
8/19/2019 · Vanessa Wegner
What this post added
This post introduces the concept of 'compliance as code' and its benefits within the DevOps lifecycle. It details how compliance requirements can be defined and enforced through code, enabling automated adjustments to meet pre-defined standards. The post outlines implementation strategies including peer reviews, static application security testing (SAST), and regulated access controls. It also discusses how GitLab utilizes an aggregate compliance framework (Adobe's CCF) to manage its own compliance program, mitigating overlapping requests and streamlining the process.