CSB-CODE-003

Installed packages must have a recorded maintainer and an approved source

Risk
High

Absent, it prevents detection, investigation or response.

Evidence
hybrid

Configuration narrows it; a person decides.

Section
Configuration

What was built here, by whom, and what came from outside.

Fix shape
inventory

Establish and maintain a record.

Maps to ISO 27001SOC 2

Control Statement: Every package installed in the instance beyond those shipped by the platform vendor must have a recorded maintainer, a recorded source, and a recorded approval.

Description: Creatio configuration is delivered in packages, each carrying a maintainer. This control requires an inventory of the packages present that were not shipped by the platform vendor — those installed from the marketplace, supplied by an implementation partner, or developed in-house — recording for each its maintainer, where it came from, who approved its installation, and whether it remains supported.

Rationale: An installed package is not an add-on to the instance; it is code running inside it, with the access the platform affords. A marketplace or partner package can define objects, run business processes, call outbound integrations and read any data the platform can reach, and nothing constrains it to the functionality it was installed for. Its trust level is therefore that of the platform itself, while the decision to install it is typically made once, quickly, to obtain a specific feature.

The inventory is what makes that decision reviewable afterwards. Without it, an organisation cannot answer which third-party code is running in its instance, who maintains it, or whether it is still maintained at all — and cannot act on a disclosed vulnerability in a package, because it does not know it has one installed.

Audit Procedure:

  1. Enumerate the packages present in the instance and their maintainers.
  2. Separate those shipped by the platform vendor from the remainder.
  3. For each remaining package, confirm the inventory records its maintainer, source, approver and current support status.
  4. Record as non-compliant every package absent from the inventory, and every entry with no recorded approval.
  5. Identify packages whose maintainer no longer supports them.

Remediation:

  1. Enumerate the non-vendor packages currently installed.
  2. For each, establish its source and maintainer, and record who approved or now accepts its installation.
  3. Remove packages that are unused or unsupported, after confirming nothing depends on them.
  4. Establish an approval step for future package installation, and a review cycle covering support status.

Default Value: Creatio records a maintainer per package but applies no approval process to installation, no distinction between trusted and untrusted sources, and no notification when an installed package ceases to be maintained.

Cite this control as CSB-CODE-003, Security Benchmark v0.5.0. Verified against Creatio 8.x. Published by ctx10; not affiliated with or endorsed by Creatio.