Security Control Framework
How GitLab built a security control framework from scratch

How GitLab built a security control framework from scratch

3/4/2026 · Davoud Tu

What this post added

This post details the creation of the GitLab Control Framework (GCF) from scratch. It outlines the process of analyzing requirements, learning from industry frameworks (NIST SP 800-53, CSF, SCF, CCF), creating 18 custom control domains (e.g., AAM, AIM, ASM, BCA, CHM, CSR, DPM, EPM, GPM, IAM, INC, ISM, PAS, PSM, SDL, SRM, TPR, TVM), and implementing a two-level hierarchy (Level 1 framework, Level 2 product-specific implementation) to manage controls across different GitLab offerings. It also highlights the extensive metadata captured for each control to operationalize the framework.

Read the original post ↗