Custom Compliance Frameworks
How GitLab went about choosing the right compliance framework

How GitLab went about choosing the right compliance framework

5/7/2019 · Jeff Burrows

What this post added

This post details GitLab's decision to adopt an "umbrella framework" approach to information security compliance, specifically by adapting Adobe's open-source CCF. This strategy aims to aggregate security controls to efficiently meet the requirements of multiple industry frameworks (ISO, SOC, PCI) rather than treating each independently. The post highlights the benefits of this approach, such as reducing redundant requests to internal teams and accelerating the development of a comprehensive compliance program.

Read the original post ↗