
7/13/2022 · Madeline Lake
What this post added
This post outlines five key compliance features within GitLab: Multi-Factor Authentication (MFA), privileged access review, protected branches, merge request approval settings, and audit events. It details how each feature contributes to security and compliance, providing links to relevant documentation and compliance standards. For MFA, it emphasizes enforcement and provides illustrative controls. For privileged access, it breaks down the access security structure (roles) and offers best practices for restricting access and deprovisioning. Protected branches are explained with best practices for securing default branches and monitoring changes. Merge request approvals are detailed with various settings to enforce segregation of duties and prevent unauthorized merges. Finally, audit events are highlighted as a monitoring control for changes to protected branch settings.