CSB-EXT-001

External identities must be confined to roles scoped for external access

Risk
Critical

Absent, it allows unauthorised access without any other control having to fail.

Evidence
hybrid

Configuration narrows it; a person decides.

Section
External access

The doors that open outward: external identities, system accounts, and what answers before anyone signs in.

Fix shape
org

One instance-level change.

Maps to GDPRISO 27001SOC 2

Control Statement: Identities issued to people outside the organisation must hold membership only in roles designated for external access, and self-registration of such identities must be a recorded decision.

Description: Creatio distinguishes identities issued to external parties — customers, partners, suppliers signing in through a portal — from those of the organisation’s own users. This control requires that every external identity’s role membership be limited to roles the organisation has designated as external-facing, and that the ability for outsiders to create such identities themselves, where the instance offers it, be switched on only by a recorded decision.

Rationale: An external identity in an internally scoped role is unauthorised access that required nothing to be broken: the sign-in works, the rights are real, and every access decision downstream of the role behaves as designed. The failure is invisible from inside — each role’s grants look correct when reviewed role by role, and the defect only appears when membership is read from the account side. Self-registration compounds it: where outsiders can create identities, the population of external accounts is no longer a list somebody approved, so confinement of the roles they land in is the only control left standing.

Audit Procedure:

  1. Enumerate the identities marked for external or portal access, in the user administration section.
  2. Obtain the organisation’s designation of which roles are intended for external access.
  3. For each external identity, review its role membership and record as non-compliant any membership in a role not designated external-facing.
  4. Determine whether self-registration of external identities is enabled, and if so, confirm a recorded decision covers it.
  5. If no designation of external-facing roles exists, record the control as failed: confinement cannot be verified against an intent nobody has stated.

Remediation:

  1. Designate, in writing, the roles intended for external access.
  2. Remove external identities from all other roles, re-granting through externally scoped roles where a genuine need exists.
  3. Disable self-registration unless a recorded decision requires it.
  4. Add the external-role designation to the periodic access review, so drift is caught on a cycle.

Default Value: Creatio places external identities under a stock role covering all external users. It records no statement of which roles are intended for external access, and does not prevent an external identity from being granted membership in any other role.

Cite this control as CSB-EXT-001, Security Benchmark v0.5.0. Verified against Creatio 8.x. Published by ctx10; not affiliated with or endorsed by Creatio.