Security Control Framework
Zero Trust at GitLab: The data classification and infrastructure challenge

Zero Trust at GitLab: The data classification and infrastructure challenge

8/21/2019 · Mark Loveless

What this post added

This post details the challenges associated with implementing Zero Trust at GitLab, specifically focusing on data classification and infrastructure. It outlines the four data classification levels (RED, ORANGE, YELLOW, GREEN) and discusses the complexities of data state changes, tracking metadata, time limits, data capability, and data movement. It also highlights infrastructure challenges related to multi-cloud environments (GCP, AWS, Azure, DigitalOcean) and the ambiguity of administrative access in SaaS applications. The post emphasizes that GitLab's all-remote nature and lack of a corporate VPN provide a head start in adopting Zero Trust.

Read the original post ↗