CRB-OWN-002

A package must say what it is for

Risk
Moderate

Defence in depth — other controls still give coverage if this one fails.

Evidence
metadata

Decidable from the instance’s own configuration.

Section
Ownership

Whose work this is, and what it was for.

Fix shape
entity · Package

One task per non-compliant package.

Control Statement: A package installed or created by the organisation must carry a description of its purpose.

Description: Creatio stores a description against every package. This control requires that packages not shipped by the platform vendor carry one, in the instance itself rather than in a document elsewhere.

Rationale: A package is the unit work arrives in, which makes its description the only place the instance can explain itself. Empty, and the name is the entire documentation — which is how an organisation ends up with a dozen packages nobody can account for, unable to say which are load-bearing and which are the residue of a project that ended years ago. The answer usually leaves with the person who installed them.

Audit Procedure:

  1. Enumerate the packages present that are not maintained by the platform vendor.
  2. Record every package whose description is empty.
  3. Note how many objects and processes each contains — the larger ones matter most.

Remediation:

  1. Write one sentence per package: what it is for, and who asked for it.
  2. Start with the packages carrying the most objects and processes.
  3. Where nobody can say what a package is for, that is the finding — record it and decide whether it can be removed.

Default Value: Creatio leaves the package description empty and never requires it, including for packages installed from the marketplace.

Cite this control as CRB-OWN-002, Release Readiness Benchmark v0.2.0. Verified against Creatio 8.x. Published by ctx10; not affiliated with or endorsed by Creatio.