A package must say what it is for
- Risk
- Moderate
- Evidence
- metadata
- Section
- Ownership
- Fix shape
- entity · Package
Defence in depth — other controls still give coverage if this one fails.
Decidable from the instance’s own configuration.
Whose work this is, and what it was for.
One task per non-compliant package.
Control Statement: A package installed or created by the organisation must carry a description of its purpose.
Description: Creatio stores a description against every package. This control requires that packages not shipped by the platform vendor carry one, in the instance itself rather than in a document elsewhere.
Rationale: A package is the unit work arrives in, which makes its description the only place the instance can explain itself. Empty, and the name is the entire documentation — which is how an organisation ends up with a dozen packages nobody can account for, unable to say which are load-bearing and which are the residue of a project that ended years ago. The answer usually leaves with the person who installed them.
Audit Procedure:
- Enumerate the packages present that are not maintained by the platform vendor.
- Record every package whose description is empty.
- Note how many objects and processes each contains — the larger ones matter most.
Remediation:
- Write one sentence per package: what it is for, and who asked for it.
- Start with the packages carrying the most objects and processes.
- Where nobody can say what a package is for, that is the finding — record it and decide whether it can be removed.
Default Value: Creatio leaves the package description empty and never requires it, including for packages installed from the marketplace.
Cite this control as CRB-OWN-002, Release Readiness Benchmark v0.2.0. Verified against
Creatio 8.x. Published by ctx10; not
affiliated with or endorsed by Creatio.