CSB-DATA-001

Objects holding personal or sensitive data must be identified and recorded

Risk
High

Absent, it prevents detection, investigation or response.

Evidence
process

Needs evidence a person keeps — an inventory, an owner, an approval.

Section
Data exposure

Where sensitive data lives and how narrowly it is read.

Fix shape
inventory

Establish and maintain a record.

Maps to GDPRISO 27001SOC 2

Control Statement: The organisation must maintain an inventory identifying which objects and columns in the instance hold personal or otherwise sensitive data.

Description: Every object holding personal data, financial data, health data, credentials, or data the organisation classifies as sensitive must be recorded, along with the specific columns concerned and the classification applied. The inventory must cover custom objects as well as standard Creatio objects that have been extended with sensitive columns.

Rationale: Sensitivity is a property of meaning, not of structure, and no amount of inspection of the configuration will reveal it: a text column named Notes may hold anything from a delivery instruction to a medical detail, and nothing in the instance distinguishes the two. Every judgement about proportionate access therefore depends on a classification a person has made and recorded. It is also the prerequisite for answering the questions a data subject request or a breach notification poses under deadline — which objects hold this person’s data, and what was exposed. An organisation without this inventory answers those questions by searching the instance under time pressure, which is where material omissions occur.

Audit Procedure:

  1. Confirm an inventory of objects and columns holding personal or sensitive data exists in the system of record required by CSB-FDNS-001.
  2. Confirm it records the classification applied to each entry.
  3. Confirm coverage of extended standard objects, not only custom ones.
  4. Sample the custom objects in the configuration and confirm that those holding sensitive data appear in the inventory.
  5. Confirm the inventory has been reviewed within the defined cycle.

Remediation:

  1. Enumerate the objects in the configuration, including standard objects carrying custom columns.
  2. Review each for personal or sensitive content and record the classification.
  3. Record the specific columns concerned, not only the object.
  4. Establish a review cycle covering newly created objects and columns.

Default Value: Creatio applies no data classification to objects or columns, and provides no facility for recording one.

Cite this control as CSB-DATA-001, Security Benchmark v0.5.0. Verified against Creatio 8.x. Published by ctx10; not affiliated with or endorsed by Creatio.