Configuration-management operations must be restricted to administrative roles
- Risk
- Critical
- Evidence
- metadata
- Section
- System operations
- Fix shape
- entity · Operation
Absent, it allows unauthorised access without any other control having to fail.
Decidable from the instance’s own configuration.
The administrative powers that sit above the access model.
One task per non-compliant operation.
Maps to ISO 27001SOC 2
Control Statement: System operations that permit changing the configuration of the instance must be granted only to roles designated as administrative.
Description:
A subset of Creatio’s system operations permits modification of the instance itself rather than the
data within it. This control requires that these be granted only to roles explicitly designated as
administrative in the role inventory required by CSB-ROLE-001.
The operations in scope include those permitting a user to:
- manage configuration elements
- manage system settings
- manage workplace and section setup
- manage the user list, user licences, or portal users
Operation names are localised and vary between versions. Identify operations by the capability they confer.
Rationale:
Configuration-management operations change how the instance behaves for everyone, and their effects
persist beyond the session in which they were made. Managing system settings reaches the settings that
several controls in this benchmark depend on, including the authentication settings in the AUTH
category — so a user holding it can weaken the instance’s password policy or session handling without
holding any authentication-specific permission. Managing configuration elements permits the
introduction of code and schema changes into a production instance outside any deployment process,
which defeats change control regardless of how rigorous that process is elsewhere.
Audit Procedure:
- Obtain the list of roles designated administrative in the role inventory.
- Open System Designer → Users and administration → Operation permissions.
- Identify the operations conferring configuration-management capability, using the capability list above.
- For each, review the roles granted permission to execute it.
- Record as non-compliant every grant to a role not designated administrative.
Remediation:
- For each non-compliant grant, determine whether the role requires the capability.
- Where it does and the role is genuinely administrative, record that designation in the role inventory.
- Where it does not, revoke the grant.
- Where a non-administrative role requires a narrow capability the operation confers broadly, meet the need another way rather than granting the operation.
Default Value: Creatio ships configuration-management operations granted to its administrative roles. Whether the roles an organisation subsequently designates as administrative match those defaults is not something Creatio verifies or reports.
Cite this control as CSB-OPS-002, Security Benchmark v0.5.0. Verified against
Creatio 8.x. Published by ctx10; not
affiliated with or endorsed by Creatio.