CSB-OPS-005

Roles holding elevated system operations must be inventoried and reviewed

Risk
High

Absent, it prevents detection, investigation or response.

Evidence
process

Needs evidence a person keeps — an inventory, an owner, an approval.

Section
System operations

The administrative powers that sit above the access model.

Fix shape
inventory

Establish and maintain a record.

Maps to ISO 27001SOC 2

Control Statement: The organisation must maintain an inventory of the roles holding elevated system operations, and must review it on a defined cycle.

Description: The operations governed by CSB-OPS-001 through CSB-OPS-004 — permission administration, configuration management, bulk extraction and unrestricted process execution — must be recorded together with the roles holding them, the justification for each grant, and the date of the last review. The inventory must be reviewed on a defined cycle and after any change to the instance’s administrative model.

Rationale: The preceding operation controls each answer a question about a single grant. This one answers the question no individual control can: whether the total administrative surface of the instance is understood and intended. Elevated operations are granted incrementally, usually to resolve a specific obstruction, and each grant is defensible at the moment it is made — so the aggregate is rarely reviewed as a whole and is frequently larger than anyone involved believes. A periodic review against a recorded justification is the only mechanism that shrinks it, because the individual grants will each survive individual scrutiny.

Audit Procedure:

  1. Confirm an inventory of elevated operation grants exists in the system of record required by CSB-FDNS-001.
  2. Confirm it covers the operations in scope of CSB-OPS-001 through CSB-OPS-004.
  3. Confirm each entry records the operation, the holding role, a justification and a review date.
  4. Confirm the last review falls within the defined cycle.
  5. Compare the inventory against the operation permissions configured in the instance and record any grant present in the instance but absent from the inventory.

Remediation:

  1. Enumerate the current grants of the operations in scope.
  2. Record each with its holding role and justification; where no justification can be established, treat the grant as a candidate for revocation.
  3. Define a review cycle and assign an accountable owner.
  4. Conduct the first review, revoking grants that no longer have a justification.

Default Value: Creatio maintains no inventory of elevated operation grants, records no justification for a grant, and provides no review or attestation mechanism.

Cite this control as CSB-OPS-005, Security Benchmark v0.5.0. Verified against Creatio 8.x. Published by ctx10; not affiliated with or endorsed by Creatio.