CRB-ATTR-001

Every custom configuration element must be attributable to an identity

Risk
High

Absent, it prevents detection, investigation or response.

Evidence
metadata

Decidable from the instance’s own configuration.

Section
Attribution

Whether a change can be traced to somebody.

Fix shape
mechanism

Build a process or capability.

Maps to ISO 27001SOC 2

Control Statement: Every configuration element the organisation owns must record a last-modifying identity that resolves to a user of the instance.

Description: Creatio stores the identity that last modified each configuration element. This control requires that identity to resolve — to a person, or to a named deployment identity. An element whose modifier cannot be resolved has no accountable author at all.

Rationale: Attribution is the difference between a change history and a list of dates. An element whose modifier does not resolve cannot be traced to anybody: not to ask why the change was made, not to establish whether it was authorised, not to find out what else that person changed at the same time. The gap is only ever discovered when somebody needs the answer, which is exactly when it cannot be reconstructed.

ctx10 counts these; it deliberately does not record WHO modified what, so the count is the finding and the list is a question for the instance itself.

Audit Procedure:

  1. Enumerate the configuration elements belonging to packages the platform vendor does not maintain.
  2. For each, read the recorded last-modifying identity.
  3. Resolve that identity against the users of the instance.
  4. Record every element whose identity does not resolve.

Remediation:

  1. For each unresolved element, establish from your own records who made the change.
  2. Where the identity belonged to a user who has been deleted, record that — deleting a user should not erase the authorship of everything they built.
  3. Where changes arrive through a deployment pipeline, give it a durable identity that will still resolve in a year.

Default Value: Creatio records the modifying identity but does not require it to remain resolvable, and does not report elements whose author can no longer be identified.

Cite this control as CRB-ATTR-001, Release Readiness Benchmark v0.2.0. Verified against Creatio 8.x. Published by ctx10; not affiliated with or endorsed by Creatio.