Inactive roles must not retain access rights
- Risk
- Moderate
- Evidence
- metadata
- Section
- Role model
- Fix shape
- entity · Role
Defence in depth — other controls still give coverage if this one fails.
Decidable from the instance’s own configuration.
The roles access is granted to, and how far each one reaches.
One task per non-compliant role.
Maps to ISO 27001
Control Statement: A role marked inactive must not retain configured access rights.
Description: Creatio allows a role to be deactivated without removing the access rights configured for it. This control requires that deactivating a role be accompanied by removal of its grants, so that the rights a role holds and the rights it can confer do not diverge.
Rationale: An inactive role holding live grants is a reactivation hazard. Deactivation is normally used as a reversible, low-commitment alternative to deletion — precisely because it is understood to be reversible — so the role is liable to be reactivated later by someone treating it as dormant rather than as a package of access. At that moment the retained grants take effect again, in an instance whose data, objects and org structure have moved on. The rights are also invisible to reviews that filter to active roles, which is the normal way to review them.
Audit Procedure:
- Enumerate the roles marked inactive in the instance.
- For each, review the object operation rights, column rights and default record rights configured for it.
- Record every inactive role holding one or more configured grants.
- Establish whether each such role is intended to be reactivated.
Remediation:
- For each inactive role holding grants, determine whether the role is genuinely retired.
- Where it is, remove its configured access rights, then delete the role.
- Where reactivation is genuinely anticipated, record the intended reactivation and the access it
would restore in the system of record required by
CSB-FDNS-001. - Add removal of access rights to the procedure followed when deactivating a role.
Default Value: Creatio does not remove or suspend a role’s configured access rights when the role is deactivated, and does not indicate on the permission screens that a grantee role is inactive.
Cite this control as CSB-ROLE-003, Security Benchmark v0.5.0. Verified against
Creatio 8.x. Published by ctx10; not
affiliated with or endorsed by Creatio.