chain security research. For product security, it introduces Spamcheck for anti-spam and Package Hunter for detecting malicious dependencies.

Read the original post ↗