Roles that reach every user must be identified and recorded
- Risk
- High
- Evidence
- hybrid
- Section
- Role model
- Fix shape
- inventory
Absent, it prevents detection, investigation or response.
Configuration narrows it; a person decides.
The roles access is granted to, and how far each one reaches.
Establish and maintain a record.
Maps to ISO 27001SOC 2
Control Statement: The organisation must identify and record every role whose membership reaches all users of the instance, and must record which population each such role represents.
Description: An organisation role at the root of the organisational structure — one with no parent — is inherited by everyone beneath it. An instance normally has more than one such role, and they do not necessarily represent the same population: internal employees and external portal users are typically separate roots with very different appropriate access. This control requires that these roles be identified, and that the population each represents be recorded.
Rationale: Several controls in this benchmark turn on whether a grant reaches everyone, and none of them can be evaluated without first establishing which roles those are. The question is easy to get wrong from naming alone: role names are free text, frequently localised, and an instance may carry more than one root whose names give no reliable indication of which covers employees and which covers external users. Recording the populations explicitly also surfaces the distinction that matters most — a grant to an externally-facing root role is exposure outside the organisation, which is a materially different finding from the same grant to an internal one.
Audit Procedure:
- Enumerate the organisation roles that have no parent role. These are the roots of the organisational structure.
- For each, determine the population it covers — internal users, external or portal users, or a subset — by inspecting its membership rather than inferring from its name.
- Confirm each appears in the inventory with its population recorded.
- Confirm that any root role representing external or portal users is explicitly identified as such.
Remediation:
- Identify the root organisation roles in the instance.
- Determine and record the population each covers, verifying against membership rather than name.
- Explicitly flag those representing external or portal users.
- Add the record to the system of record required by
CSB-FDNS-001and re-verify it whenever the organisational structure changes.
Default Value: Creatio ships with root organisation roles covering all internal users and all external users. It does not distinguish them in any machine-readable way beyond their names and membership, and does not warn when a permission is granted to one.
Cite this control as CSB-ROLE-002, Security Benchmark v0.5.0. Verified against
Creatio 8.x. Published by ctx10; not
affiliated with or endorsed by Creatio.