Submind YouTube summaries
Thumbnail for How to Use GitLab Compliance Center Templates to Fix Policy Drift

How to Use GitLab Compliance Center Templates to Fix Policy Drift

Watch on YouTube

Video summary

Managing compliance across multiple projects often leads to policy drift, where controls become misaligned over time and proving adherence to standards like SOC 2 turns into a chaotic manual process. To solve this issue, the video introduces GitLab's Compliance Center as a centralized hub that transforms static standards into reusable, enforceable labels known as frameworks. Instead of building compliance structures from scratch for every project, teams can leverage pre-built templates that come with requirements and controls already aligned to common industry standards such as SOC 2, COSO principles, vulnerability scanning, access controls, and change management. The tutorial demonstrates how to create a new framework by navigating to the Secure tab within a top-level group and selecting the option to build from an existing template. Users can choose specific templates like the System and Organization Controls 2 framework, customize details such as names, descriptions, and colors, and even set the framework as the default for all projects in the group so they automatically inherit these standards. Once selected, users review the included requirements before applying the framework to specific projects that need it, effectively turning compliance policies into code rather than relying on manual configuration. After a framework is successfully created and applied, GitLab provides powerful reporting tools located under the Compliance Center status section in the top-level group. These reports automatically surface recent instances where projects adhere to or deviate from established controls, allowing teams to quickly identify gaps and receive actionable suggestions for resolution. By utilizing these templates and automated enforcement mechanisms, organizations can eliminate policy drift, maintain synchronized standards across their entire portfolio, and streamline the process of proving compliance without constant manual intervention.
Read the full video transcript
Hello. My name is Fernando and I'm a developer advocate here at GitLab. If you manage compliance across [music] more than a handful of projects, you know the drift problem. Controls get set up project by [music] project, policies fall out of sync, and proving you actually meet a standard like SOC 2 turns into a manual scramble. Compliance frameworks fix that by turning a standard into a reusable enforceable label. And instead of building one from scratch, [music] you can start from a pre-built template. Let's use a SOC 2 framework template in order to get started. In [music] order to create a new compliance framework from our top-level group, we must go to the secure side tab [music] and select compliance center. This is the central location for compliance teams to manage their compliance standards adherence reporting, violation reporting, and compliance frameworks for their group. We can press the new framework button in order to get started. We can create a blank framework, import a framework, or create one from a template. Let's select create from template. Here we can see several predefined out-of-the-box templates. They include preconfigured requirements and controls aligned to common compliance standards, so you can get quickly started without manual setup. I'm going to go ahead and look at the SOC 2 compliance framework. This is the System and Organization Controls 2 framework with requirements mapped to COSO principles covering vulnerability scanning, access controls, and change management. I'll go ahead and select use template. From here, we can customize the name, description, and color if we'd like. You can also set the framework as the group default if you want every project in the group to inherit this framework automatically, select next to go to the requirements and control section where we can preview the included requirements added by this framework. We'll be able to edit them later on after the framework has been created. Now, let's press next to proceed to the scoping section. Here, we can apply the framework to projects that require it. I'm going to select the Tanuki Shop SOC 2 project and then select create framework to continue. Now, we can see that our framework has been created successfully. If I select the edit button, I can go ahead and change the basic information as well as the requirements and controls for this framework based on my organization's needs. This includes adding external controls to meet SOC 2 compliance. Now that our framework has been applied, we can use the compliance status report found in the top-level group under secure, compliance center, and status. This report surfaces the most recent instances where projects do and do not adhere to a framework's controls, so you can spot and close gaps fast. Each row tells you the status, requirement, framework, project, when it was last scanned, [music] and provides suggestions on how to resolve these issues. So, instead of policy [music] and controls by hand, you import a standard one, enforce it as code, and watch adherence [music] in one place. See the links in the description and be sure to subscribe [music] for more GitLab videos. Thank you.