@@ -154,7 +154,7 @@ The following teams comprise the sub-department:
- Vulnerability Research group - [handbook](/handbook/engineering/development/sec/secure/vulnerability-research/)
- API Security - [handbook](/handbook/engineering/development/sec/secure/dynamic-analysis/api-security/)
- Security Risk Management
- Security Policies group - [handbook](/handbook/engineering/development/sec/software-supply-chain-security/security-policies/)
- Security Policies group - [handbook](/handbook/engineering/development/sec/security-risk-management/security-policies/)
- Threat Insights group - [handbook](/handbook/engineering/development/sec/security-risk-management/security-insights/)
It is important to delineate who the EM and PM DRIs are for every functionality, especially where this may not be obvious. This is documented on a dedicated [delineation page](delineate-sec.html).
@@ -43,31 +43,15 @@ We use our [Security Policies Priorities](https://about.gitlab.com/direction/sec
Complete items are removed from the table once the code is in production without a feature flag, and a release post, if applicable, has been merged. The epic is closed at this point.
The Security Policies group largely follows GitLab's [Product Development Flow](/handbook/product-development/product-development-flow/).
Additional information about how we operate can be found on the [Planning page](/handbook/engineering/development/sec/security-risk-management/srm-planning/).
Our current workflow is visualized as flowchart on the [Workflow page](/handbook/engineering/development/sec/software-supply-chain-security/security-policies/workflow/).
Our current workflow is visualized as flowchart on the [Workflow page](/handbook/engineering/development/sec/security-risk-management/security-policies/workflow/).
Our current process on how we work on features is on the [Feature process page](/handbook/engineering/development/sec/software-supply-chain-security/security-policies/feature_process/)
Our current process on how we work on features is on the [Feature process page](/handbook/engineering/development/sec/security-risk-management/security-policies/feature_process/)