Security Risk Team
Security Risk Mission
To drive security risk treatment at GitLab by empowering teams to make informed and intelligent decisions through proactive identification, monitoring, prioritization, and reporting of security risks.
Core Competencies
Security Operational Risk Management (StORM) Program
The Security Risk team manages an integrated Operational Risk Management program focused on the identification, assessment, continuous monitoring, and reporting of Security Risks across the organization. Risk Reduction is 1 of 5 of the Security Department’s operating principles (Security Vision and Mission). As such, the Security Risk Team takes a leading role in providing the information required by leadership to establish our Strategic Roadmap and our quarterly Objectives and Key Results (OKRs).
Visit the StORM Program & Procedures handbook page for additional details, including a quick introduction to Risk Management at GitLab as well as information about the purpose, scope, and specific procedures executed as part of the program.
Please refer to the communication section of the StORM Program & Procedures page for information on the various ways that team members can use to escalate potential risks to the Security Risk Team.
Security Third Party Risk Management (TPRM) Program
GitLab maintains an industry-leading Third Party Risk Management (TPRM) Program through the use of automation, continuous monitoring, and deep integration across business functions to validate the security of GitLab data shared with external parties.
The integration of GitLab’s TPRM program within the vendor Procurement flow enables cross-functional collaboration between Privacy, Legal, IT, and People Operations to facilitate transparent, risk-based decision making, Business and Stakeholder-focused Results, and adherence to GitLab’s Regulatory and Compliance Obligations. The vendor relationships maintained through this program are leveraged to create efficiencies across the organization.
Business Impact Analysis (BIA) and Critical System Tiering (CST)
The Business Impact Analysis (BIA) helps determine the systems critical to serving GitLab’s Customers.
The output of the BIA is the designation of a Critical System Tier (CST) for a new system by the Security Risk Team.
Asset Inventory Maintenance
Establishing a complete and accurate inventory of assets is key to the success of GitLab’s Risk Program. As such, the Security Risk Team collaborates closely with IT and Business Owners to ensure new systems are added to the Tech Stack.
Team Members
Functional DRIs
While the DRI is the individual who is ultimately held accountable for the success or failure of any given project, they are not necessarily the individual that does the tactical project work. The DRI should consult and collaborate with all teams and stakeholders involved to ensure they have all relevant context, to gather input/feedback from others, and to divide action items and tasks amongst those involved.
DRIs are responsible for ensuring a handbook-first approach to their project(s) and challenging existing processes for efficiency.
Function | DRI |
---|---|
Annual Risk Assessment | Kyle Smith |
Business Impact Analysis | Nirmal Devarajan |
New System Additions to Tech Stack and Post-Implementation Checks | Nirmal Devarajan |
Critical System Tiering | Kyle Smith |
Ongoing SecRisk-Related Observations Management | Nirmal Devarajan |
Ongoing Risk Treatment | Kyle Smith |
Ongoing TPRM Assessments | Ryan Lawson |
Periodic SOX CUEC Facilitation | Eric Geving |
Periodic TPRM Assessments | Eric Geving |
TPRM Data Quality and Emerging Requirements Management | Eric Geving |
StORM Metrics and Reporting | Kyle Smith |
TPRM Metrics and Reporting | Ryan Lawson |
TPRM Application Integrations | Ryan Lawson |
Contact the Team
- Email:
securityrisk@gitlab.com
- Slack:
- #security-risk-management channel
- #sec-assurance channel (includes the broader Security Assurance Team)
- Mention
@security-risk
- GitLab: Tag the team across GitLab using
@gitlab-com/gl-security/security-assurance/security-risk-team
Return to the Security Assurance Homepage
Security Third Party Risk Management
SOX CUEC Mapping Procedure
974b128c
)