
How GitLab built a security control framework from scratch
3/4/2026
This post details the creation of the GitLab Control Framework (GCF) from scratch. It outlines the process of analyzing requirements, learning from industry frameworks (NIST SP 800-53, CSF, SCF, CCF), creating 18 custom control domains (e.g., AAM, AIM, ASM, BCA, CHM, CSR, DPM, EPM, GPM, IAM, INC, ISM, PAS, PSM, SDL, SRM, TPR, TVM), and implementing a two-level hierarchy (Level 1 framework, Level 2 product-specific implementation) to manage controls across different GitLab offerings. It also highlights the extensive metadata captured for each control to operationalize the framework.



















































