CSB-OPS-004

Unrestricted business process execution must not be granted to external or company-wide roles

Risk
High

Absent, it prevents detection, investigation or response.

Evidence
metadata

Decidable from the instance’s own configuration.

Section
System operations

The administrative powers that sit above the access model.

Fix shape
entity · Operation

One task per non-compliant operation.

Maps to ISO 27001SOC 2

Control Statement: The system operation permitting execution of any business process must not be granted to a role representing external users, nor to a role reaching every user.

Description: Creatio provides a system operation permitting a user to run any business process in the instance, irrespective of whether that process is reachable from the interface available to them. This control requires that the operation not be granted to roles representing external or portal users, nor to roles reaching the entire organisation.

Rationale: Business processes routinely perform work their initiator could not perform directly — that is frequently their purpose. A process may read across objects the user cannot open, write records they cannot create, call an integration under stored credentials, or send correspondence on the organisation’s behalf. The operation that permits running any process therefore confers, in aggregate, much of what the instance’s automation is capable of, without regard to the object rights that would otherwise constrain the user.

Granting it to a role representing external or portal users is the more serious case: those users are outside the organisation, and the processes they gain the ability to invoke were designed on the assumption that only staff could reach them.

Audit Procedure:

  1. Obtain the list of roles reaching every user, and those identified as representing external or portal users, as recorded under CSB-ROLE-002.
  2. Open System Designer → Users and administration → Operation permissions.
  3. Identify the operation conferring the ability to run all business processes.
  4. Review the roles granted permission to execute it.
  5. Record as non-compliant every grant to a role identified in step 1.

Remediation:

  1. Determine which roles genuinely require the ability to run processes not reachable from their interface.
  2. Grant the operation to those roles explicitly.
  3. Revoke it from roles representing external users first, then from roles reaching every user.
  4. Where specific processes must remain available to a broad audience, make those processes reachable individually rather than granting unrestricted execution.

Default Value: Creatio grants this operation broadly on installation, commonly including roles covering all employees and all external users. Its presence on those roles is therefore usually an inherited default rather than a decision, and it will not appear in any record of granted permissions.

Cite this control as CSB-OPS-004, Security Benchmark v0.5.0. Verified against Creatio 8.x. Published by ctx10; not affiliated with or endorsed by Creatio.