Video summary
Managing compliance across multiple projects often leads to policy drift, where controls become misaligned over time and proving adherence to standards like SOC 2 turns into a chaotic manual process. To solve this issue, the video introduces GitLab's Compliance Center as a centralized hub that transforms static standards into reusable, enforceable labels known as frameworks. Instead of building compliance structures from scratch for every project, teams can leverage pre-built templates that come with requirements and controls already aligned to common industry standards such as SOC 2, COSO principles, vulnerability scanning, access controls, and change management.
The tutorial demonstrates how to create a new framework by navigating to the Secure tab within a top-level group and selecting the option to build from an existing template. Users can choose specific templates like the System and Organization Controls 2 framework, customize details such as names, descriptions, and colors, and even set the framework as the default for all projects in the group so they automatically inherit these standards. Once selected, users review the included requirements before applying the framework to specific projects that need it, effectively turning compliance policies into code rather than relying on manual configuration.
After a framework is successfully created and applied, GitLab provides powerful reporting tools located under the Compliance Center status section in the top-level group. These reports automatically surface recent instances where projects adhere to or deviate from established controls, allowing teams to quickly identify gaps and receive actionable suggestions for resolution. By utilizing these templates and automated enforcement mechanisms, organizations can eliminate policy drift, maintain synchronized standards across their entire portfolio, and streamline the process of proving compliance without constant manual intervention.
Read the full video transcript
Hello. My name is Fernando and I'm a
developer advocate here at GitLab. If
you manage compliance across [music]
more than a handful of projects, you
know the drift problem. Controls get set
up project by [music] project, policies
fall out of sync, and proving you
actually meet a standard like SOC 2
turns into a manual scramble. Compliance
frameworks fix that by turning a
standard into a reusable enforceable
label. And instead of building one from
scratch, [music]
you can start from a pre-built template.
Let's use a SOC 2 framework template in
order to get started.
In [music] order to create a new
compliance framework from our top-level
group, we must go to the secure side tab
[music] and select compliance center.
This is the central location for
compliance teams to manage their
compliance standards adherence
reporting, violation reporting, and
compliance frameworks for their group.
We can press the new framework button in
order to get started. We can create a
blank framework, import a framework, or
create one from a template. Let's select
create from template. Here we can see
several predefined out-of-the-box
templates.
They include preconfigured requirements
and controls aligned to common
compliance standards, so you can get
quickly started without manual setup.
I'm going to go ahead and look at the
SOC 2 compliance framework.
This is the System and Organization
Controls 2 framework with requirements
mapped to COSO principles covering
vulnerability scanning, access controls,
and change management. I'll go ahead and
select use template. From here, we can
customize the name, description, and
color if we'd like. You can also set the
framework as the group default if you
want every project in the group to
inherit this framework automatically,
select next to go to the requirements
and control section where we can preview
the included requirements added by this
framework. We'll be able to edit them
later on after the framework has been
created. Now, let's press next to
proceed to the scoping section. Here, we
can apply the framework to projects that
require it. I'm going to select the
Tanuki Shop SOC 2 project and then
select create framework to continue.
Now, we can see that our framework has
been created successfully. If I select
the edit button, I can go ahead and
change the basic information as well as
the requirements and controls for this
framework based on my organization's
needs. This includes adding external
controls to meet SOC 2 compliance.
Now that our framework has been applied,
we can use the compliance status report
found in the top-level group under
secure, compliance center, and status.
This report surfaces the most recent
instances where projects do and do not
adhere to a framework's controls, so you
can spot and close gaps fast. Each row
tells you the status, requirement,
framework, project, when it was last
scanned, [music]
and provides suggestions on how to
resolve these issues.
So, instead of policy [music] and
controls by hand, you import a standard
one, enforce it as code, and watch
adherence [music] in one place. See the
links in the description and be sure to
subscribe [music]
for more GitLab videos. Thank you.