The Security Benchmark for Creatio
Who can see, change and remove what — and whether the instance can prove it. Access rights, roles, administrative operations, sign-in policy and data exposure.
- Controls
- 30
- Critical
- 4
- High
- 16
- Moderate
- 10
- Verified against
- Creatio 8.x
Risk says what happens when a control is absent — not how hard it is to fix.
- CriticalAbsent, it allows unauthorised access without any other control having to fail.
- HighAbsent, it prevents detection, investigation or response.
- ModerateDefence in depth — other controls still give coverage if this one fails.
FDNS Foundations
What every other control assumes is written down somewhere.
ACS Access controls
Who may read, create, change and delete each object.
- CSB-ACS-001 Custom objects that store business data must have access rights enabled Critical
- CSB-ACS-002 Delete rights on custom objects must not be granted to a company-wide role High
- CSB-ACS-003 Default record rights must not grant delegation to a company-wide role High
- CSB-ACS-004 Access rights must not reference objects that no longer exist Moderate
- CSB-ACS-005 Access rights must be granted to roles, not to individual users High
ROLE Role model
The roles access is granted to, and how far each one reaches.
OPS System operations
The administrative powers that sit above the access model.
- CSB-OPS-001 Permission-administration operations must not be granted to a company-wide role Critical
- CSB-OPS-002 Configuration-management operations must be restricted to administrative roles Critical
- CSB-OPS-003 Bulk data export operations must be restricted to roles that require them High
- CSB-OPS-004 Unrestricted business process execution must not be granted to external or company-wide roles High
- CSB-OPS-005 Roles holding elevated system operations must be inventoried and reviewed High
AUTH Authentication
Passwords, lockout, sessions, and what the sign-in page gives away.
- CSB-AUTH-001 A minimum password length must be enforced High
- CSB-AUTH-002 Password composition requirements must be enforced Moderate
- CSB-AUTH-003 Password reuse must be prevented Moderate
- CSB-AUTH-004 Accounts must be locked after repeated failed authentication attempts High
- CSB-AUTH-005 Login messages must not disclose account state Moderate
- CSB-AUTH-006 User sessions must expire after a bounded period of inactivity Moderate
DATA Data exposure
Where sensitive data lives and how narrowly it is read.
EXT External access
The doors that open outward: external identities, system accounts, and what answers before anyone signs in.
- CSB-EXT-001 External identities must be confined to roles scoped for external access Critical
- CSB-EXT-002 Accounts operated by systems must be inventoried with a named owner High
- CSB-EXT-003 Application credentials issued for integrations must be inventoried and reviewed High
- CSB-EXT-004 Attachments must not be governed more openly than the records they belong to High
- CSB-EXT-005 Where the instance answers from must be a recorded decision Moderate
- CSB-EXT-006 Entry points that answer without a signed-in user must be inventoried and justified High
CODE Configuration
What was built here, by whom, and what came from outside.
Published by ctx10. Not affiliated with, endorsed by, or sponsored by Creatio.