Security Policies and Standards
These standards define a baseline set of security requirements that must be implemented and followed.
List of policies and standards
A list of policies and standards including both internal and external ones is available on the internal handbook. Information on how to add to the list below is available there as well.
List of public policies and standards
- Access Control (AC) or Identification and Authentication (IA)
-
Awareness and Training (AT)
- Policies
- Standards
- Policies
- Audit and Accountability (AU)
-
Assessment, Authorization, and Monitoring (CA), Planning (PL), System and Communications Protection (SC), or System and Information Integrity (SI)
- Policies
- Backups of GitLab.com
- Encryption Policy
- GCF Security Control Lifecycle
- GitLab Internal Acceptable Use Policy
- GitLab Security Compliance Controls
- Information Security and Artificial Intelligence Management System
- Monitoring of GitLab.com
- Penetration Testing Policy
- Production Architecture
- Security and Technology Policies Management
- Software Development Lifecycle Policy
- Standards
- Policies
- Configuration Management (CM) or Maintenance (MA)
-
Contingency Planning (CP) or Incident Response (IR)
- Policies
- Standards
-
Media Protection (MP)
- Policies
- Standards
- Policies
-
Physical and Environmental Protection (PE)
- Policies
- Standards
- Policies
-
Personnel Security (PS)
- Policies
- Standards
- Risk Assessment (RA)
-
System and Services Acquisition (SA) or Supply Chain Risk Management (SR)
- Policies
- Standards
- Policies
Last modified October 3, 2025: More policy reorganization (
10563f30
)