Objects holding personal or sensitive data must be identified and recorded
- Risk
- High
- Evidence
- process
- Section
- Data exposure
- Fix shape
- inventory
Absent, it prevents detection, investigation or response.
Needs evidence a person keeps — an inventory, an owner, an approval.
Where sensitive data lives and how narrowly it is read.
Establish and maintain a record.
Maps to GDPRISO 27001SOC 2
Control Statement: The organisation must maintain an inventory identifying which objects and columns in the instance hold personal or otherwise sensitive data.
Description: Every object holding personal data, financial data, health data, credentials, or data the organisation classifies as sensitive must be recorded, along with the specific columns concerned and the classification applied. The inventory must cover custom objects as well as standard Creatio objects that have been extended with sensitive columns.
Rationale:
Sensitivity is a property of meaning, not of structure, and no amount of inspection of the
configuration will reveal it: a text column named Notes may hold anything from a delivery
instruction to a medical detail, and nothing in the instance distinguishes the two. Every judgement
about proportionate access therefore depends on a classification a person has made and recorded. It is
also the prerequisite for answering the questions a data subject request or a breach notification
poses under deadline — which objects hold this person’s data, and what was exposed. An organisation
without this inventory answers those questions by searching the instance under time pressure, which is
where material omissions occur.
Audit Procedure:
- Confirm an inventory of objects and columns holding personal or sensitive data exists in the system
of record required by
CSB-FDNS-001. - Confirm it records the classification applied to each entry.
- Confirm coverage of extended standard objects, not only custom ones.
- Sample the custom objects in the configuration and confirm that those holding sensitive data appear in the inventory.
- Confirm the inventory has been reviewed within the defined cycle.
Remediation:
- Enumerate the objects in the configuration, including standard objects carrying custom columns.
- Review each for personal or sensitive content and record the classification.
- Record the specific columns concerned, not only the object.
- Establish a review cycle covering newly created objects and columns.
Default Value: Creatio applies no data classification to objects or columns, and provides no facility for recording one.
Cite this control as CSB-DATA-001, Security Benchmark v0.5.0. Verified against
Creatio 8.x. Published by ctx10; not
affiliated with or endorsed by Creatio.