Custom Compliance Frameworks
Managing risk with GitLab's plan of actions & milestones

Managing risk with GitLab's plan of actions & milestones

7/7/2022 · Sameer Kamani

What this post added

This post details how GitLab can be used to manage the Plan of Actions and Milestones (POA&M) process for risk management, particularly in the context of NIST RMF. It explains how GitLab's security scanners identify vulnerabilities, how Vulnerability Reports can be used for triage and management, and how vulnerabilities can be converted into GitLab Issues for tracking remediation with due dates and milestones. It also highlights the use of Epics, Labels, and Issue Boards for managing these work items and the benefits of having a single system for continuous monitoring and mitigation.

Read the original post ↗