Roles and responsibilities for the governance of Information Security within GitLab are formally documented within the organizational chart and job descriptions and are communicated through the GitLab handbook.
To be able to effectively work with the Security team at GitLab, knowing who is responsible for what is important in order to direct questions, concerns, and specific efforts to the right person(s). The purpose of this control is to ensure roles and responsibilities for the Security team are updated and kept current, and that the reporting structure within the department remains transparent.
The scope is to ensure GitLab security team understand their roles & responsibilities, and adhere to them so as to ensure the confidentiality, integrity, and availability of GitLab's information and information systems. Based on that the following are accomplished:
Non-public information relating to this security control as well as links to the work associated with various phases of project work can be found in the Security Roles and Responsibilities control issue.