Permission-administration operations must not be granted to a company-wide role
- Risk
- Critical
- Evidence
- metadata
- Section
- System operations
- Fix shape
- entity · Operation
Absent, it allows unauthorised access without any other control having to fail.
Decidable from the instance’s own configuration.
The administrative powers that sit above the access model.
One task per non-compliant operation.
Maps to ISO 27001SOC 2
Control Statement: System operations that permit changing access rights must not be granted to a role that reaches every user.
Description:
Creatio governs administrative capability through system operation permissions, configured separately
from object access rights. A subset of these operations permits changing access rights themselves.
This control requires that no such operation be granted to a role reaching the entire organisation, as
identified under CSB-ROLE-002.
The operations in scope are those that permit a user to alter who has access, including:
- changing operation permissions on an object
- changing column permissions on an object
- enabling or disabling column permissions on an object
- changing permissions to add records to an object
- changing the grantee of an object operation permission
- changing delegated permissions
- delegating access on behalf of another user
Operation names are localised and vary between versions. Identify operations by the capability they confer, not by matching the strings above.
Rationale: These operations sit above the access model rather than inside it. A user holding one does not merely have broad access — they can grant themselves any access the instance is capable of expressing, which makes every other access control in this benchmark advisory for as long as the grant stands. It also makes the escalation invisible to review, because the resulting rights appear as ordinary grants indistinguishable from ones an administrator intended. Where the grantee is a role reaching every user, the instance has no enforceable access boundary at all.
Audit Procedure:
- Obtain the list of roles reaching every user, as recorded under
CSB-ROLE-002. - Open System Designer → Users and administration → Operation permissions.
- Identify the operations that confer the ability to change access rights, using the capability list above rather than name matching.
- For each, review the roles granted permission to execute it.
- Record as non-compliant every grant of such an operation to a role identified in step 1.
Remediation:
- Identify the administrative roles that genuinely require each permission-administration operation.
- Grant the operation to those roles explicitly.
- Revoke it from the company-wide role.
- Review the access rights configured while the grant was in force, since rights created through it remain in place after the operation is revoked.
- Record the resulting grants in the inventory required by
CSB-OPS-005.
Default Value: Creatio ships permission-administration operations granted to its administrative roles and not to company-wide roles. Grants that reach a company-wide role are therefore the result of a change made after installation.
Cite this control as CSB-OPS-001, Security Benchmark v0.5.0. Verified against
Creatio 8.x. Published by ctx10; not
affiliated with or endorsed by Creatio.