Skip to content

GitLab access control & privilege security checks

Admin roles, standing privileges, permission scopes and policy enforcement — the settings that decide how much damage one compromised account can do.

On GitLab, Black Cat runs 9 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the GitLab connector needs.

Checks (9)

severity: medium Group Membership Unlocked fix difficulty: easy #

Lock GitLab group membership to prevent subgroup owners from adding members outside the hierarchy

  1. Navigate to Group > Settings > General > Permissions
  2. Check Membership lock checkbox
  3. Save changes
  4. Communicate policy to subgroup owners

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: critical Project Merge Approvals Disabled fix difficulty: easy #

Require at least one merge request approval for GitLab projects

  1. Navigate to GitLab Project Settings > Merge requests
  2. Set 'Approvals required' to at least 1
  3. Consider enabling 'Prevent approval by author'

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: critical Project Branch Protection Disabled fix difficulty: easy #

Enable branch protection on the default GitLab project branch to restrict direct pushes

  1. Navigate to GitLab Project Settings > Repository > Protected branches
  2. Add the default branch to the protected branches list
  3. Set push access to 'Maintainers' and merge access to 'Developers + Maintainers'

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.c NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: high Project Force Push Allowed fix difficulty: easy #

Disable force push on the default protected branch of the GitLab project

  1. Navigate to Project > Settings > Repository > Protected Branches
  2. Find the default branch
  3. Disable Allow force push
  4. Save changes
  5. Communicate policy to developers

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.c NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: medium Project No Code Owner Approval fix difficulty: medium #

Require code owner approval on the default GitLab project branch and create a CODEOWNERS file

  1. Navigate to Project > Settings > Repository > Protected Branches
  2. Find the default branch
  3. Enable Require approval from code owners
  4. Create or update CODEOWNERS file
  5. Save changes

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: low Deactivated Member Not Removed fix difficulty: easy #

Remove deactivated GitLab members from the group and any subgroups

  1. Navigate to Group > Members
  2. Find deactivated member
  3. Confirm account is no longer needed
  4. Remove from group
  5. Verify removal from any subgroups

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-308.a3 NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: low Pending Invitation Not Accepted fix difficulty: easy #

Review and resend or revoke long-pending GitLab group invitations

  1. Navigate to Group > Members > Invited
  2. Find pending invitation
  3. Verify if invitation is still needed
  4. Resend or revoke as appropriate
  5. Follow up with invitee if needed

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: medium Group Subgroup Creation Permissive fix difficulty: easy #

Restrict subgroup creation to group owners only

  1. Navigate to Group > Settings > General > Permissions
  2. Set "Allowed to create subgroups" to "Owners"
  3. Save changes

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: medium Blocked Member Not Removed fix difficulty: easy #

Remove blocked members from the GitLab group

  1. Navigate to Group > Members
  2. Find the blocked member
  3. Confirm the account is no longer needed
  4. Remove from the group and any subgroups

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

More GitLab checks

The information on this page is provided for general informational purposes and is believed to be accurate as of its most recent update. Product names, logos, and trademarks are the property of their respective owners and are used for identification purposes only; their use does not imply any affiliation with or endorsement by those owners. Descriptions of third-party applications and of compliance frameworks are based on publicly available documentation and may change over time.

See these checks run on your stack

Start a free 14-day trial — no credit card required.

Start Free Trial