
GitLab
Security•2026-03-04
How GitLab built a security control framework from scratch
GitLab's Security Compliance team built a custom control framework (GCF) after finding existing frameworks like NIST SP 800-53 inadequate for their multi-product, cloud-native environment.