Gitlab hero border pattern left svg Gitlab hero border pattern right svg

TPM.3.01 - Approved Service Provider Listing Control Guidance

On this page

TPM.3.01 - Approved Service Provider Listing

Control Statement

GitLab maintains a list of approved, managed service providers and the services they provide to GitLab.

Context

Maintaining a list of approved service providers will assist in validating exactly what a service provider offers. Documentation should include:

Scope

All externally sourced service providers utilized by GitLab that handles credit card data.

Ownership

Owner of service provider relationship.

Implementation Guidance

For detailed implementation guidance relevant to GitLab team-members, refer to the full guidance documentation.

For all reference links relevant to this control, refer to the full guidance documentation.

Examples of evidence an auditor might request to satisfy this control

For examples of evidence an auditor might request, refer to the full guidance documentation.

Framework Mapping