Bulk data export operations must be restricted to roles that require them
- Risk
- High
- Evidence
- metadata
- Section
- System operations
- Fix shape
- entity · Operation
Absent, it prevents detection, investigation or response.
Decidable from the instance’s own configuration.
The administrative powers that sit above the access model.
One task per non-compliant operation.
Maps to GDPRISO 27001SOC 2
Control Statement: System operations that permit bulk extraction of records must be granted only to roles whose function requires them.
Description: Creatio provides system operations permitting records to be extracted in bulk, separately from the object rights governing whether a user may read those records. This control requires that such operations be granted only to roles with a recorded need.
The operations in scope include those permitting a user to:
- export list records
- export contacts to an external mail or contact service
- import records in bulk, where the same capability permits round-tripping data out of the instance
Operation names are localised and vary between versions. Identify operations by the capability they confer.
Rationale: Read access and bulk extraction are different risks and Creatio governs them separately, which is the useful part of this control. A user who may legitimately read customer records one at a time in the course of their work is not thereby authorised to remove the entire customer list from the organisation’s control. Export operations convert per-record access into a portable copy that leaves the instance entirely — beyond the reach of every access control, retention rule and audit facility that applied while the data was inside it. Export to an external contact or mail service is the sharper case, since the destination is frequently a personal account.
Audit Procedure:
- Open System Designer → Users and administration → Operation permissions.
- Identify the operations conferring bulk extraction capability, using the capability list above.
- For each, review the roles granted permission to execute it.
- For each grant, confirm a recorded business need exists for that role.
- Record as non-compliant any grant without a recorded need, and any grant to a role reaching every
user as identified under
CSB-ROLE-002.
Remediation:
- Identify the roles whose function genuinely requires bulk extraction.
- Grant the relevant operations to those roles explicitly and record the justification.
- Revoke the operations from all other roles, beginning with any role reaching every user.
- Where export to external contact or mail services is not required, revoke those operations entirely rather than narrowing them.
Default Value: Creatio grants several export-related operations broadly on installation, including to roles covering all employees. Bulk extraction capability is therefore frequently present organisation-wide without any decision having been made to grant it.
Cite this control as CSB-OPS-003, Security Benchmark v0.5.0. Verified against
Creatio 8.x. Published by ctx10; not
affiliated with or endorsed by Creatio.