CSB-ROLE-002

Roles that reach every user must be identified and recorded

Risk
High

Absent, it prevents detection, investigation or response.

Evidence
hybrid

Configuration narrows it; a person decides.

Section
Role model

The roles access is granted to, and how far each one reaches.

Fix shape
inventory

Establish and maintain a record.

Maps to ISO 27001SOC 2

Control Statement: The organisation must identify and record every role whose membership reaches all users of the instance, and must record which population each such role represents.

Description: An organisation role at the root of the organisational structure — one with no parent — is inherited by everyone beneath it. An instance normally has more than one such role, and they do not necessarily represent the same population: internal employees and external portal users are typically separate roots with very different appropriate access. This control requires that these roles be identified, and that the population each represents be recorded.

Rationale: Several controls in this benchmark turn on whether a grant reaches everyone, and none of them can be evaluated without first establishing which roles those are. The question is easy to get wrong from naming alone: role names are free text, frequently localised, and an instance may carry more than one root whose names give no reliable indication of which covers employees and which covers external users. Recording the populations explicitly also surfaces the distinction that matters most — a grant to an externally-facing root role is exposure outside the organisation, which is a materially different finding from the same grant to an internal one.

Audit Procedure:

  1. Enumerate the organisation roles that have no parent role. These are the roots of the organisational structure.
  2. For each, determine the population it covers — internal users, external or portal users, or a subset — by inspecting its membership rather than inferring from its name.
  3. Confirm each appears in the inventory with its population recorded.
  4. Confirm that any root role representing external or portal users is explicitly identified as such.

Remediation:

  1. Identify the root organisation roles in the instance.
  2. Determine and record the population each covers, verifying against membership rather than name.
  3. Explicitly flag those representing external or portal users.
  4. Add the record to the system of record required by CSB-FDNS-001 and re-verify it whenever the organisational structure changes.

Default Value: Creatio ships with root organisation roles covering all internal users and all external users. It does not distinguish them in any machine-readable way beyond their names and membership, and does not warn when a permission is granted to one.

Cite this control as CSB-ROLE-002, Security Benchmark v0.5.0. Verified against Creatio 8.x. Published by ctx10; not affiliated with or endorsed by Creatio.