Where the instance answers from must be a recorded decision
- Risk
- Moderate
- Evidence
- process
- Section
- External access
- Fix shape
- org
Defence in depth — other controls still give coverage if this one fails.
Needs evidence a person keeps — an inventory, an owner, an approval.
The doors that open outward: external identities, system accounts, and what answers before anyone signs in.
One instance-level change.
Maps to ISO 27001SOC 2
Control Statement: The organisation must record a decision on the networks from which the instance may be reached, and where that decision restricts reachability, the restriction must be verifiably in force.
Description: A Creatio instance answers to any network that can reach its address unless something in front of it — a VPN, an allowlist at the proxy or hosting layer, a private network — decides otherwise. This control does not require that reachability be restricted; it requires that reachability be decided: a recorded statement of where the instance may be reached from, who decided it, and — where the decision restricts — evidence that the restriction actually holds.
Rationale: Every credential control in this benchmark assumes an attacker who can reach the sign-in page. Unrestricted reachability is the correct choice for some organisations and an accident for most — the difference is whether anybody decided. An instance reachable from everywhere by decision has an owner who accepted that exposure and compensated elsewhere; one reachable from everywhere by default has an attack surface nobody signed for. The recorded decision is also what an incident review reaches for first: whether the access that occurred was possible by design.
Audit Procedure:
- Obtain the recorded reachability decision: the permitted networks, who decided, and when it was last reviewed.
- If no record exists, the control fails; current reachability being restricted does not substitute for a decision nobody recorded.
- Where the decision restricts reachability, attempt to reach the sign-in page from a network the decision excludes, and confirm the attempt fails.
- Confirm the restriction covers every route to the instance — the application address, and any integration or service endpoints it exposes — not only the address people use.
Remediation:
- Decide, with whoever owns the instance’s risk, the networks the instance should answer from.
- Record the decision, the decider and the date.
- Where the decision restricts, implement the restriction at the network or hosting layer, and verify it from an excluded network.
- Review the decision when the hosting arrangement changes, and on the periodic security review cycle.
Default Value: A Creatio instance imposes no network-level restriction of its own: it answers to whatever can reach its address. Restricting where it answers from is deployment infrastructure, not product configuration, and is absent unless somebody built it.
Cite this control as CSB-EXT-005, Security Benchmark v0.5.0. Verified against
Creatio 8.x. Published by ctx10; not
affiliated with or endorsed by Creatio.