CSB · v0.5.0 · draft

The Security Benchmark for Creatio

Who can see, change and remove what — and whether the instance can prove it. Access rights, roles, administrative operations, sign-in policy and data exposure.

Controls
30
Critical
4
High
16
Moderate
10
Verified against
Creatio 8.x

Risk says what happens when a control is absent — not how hard it is to fix.

FDNS Foundations

What every other control assumes is written down somewhere.

  1. CSB-FDNS-001 Centralised security system of record High

ACS Access controls

Who may read, create, change and delete each object.

  1. CSB-ACS-001 Custom objects that store business data must have access rights enabled Critical
  2. CSB-ACS-002 Delete rights on custom objects must not be granted to a company-wide role High
  3. CSB-ACS-003 Default record rights must not grant delegation to a company-wide role High
  4. CSB-ACS-004 Access rights must not reference objects that no longer exist Moderate
  5. CSB-ACS-005 Access rights must be granted to roles, not to individual users High

ROLE Role model

The roles access is granted to, and how far each one reaches.

  1. CSB-ROLE-001 Every role must have a recorded purpose and owner Moderate
  2. CSB-ROLE-002 Roles that reach every user must be identified and recorded High
  3. CSB-ROLE-003 Inactive roles must not retain access rights Moderate

OPS System operations

The administrative powers that sit above the access model.

  1. CSB-OPS-001 Permission-administration operations must not be granted to a company-wide role Critical
  2. CSB-OPS-002 Configuration-management operations must be restricted to administrative roles Critical
  3. CSB-OPS-003 Bulk data export operations must be restricted to roles that require them High
  4. CSB-OPS-004 Unrestricted business process execution must not be granted to external or company-wide roles High
  5. CSB-OPS-005 Roles holding elevated system operations must be inventoried and reviewed High

AUTH Authentication

Passwords, lockout, sessions, and what the sign-in page gives away.

  1. CSB-AUTH-001 A minimum password length must be enforced High
  2. CSB-AUTH-002 Password composition requirements must be enforced Moderate
  3. CSB-AUTH-003 Password reuse must be prevented Moderate
  4. CSB-AUTH-004 Accounts must be locked after repeated failed authentication attempts High
  5. CSB-AUTH-005 Login messages must not disclose account state Moderate
  6. CSB-AUTH-006 User sessions must expire after a bounded period of inactivity Moderate

DATA Data exposure

Where sensitive data lives and how narrowly it is read.

  1. CSB-DATA-001 Objects holding personal or sensitive data must be identified and recorded High
  2. CSB-DATA-003 Column rights must not reference columns that no longer exist Moderate
  3. CSB-DATA-004 Automated reads must select only the columns they require Moderate

EXT External access

The doors that open outward: external identities, system accounts, and what answers before anyone signs in.

  1. CSB-EXT-001 External identities must be confined to roles scoped for external access Critical
  2. CSB-EXT-002 Accounts operated by systems must be inventoried with a named owner High
  3. CSB-EXT-003 Application credentials issued for integrations must be inventoried and reviewed High
  4. CSB-EXT-004 Attachments must not be governed more openly than the records they belong to High
  5. CSB-EXT-005 Where the instance answers from must be a recorded decision Moderate
  6. CSB-EXT-006 Entry points that answer without a signed-in user must be inventoried and justified High

CODE Configuration

What was built here, by whom, and what came from outside.

  1. CSB-CODE-003 Installed packages must have a recorded maintainer and an approved source High

Published by ctx10. Not affiliated with, endorsed by, or sponsored by Creatio.