Every role must have a recorded purpose and owner
- Risk
- Moderate
- Evidence
- process
- Section
- Role model
- Fix shape
- inventory
Defence in depth — other controls still give coverage if this one fails.
Needs evidence a person keeps — an inventory, an owner, an approval.
The roles access is granted to, and how far each one reaches.
Establish and maintain a record.
Maps to ISO 27001SOC 2
Control Statement: The organisation must maintain an inventory recording, for every role in the instance, the function it represents and the person accountable for its membership.
Description: Every organisation, department, team and functional role must appear in an inventory stating what the role is for and who is accountable for deciding who belongs to it. The inventory must be reviewed on a defined cycle, and roles no longer serving a purpose must be removed or explicitly retired.
Rationale: Access review is only meaningful against a statement of intent. Presented with a role granting edit rights on twelve objects, a reviewer with no record of the role’s purpose cannot say whether that is correct — the configuration describes what the role does, never what it was meant to do, and the two diverge silently as an implementation ages. Roles accumulated during implementation and never removed are the normal case rather than the exception, and each one is access nobody is accountable for.
Audit Procedure:
- Enumerate the roles configured in the instance, excluding individual user accounts.
- Confirm each appears in the role inventory.
- Confirm each inventory entry records the role’s purpose and a named accountable owner.
- Confirm the inventory has been reviewed within the defined cycle.
- Identify roles present in the instance but absent from the inventory, and inventory entries with no corresponding role.
Remediation:
- Enumerate the roles currently configured.
- For each, record its purpose and identify an accountable owner; where no purpose can be established, mark the role as a candidate for removal.
- Remove or retire roles confirmed as serving no purpose, after verifying they hold no access other roles depend on.
- Establish a review cycle and record the date of each review.
Default Value: Creatio stores role names and structure but records no statement of purpose and no accountable owner for a role, and does not prompt for either when a role is created.
Cite this control as CSB-ROLE-001, Security Benchmark v0.5.0. Verified against
Creatio 8.x. Published by ctx10; not
affiliated with or endorsed by Creatio.