Roles holding elevated system operations must be inventoried and reviewed
- Risk
- High
- Evidence
- process
- Section
- System operations
- Fix shape
- inventory
Absent, it prevents detection, investigation or response.
Needs evidence a person keeps — an inventory, an owner, an approval.
The administrative powers that sit above the access model.
Establish and maintain a record.
Maps to ISO 27001SOC 2
Control Statement: The organisation must maintain an inventory of the roles holding elevated system operations, and must review it on a defined cycle.
Description:
The operations governed by CSB-OPS-001 through CSB-OPS-004 — permission administration,
configuration management, bulk extraction and unrestricted process execution — must be recorded
together with the roles holding them, the justification for each grant, and the date of the last
review. The inventory must be reviewed on a defined cycle and after any change to the instance’s
administrative model.
Rationale: The preceding operation controls each answer a question about a single grant. This one answers the question no individual control can: whether the total administrative surface of the instance is understood and intended. Elevated operations are granted incrementally, usually to resolve a specific obstruction, and each grant is defensible at the moment it is made — so the aggregate is rarely reviewed as a whole and is frequently larger than anyone involved believes. A periodic review against a recorded justification is the only mechanism that shrinks it, because the individual grants will each survive individual scrutiny.
Audit Procedure:
- Confirm an inventory of elevated operation grants exists in the system of record required by
CSB-FDNS-001. - Confirm it covers the operations in scope of
CSB-OPS-001throughCSB-OPS-004. - Confirm each entry records the operation, the holding role, a justification and a review date.
- Confirm the last review falls within the defined cycle.
- Compare the inventory against the operation permissions configured in the instance and record any grant present in the instance but absent from the inventory.
Remediation:
- Enumerate the current grants of the operations in scope.
- Record each with its holding role and justification; where no justification can be established, treat the grant as a candidate for revocation.
- Define a review cycle and assign an accountable owner.
- Conduct the first review, revoking grants that no longer have a justification.
Default Value: Creatio maintains no inventory of elevated operation grants, records no justification for a grant, and provides no review or attestation mechanism.
Cite this control as CSB-OPS-005, Security Benchmark v0.5.0. Verified against
Creatio 8.x. Published by ctx10; not
affiliated with or endorsed by Creatio.