CRB · v0.2.0 · draft

The Release Readiness Benchmark for Creatio

Whether this instance is ready to be released, and to be run. What is live and who put it there, whether anybody reviews what changed, whether a restore has ever been rehearsed, and who authorised go-live against what.

Controls
10
High
7
Moderate
3
Verified against
Creatio 8.x

Risk says what happens when a control is absent, not how hard it is to fix.

ATTR Attribution

Whether a change can be traced to somebody.

  1. CRB-ATTR-001 Every custom configuration element must be attributable to an identity High
  2. CRB-ATTR-002 The identities that change production configuration must be inventoried High

REV Review

Whether anybody reads what changed.

  1. CRB-REV-001 Production configuration changes must be reviewed on a cycle High

SCHED Schedules

Timers, and whether what they start still runs.

  1. CRB-SCHED-001 A schedule must not point at a process that cannot run High

RECV Recovery

Whether the way back exists before it is needed.

  1. CRB-RECV-001 The production instance must have a rehearsed restore path High
  2. CRB-RECV-002 Production configuration changes must have a rollback path High

ENV Environments

Where changes are verified before users meet them.

  1. CRB-ENV-001 Production changes must be staged through a non-production environment Moderate

GATE Go-live

Who said this was ready, and against what.

  1. CRB-GATE-001 Go-live must be authorised against recorded criteria by a named owner Moderate

OWN Ownership

Whose work this is, and what it was for.

  1. CRB-OWN-001 Custom configuration elements must carry the instance naming prefix High
  2. CRB-OWN-002 A package must say what it is for Moderate

Published by ctx10. Not affiliated with, endorsed by, or sponsored by Creatio.