Attachments must not be governed more openly than the records they belong to
- Risk
- High
- Evidence
- hybrid
- Section
- External access
- Fix shape
- org
Absent, it prevents detection, investigation or response.
Configuration narrows it; a person decides.
The doors that open outward: external identities, system accounts, and what answers before anyone signs in.
One instance-level change.
Maps to GDPRISO 27001SOC 2
Control Statement: Where access to a record type is restricted, access to the files attached to those records must be restricted at least as narrowly.
Description: Creatio stores each record type’s attachments in a companion object with an access model of its own, configured independently of the record’s. This control requires that wherever the organisation has restricted a record type — per-record rights, or rights limited to particular roles — the companion attachment object carries restrictions at least as narrow. It applies to every record type holding restricted data, including the stock ones.
Rationale: What an organisation restricts about a record is usually most concentrated in its attachments: the signed contract on the order, the identity document on the contact, the medical report on the case. Because the attachment object is governed separately, restricting the record does nothing to the files, and the gap does not announce itself — every screen shows attachments under the record they belong to, so the files look inherited while being independently, and more openly, governed. A reader who cannot open the record can still be one list view away from everything attached to it.
Audit Procedure:
- Enumerate the record types the organisation restricts, from the object permissions section.
- For each, locate the companion attachment object and review its access model.
- Record as non-compliant every restricted record type whose attachment object is unrestricted, or restricted more loosely than the record itself.
- For a sample of restricted records, confirm as a user without access to the record that its attachments cannot be reached through list views, lookups or reporting.
Remediation:
- For each non-compliant pair, enable access administration on the attachment object.
- Configure the attachment object’s rights to mirror the record’s, or narrower.
- Verify, as an unauthorised user, that the attachments are no longer reachable.
- Add the record/attachment comparison to the periodic access review, so new restricted record types are checked as they appear.
Default Value: Creatio ships attachment objects with record-level access administration disabled, including for record types whose parent ships with it enabled — an attachment can therefore be more reachable than the record it belongs to in stock configuration, before anybody has changed anything.
Cite this control as CSB-EXT-004, Security Benchmark v0.5.0. Verified against
Creatio 8.x. Published by ctx10; not
affiliated with or endorsed by Creatio.