Security Control Framework
How we made GitLab more secure in 2020

How we made GitLab more secure in 2020

12/16/2020 · Johnathan Hunt

What this post added

This post details the implementation of a next-generation SIEM (Panther Labs) for improved visibility, detection, and response for GitLab.com and the GitLab organization. It also highlights the creation of a public 'Red Team Tech Notes' project to share technical challenges and solutions, and mentions ongoing work in purple-teaming, table-top exercises, and tooling improvements for the SIRT team. Additionally, it covers the achievement of SOC 2 Type 1 compliance, the establishment of a Security Operational Risk Management program (StORM), and the deployment of the Customer Assurance Package (CAP) for self-serve security information. Finally, it describes the development of functionality to identify accidentally disclosed AWS instance keys and the creation of 'Package Hunter' for enhanced dependency scanning to detect malicious packages.

Read the original post ↗