Centralised security system of record
- Risk
- High
- Evidence
- process
- Section
- Foundations
- Fix shape
- inventory
Absent, it prevents detection, investigation or response.
Needs evidence a person keeps — an inventory, an owner, an approval.
What every other control assumes is written down somewhere.
Establish and maintain a record.
Maps to ISO 27001SOC 2
Control Statement: The organisation must maintain a centralised system of record documenting its Creatio security configuration decisions, exceptions, justifications, and the inventories this benchmark requires.
Description: The organisation must maintain a centralised, durable and accessible record of security-relevant decisions about its Creatio implementation: which roles exist and why, which objects hold sensitive data, which elevated permissions have been granted and on whose authority, and which controls in this benchmark have an approved exception. The record must not depend on personal recollection or on the implementation partner’s institutional memory.
Rationale: Creatio implementations are commonly built by a partner and then handed to a customer who inherits the configuration without the reasoning behind it. Every other control in this benchmark asks whether a configuration is intentional — and that question is unanswerable without a record of what was intended. Without one, a reviewer cannot distinguish a deliberate design decision from an accident that has survived three years, and each successive audit re-derives the same conclusions from scratch.
Audit Procedure:
- Identify the designated system of record for Creatio security governance.
- Confirm it is centrally accessible to authorised personnel and does not depend on any individual remaining with the organisation or the partner.
- Confirm it contains the inventories required by this benchmark, including the role inventory
(
CSB-ROLE-001), the elevated-permission inventory (CSB-OPS-002), and the sensitive-data object inventory (CSB-DATA-001). - Confirm every recorded exception carries a justification, an approver and a review date.
- Confirm the record reflects the configuration as it exists at the time of audit, by sampling at least three entries against the live instance.
Remediation:
- Designate a centralised system of record capable of holding the required inventories and decisions.
- Populate it with the inventories this benchmark requires.
- Record existing deviations as explicit, justified and approved exceptions rather than leaving them undocumented.
- Establish a maintenance process that updates the record whenever the configuration changes.
Default Value: Creatio does not provide or require any system of record for security configuration decisions, exceptions or justifications. Configuration changes are stored, but the reasoning behind them is not.
Cite this control as CSB-FDNS-001, Security Benchmark v0.5.0. Verified against
Creatio 8.x. Published by ctx10; not
affiliated with or endorsed by Creatio.