
5/7/2019 · Jeff Burrows
What this post added
This post details GitLab's decision to adopt an "umbrella framework" approach to information security compliance, specifically by adapting Adobe's open-source CCF. This strategy aims to aggregate security controls to efficiently meet the requirements of multiple industry frameworks (ISO, SOC, PCI) rather than treating each independently. The post highlights the benefits of this approach, such as reducing redundant requests to internal teams and accelerating the development of a comprehensive compliance program.