Accounts operated by systems must be inventoried with a named owner
- Risk
- High
- Evidence
- process
- Section
- External access
- Fix shape
- inventory
Absent, it prevents detection, investigation or response.
Needs evidence a person keeps — an inventory, an owner, an approval.
The doors that open outward: external identities, system accounts, and what answers before anyone signs in.
Establish and maintain a record.
Maps to ISO 27001SOC 2
Control Statement: The organisation must maintain an inventory recording, for every account operated by software rather than a person, the system that uses it, the access it requires, and a named accountable owner.
Description: Integrations, middleware, scheduled jobs and connected services sign in to Creatio through accounts of their own. Each such account must appear in an inventory stating which system holds its credentials, why it has the rights it has, and which person answers for it. Accounts serving systems that no longer exist must be deactivated.
Rationale: A system-operated account has no employment relationship to end and no leaver process to catch it: its credential outlives every staff departure, sits in configuration files and secret stores outside the instance, and is exercised at whatever hour the software runs. It is also the account whose activity looks most legitimate — steady, high-volume, and identical every day — which is precisely what makes misuse of one hard to notice. Without a named owner there is nobody to ask the only questions that matter about such an account: whether it is still needed, and whether its rights are still the ones the integration requires.
Audit Procedure:
- Enumerate the accounts marked as system-operated in the user administration section, together with any account whose sign-in activity shows software rather than a person behind it.
- Confirm each appears in the inventory.
- Confirm each inventory entry records the consuming system, the rights required, and a named owner.
- Confirm each account’s actual rights do not exceed what its entry records as required.
- Record as non-compliant any account absent from the inventory, any entry whose consuming system no longer exists, and any account still active whose entry says it should not be.
Remediation:
- Enumerate the system-operated accounts currently able to sign in.
- For each, identify the consuming system and an accountable owner; where neither can be established, deactivate the account and observe what stops.
- Reduce each account’s rights to what its integration demonstrably requires.
- Establish a review cycle aligned with the role inventory review, and record the date of each pass.
Default Value: Creatio records an account type distinguishing system-operated accounts from those used by people, but records no owner, no consuming system and no statement of required rights for either kind.
Cite this control as CSB-EXT-002, Security Benchmark v0.5.0. Verified against
Creatio 8.x. Published by ctx10; not
affiliated with or endorsed by Creatio.