CSB-EXT-005

Where the instance answers from must be a recorded decision

Risk
Moderate

Defence in depth — other controls still give coverage if this one fails.

Evidence
process

Needs evidence a person keeps — an inventory, an owner, an approval.

Section
External access

The doors that open outward: external identities, system accounts, and what answers before anyone signs in.

Fix shape
org

One instance-level change.

Maps to ISO 27001SOC 2

Control Statement: The organisation must record a decision on the networks from which the instance may be reached, and where that decision restricts reachability, the restriction must be verifiably in force.

Description: A Creatio instance answers to any network that can reach its address unless something in front of it — a VPN, an allowlist at the proxy or hosting layer, a private network — decides otherwise. This control does not require that reachability be restricted; it requires that reachability be decided: a recorded statement of where the instance may be reached from, who decided it, and — where the decision restricts — evidence that the restriction actually holds.

Rationale: Every credential control in this benchmark assumes an attacker who can reach the sign-in page. Unrestricted reachability is the correct choice for some organisations and an accident for most — the difference is whether anybody decided. An instance reachable from everywhere by decision has an owner who accepted that exposure and compensated elsewhere; one reachable from everywhere by default has an attack surface nobody signed for. The recorded decision is also what an incident review reaches for first: whether the access that occurred was possible by design.

Audit Procedure:

  1. Obtain the recorded reachability decision: the permitted networks, who decided, and when it was last reviewed.
  2. If no record exists, the control fails; current reachability being restricted does not substitute for a decision nobody recorded.
  3. Where the decision restricts reachability, attempt to reach the sign-in page from a network the decision excludes, and confirm the attempt fails.
  4. Confirm the restriction covers every route to the instance — the application address, and any integration or service endpoints it exposes — not only the address people use.

Remediation:

  1. Decide, with whoever owns the instance’s risk, the networks the instance should answer from.
  2. Record the decision, the decider and the date.
  3. Where the decision restricts, implement the restriction at the network or hosting layer, and verify it from an excluded network.
  4. Review the decision when the hosting arrangement changes, and on the periodic security review cycle.

Default Value: A Creatio instance imposes no network-level restriction of its own: it answers to whatever can reach its address. Restricting where it answers from is deployment infrastructure, not product configuration, and is absent unless somebody built it.

Cite this control as CSB-EXT-005, Security Benchmark v0.5.0. Verified against Creatio 8.x. Published by ctx10; not affiliated with or endorsed by Creatio.