Security Control Framework
How GitLab uses Third Party Security Rating to Build Customer Confidence

How GitLab uses Third Party Security Rating to Build Customer Confidence

12/18/2020 · Meghan Maneval

What this post added

This post details GitLab's partnership with BitSight to improve its third-party security rating. It outlines the challenges of inaccurate ratings due to non-production environments and dynamic infrastructure, and the steps taken to address these. These steps included validating the digital footprint, identifying and removing unused IPs, and creating custom environment tags (Production, Pre-Production, User Managed IPs) to segment findings. The post also describes the implementation of a continuous process for identifying new findings, managing the score, and tracking remediation through regular auditing and monitoring. The goal was to improve GitLab's security posture and build customer confidence.

Read the original post ↗