Security Control Framework
Zero Trust at GitLab: Problems, goals, and coming challenges

Zero Trust at GitLab: Problems, goals, and coming challenges

8/9/2019 · Mark Loveless

What this post added

This post details the problems, goals, and expected challenges in implementing Zero Trust at GitLab. It defines the problem as the difficulty in implementing Zero Trust due to differing interpretations and the need for all components to work together. The goals outlined are to protect data based on classification, ensure positive identification of team members and devices in real-time, incorporate geo-location, subject automated processes to the same policies, log all transactions, not weaken existing controls, and make security easier. Expected challenge areas include the company's network (no perimeter, remote team members), applications and data (public cloud offerings, third-party services), customer data protection, scaling, and global team member/customer regulations.

Read the original post ↗