All Revenue Officials and Employees Concerned
Revenue Memorandum Order No. 003-14 • Bureau of Internal Revenue (BIR) Issuances • Revenue Memorandum Orders • Nov 6, 2013
Full text
November 6, 2013 REVENUE MEMORANDUM ORDER NO. 003-14 TO : All Revenue Officials and Employees Concerned SUBJECT : Amending RMO No. 4-2014 on the Allocation of the CY 2014 BIR Collection Goal by Implementing Office As a public office mandated to enforce the internal revenue laws of the Philippines, along with the sensitive duty of performing tax collection, accounting and recording thereof, the Bureau of Internal Revenue (BIR) recognizes that the information systems, including information about its employees and taxpayers, are among its most valuable assets. Information security is essential in maintaining the confidentiality, integrity and availability of the assets entrusted to the Bureau. It is vital in establishing and sustaining trust between the Bureau and its stakeholders, maintaining compliance with relevant regulation and protecting its reputation. Thus, the BIR Information Security Charter (the "InfoSec Charter") (Annex "A" hereof) is hereby promulgated to establish a framework for the Bureau's information security and outline its information security governance structure. The InfoSec Charter defines the roles and responsibilities of the Commissioner of Internal Revenue, its officials, employees and related third parties having access to the BIR's information systems. Henceforth, to ensure faithful compliance and awareness on the important roles and responsibilities for information security, the revenue officials, employees and related third parties are enjoined to read, understand, observe, and uphold the InfoSec Charter. cHESAD This Order shall take effect immediately. (SGD.) KIM S. JACINTO-HENARES Commissioner of Internal Revenue ANNEX A Information Security Charter Revision History Version Date Author(s) Revision Notes 1.0 April 27, 2012 Security Management Introduced a new framework Division (SMD) shifting information security from SMD-centric to Bureau- centric information security management and implementation. ____ ___________ _____________ ____________________ ____ ___________ _____________ ____________________ ____ ___________ _____________ ____________________ ____ ___________ _____________ ____________________ ____ ___________ _____________ ____________________ Table of Contents 1 Introduction 2 Information Security Management Framework 3 Strategy and Policy Setting 3.1 Commissioner of Internal Revenue 3.2 Information Security Steering Committee 4 Support and Monitoring 4.1 Information Security Technical Working Group 4.2 Security Management Division (SMD) 5 Deployment and Execution 5.1 Support Groups, SMD and All Employees of the Bureau 5.2 Information Systems Group 5.3 Third Party 6 Independent Assessment and Compliance 6.1 Performance Evaluation Division and Third Party Certification Bodies Attachment A : Security Management Division Roles and Responsibilities 1 Introduction This document covers the organizational arrangements for managing information security throughout the Bureau of Internal Revenue (BIR) 2 Information Security Management Framework This framework establishes the responsibility, accountability and reporting lines within the information security organization of the Bureau. Responsibility over information security is placed upon the information security owners and the entire Bureau must be involved in developing, implementing, and improving information security controls. This framework is divided into four security functions namely, strategy and policy setting, support and monitoring, deployment and execution, and independent assessment and compliance covering responsibilities for the entire Bureau. This framework is illustrated below. HTScEI 3 Strategy and Policy Setting Strategy and policy setting is a strategic function. It involves high level decision making that drives security direction of the Bureau. It includes assignment of roles and responsibilities and allocation of resources for information security initiatives. 3.1 Commissioner of Internal Revenue The Commissioner of Internal Revenue sets the overall information security direction and is ultimately accountable for the overall governance and assurance of the Bureau's information security effectiveness. 3.1.1 Approve assignment of specific roles and responsibilities for information security across the Bureau. 3.1.2 Provide the resources needed for information security. 3.2 Information Security Steering Committee The Information Security Steering Committee (ISSC) provides a top-down management structure and a practical mechanism for coordinating information security activity throughout the Bureau. This committee is composed of the following: Commissioner of Internal Revenue (Chairman) TAECSD Deputy Commissioner for Information Systems Group Deputy Commissioner for Legal Group Deputy Commissioner for Resource Management Group Deputy Commissioner for Operations Group Assistant Commissioner of Project Management and Implementation Service Assistant Commissioner of Information Systems Project Management Service Assistant Commissioner of Information Systems Development and Operations Service Assistant Commissioner of Internal Affairs Service Assistant Commissioner of Human Resource Development Service This committee is responsible for ensuring that the objective of a secure operating environment is clearly defined in the Bureau's strategic plans. This committee is the project sponsor of information security implementations. IDTcHa 3.2.1 Ensure that Information security goals are identified, meet the organizational requirements, and are integrated in relevant processes. 3.2.2 Review and recommend the approval of information security policies to the Commissioner of Internal Revenue. 3.2.3 Review and approve information security guidelines, standards and procedures. 3.2.4 Meet regularly to discuss information security issues and document actions agreed at meetings. 3.2.5 Monitor information security performance and the Bureau's exposure to information security threats. 3.2.6 Provide clear direction and visible management support for security initiatives. 3.2.7 Initiate plans and programs to maintain information security awareness. 3.2.8 Ensure that the implementation of information security controls is coordinated across the Bureau. 4 Support and Monitoring This function involves the implementation of information security controls. This entails identifying security risks and controls and what assets are exposed to these risks and setting the direction of where and what security controls should be placed to mitigate the risks. AICEDc 4.1 Information Security Technical Working Group The Information Security Technical Working Group (ISTWG) is both a consultative and enforcement body serving as liaisons of the Information Security Steering Committee to all represented BIR offices. 4.1.1 Membership 4.1.1.1 The ISTWG forums/meetings is presided by the Head of the ISTWG. 4.1.1.2 The ISTWG is composed of representatives from different offices of the Bureau. HREA of the Information Systems Project Management Service (Head) Information Systems Group Legal Group Operations Group Information Systems Development and Operations Service Financial Service TAaCED Security Management Division Network Management and Technical Support Division Data Warehousing and Systems Operations Division IT Planning and Standards Division Internal Investigation Division Personnel Adjudication Division Performance Evaluation Division Training Delivery Division Management Division 4.1.2 Responsibilities 4.1.2.1 Initiate enforcement of security controls across the Bureau, consistent with policies, standards and guidelines, and directions set by the BIR Information Security Steering Committee. HIcTDE 4.1.2.2 Actively participate in security activities and compliance to security policies, standards, guidelines and procedures in various BIR offices. 4.1.2.3 Monitor acceptance and compliance to security policies, standards, guidelines and procedures in various BIR offices. 4.1.2.4 Resolve security-related issues and identify concerns that require resolutions. 4.1.2.5 Advise top management on changes to the various BIR offices technology infrastructure that may have impact on the overall information security posture of the Bureau. 4.1.2.6 Review policies, standards, and procedures affecting the information security posture of the entire Bureau. 4.1.2.7 Meet regularly to discuss information security issues affecting the Bureau and document actions agreed at meetings. 4.1.2.8 Provide direction on tactical decisions on application of security controls being contemplated by the Security Management Division when required. 4.2 Security Management Division (SMD) cCTAIE The Security Management Division holds a special role in the support and monitoring function as it generally acts as the alter ego of the ISSC, performing support and monitoring duties together with the ISTWG as identified by the ISSC's initiatives. 4.2.1 Security Architecture The Security Architecture function has the overall responsibility for the model, program and processes for the Bureau security architecture. This function provides tactical decisions on the application of standard security controls throughout the Bureau. 4.2.2 Security Monitoring and Reporting This function is to ensure that the objectives of information security strategies and policies continue to be met and the related operational risks are maintained at an acceptable level over time. Please refer to Attachment A for the detailed roles and responsibilities of SMD. 5 Deployment and Execution Deployment and execution is the operational aspect of security functions. This function involves the actual implementation of security strategy and controls including minimum security baseline standards, user access management and system administration. AIHTEa 5.1 Support Groups, SMD and All Employees of the Bureau All information asset owners, users, and custodians are responsible for the deployment and execution of the information security controls of the Bureau. Primarily so for the following support groups as they hold special interest areas relating to information security and information within the Bureau: Operations Group Information Systems Group Legal Group Resource Management Group 5.1.1 Responsibilities: 5.1.1.1 Implement all applicable information security policies, standards, and procedures. 5.1.1.2 Implement information asset inventory and classification 5.1.1.2.1 Maintains completeness and integrity of the Bureau's information asset inventory and ensures that each information asset is given the appropriate classification and sensitivity levels by their information asset owners. EcDSHT 5.1.1.2.2 Verifies the validity of an existing inventory of information assets and ensures that the inventory of information assets is available to all employees of the Bureau on a need-to-know basis. 5.1.1.2.3 Ensures security controls are in place to protect data privacy of information assets as required by the relevant legislation, regulation and applicable contractual clauses. 5.1.1.2.4 Promptly secures information assets and reports information security violations. 5.1.1.3 Develop, update, deploy and monitor the security awareness program 5.1.1.3.1 SMD Security Deployment Provides input for the security awareness program Facilitates and monitors the technical portion of the security software implementation. This includes the operation of existing security systems and evaluation of security products to be purchased. IDAESH Please refer to Attachment A for the detailed roles and responsibilities of SMD. 5.1.1.3.2 Support groups and employees to participate in information security awareness initiatives in coordination with SMD. 5.1.1.3.3 Training Management Division (TMD) assists SMD in the development and update of the Information Security Awareness Program. 5.1.1.3.4 Training Delivery Division (TDD) assists SMD in the conduct of the Information Security Awareness Program. 5.1.1.4 Ensure timely modification/revocation of access privileges by monitoring employee movements and resignations through information provided by the Personnel Division. 5.2 Information Systems Group 5.2.1 Implement minimum technical security baseline standards. 5.2.2 Implement and administer security solutions such as: Patch management Anti-virus management EcDATH Intrusion Detection and Prevention System (IDPS) Firewall Other security solutions to be deployed 5.2.3 Implement changes according to information security processes such as: Appropriation and deletion of user accounts Patch implementation Changes to security solutions 5.2.4 Manage user access rights and privileges ( i.e. , Application System, Operating System, Database, Network). 5.2.5 Administer security solutions for the Bureau and ensure that these security solutions are working as intended. ( i.e. , firewall, intrusion detection and prevention system, anti-virus, etc.). 5.3 Third Parties Third parties are persons doing business with BIR 5.3.1 Adhere to the Bureau's policies, guidelines, standards and procedures in performing their contractual obligations. SECcIH 5.3.2 Comply with Service Level Agreements (SLA) and contracts. 5.3.3 Ensure proper handling of Bureau's information in the course of executing contracted functions. 5.3.4 Use IT resources for management approved purposes only. 5.3.5 Report any issues or security incidences affecting the Bureau. 6 Independent Assessment and Compliance This function covers independent and risk-based assessment of security controls and periodic review of the overall information security management process of the Bureau. 6.1 Performance Evaluation Division and Third Parties 6.1.1 Assess compliance with the Bureau's information security policies, standards, guidelines and procedures. 6.1.2 Ensure adequate execution of support and monitoring of security controls. 6.1.3 Evaluate appropriateness of deployment and execution of security controls. 6.1.4 Undertake independent and risk-based assessment of security program and compliance testing. AECIaD ATTACHMENT A Security Management Division Roles and Responsibilities Table of Contents 1 Introduction 2 Information Security Organizational Structure 2.1 Security Management Division (SMD) 3 SMD Roles and Responsibilities 3.1 Security Architecture 3.1.1 Information Security Policy Development 3.1.2 Risk Management 3.1.3 Business Continuity Support 3.2 Security Deployment 3.2.1 Security Awareness 3.2.2 Infrastructure Design 3.2.3 Product Evaluation/Selection 3.2.4 Build and Test 3.2.5 Configuration Management 3.3 Security Monitoring and Reporting 3.3.1 Incident Management 3.3.2 User Account Management 3.3.3 Audit and Log Review 3.3.4 Vulnerability Assessment 3.3.5 Physical and Environmental Security 3.3.6 Security Solutions Monitoring 3.3.7 Legal, Third Party, Regulatory and Audit Compliance 3.3.8 Security Governance and Reporting Revision History Version Date Author(s) Revision Notes ________ __________ ___________ ____________ ________ __________ ___________ ____________ ________ __________ ___________ ____________ ________ __________ ___________ ____________ ________ __________ ___________ ____________ 1 Introduction Safeguarding information and systems requires information security activity to be organized effectively throughout the Bureau of Internal Revenue (BIR). This document covers the organizational arrangements for managing information security throughout the BIR, raising security, and ensuring that Security Management Division (SMD) is equipped with the skills and expertise required to design, run and monitor the systems correctly and securely. 2 Information Security Organizational Structure 2.1 Security Management Division (SMD) The BIR is supported by an information security function that has the primary responsibility for promoting good practices in information security across the Bureau. The Chief of the SMD is the head of the information security function and is dedicated to information security full-time. The SMD's main objective is to ensure that good practices in information security are applied effectively throughout the Bureau. Primary of which is to support the initiatives set out by the Information Security Steering Committee (ISSC). HIACEa The SMD should: Be adequately resourced in terms of the number of staff, their range and level of skills, and relevant security management tools ( e.g. , vulnerability assessment software). Have sufficient support from BIR management and Heads of Offices. Maintain adequate contact with resource persons representing the entire Bureau through the Information Security Technical Working Group. Maintain contact with counterparts outside of the Bureau (including government and law enforcement agencies) and with security experts in technology companies and external service providers. 3 SMD Roles and Responsibilities 3.1 Security Architecture 3.1.1 Information Security Policy Development 3.1.1.1 Support the ISSC's policy development by documenting and drafting updates to the information security policies addressing current information security concerns of the Bureau. 3.1.1.2 Coordinate with the ISTWG on consultations regarding updates on the information security policies. Document, facilitate approvals and monitor deviations from security policies, guidelines, standards, and security management procedures. SHCaEA 3.1.2 Risk Management 3.1.2.1 Facilitate and monitor the status of information security risk assessments on the Bureau's information security assets. 3.1.2.2 Assist information asset owners in evaluating cost-effectiveness of security controls. 3.1.2.3 Provide a mechanism for documenting risk assessment determinations and plans for reducing information security risks. 3.1.2.4 Review and recommend approval/disapproval of recommendations on the risk mitigation plan of various divisions regarding the levels of protection needed and make final determinations on tactical implementation of best practices in accordance with the direction provided by the ISSC. 3.1.3 Business Continuity Support 3.1.3.1 Coordinate with other members of the Business Continuity Plan (BCP) Team to incorporate information security within the business continuity program of the Bureau. EIAHcC 3.1.3.2 Facilitate and monitor implementation of information security controls on critical resources in recovery sites and management of information security after a disaster. 3.2 Security Deployment 3.2.1 Security Awareness 3.2.1.1 Facilitate development of materials for the Bureau's security awareness program. 3.2.1.2 Implement the Information Security Awareness Program across different offices. 3.2.1.3 Update the Information Security Awareness Program for any changes in the information security policies, standards, guidelines and procedures adopted by the Bureau. 3.2.2 Infrastructure Design 3.2.2.1 Facilitate assessment of security on networks and information assets to determine if the security controls implemented are adequate to protect the overall network infrastructure of the Bureau. 3.2.2.2 Facilitate the development of a secure network infrastructure design for the Bureau and coordinate with the network and system administrators in implementing such design. acCETD 3.2.2.3 Facilitate updates on the secure network infrastructure design based on new network components and monitor that these new components are placed in secure segments of the Bureau's network infrastructure. 3.2.2.4 Work in consultation with the appropriate ISG personnel and information asset owners to determine which specific network segment the information assets of the Bureau should be in placed and assist in security solution implementations. 3.2.2.5 Coordinate with the network and system administrators to ensure consistent security functionality across different hardware/software platforms. 3.2.3 Product Evaluation/Selection 3.2.3.1 Research and maintain current information on vulnerabilities and security controls that serve as the basis for technical controls. 3.2.3.2 Research on the viability and applicability of emerging security technology and assess vulnerabilities of emerging technologies. 3.2.3.3 Monitor operational trends and technological developments and facilitate evaluation of the applicability of new technologies to the information security environment of the Bureau. DcIHSa 3.2.3.4 Monitor the market for new security solutions such as firewall products, single sign-on, encryption, password generation, and secure internetworking, and recommend security solutions that may be implemented. 3.2.3.5 Facilitate evaluation of security controls on all new systems. 3.2.4 Build and Test 3.2.4.1 Spearhead the implementation of new security solutions. 3.2.4.2 Test and approve access control systems before implementation. 3.2.4.3 Ensure that information security requirements are identified and agreed on prior to the development and/or implementation of applications systems. 3.2.4.4 Develop secure coding development standards and monitor compliance of application developers. 3.2.5 Configuration Management 3.2.5.1 Facilitate development of platform-specific standards and procedures; and monitor to ensure that such are implemented on the specific information systems. cDAEIH 3.2.5.2 Facilitate updates on the appropriate secured configuration of information systems and the minimum baseline standards to address known vulnerabilities. 3.3 Security Monitoring and Reporting 3.3.1 Incident Management 3.3.1.1 Receive all reports of information security 'incidents', 'breaches', suspected 'incidents' or 'breaches' or potential control weaknesses from the Bureau's employees and management; and determine appropriate actions and remedies for these incidents. 3.3.1.2 Coordinate with Legal Group, Human Resource Development Service (HRDS), Information Systems Group, and all other concerned offices for the investigation of all security-related incidents. 3.3.1.3 Establish and administer a review process to address extenuating circumstances. 3.3.1.4 Establish and administer a plan to address policy and procedure violations. 3.3.1.5 Coordinate with external parties during the investigation and handling of security incidents. cADSCT 3.3.2 User Account Management 3.3.2.1 Coordinate with various information asset owners and system administrators in managing user access to Bureau's information systems 3.3.2.2 In coordination with the information asset owners, maintain a list of access rights for all application systems and the appropriate Bureau personnel who should be given the specific access rights 3.3.2.3 Establish links with HRDS and Personnel Division regarding creations, deletions, or movement in the Bureau's personnel and coordinate with information asset owners and system administrators in ensuring that user accounts and access rights are created, deleted or modified on time 3.3.2.4 Monitor creation and deletion of user accounts and access rights of users to specific information systems 3.3.2.5 Identify and monitor powerful accounts powerful accounts is one in which the incumbent can view confidential or private information, can alter sensitive information, or is depended upon for the continuity of information assets that are determined to be essential 3.3.3 Audit and Log Review 3.3.3.1 Identify critical information systems and activities based on the inventory of information assets and ensure that audit logs are enabled for critical information systems. DEcTIS 3.3.3.2 Regularly review audit logs and ensure that only authorized personnel have access to the Bureau's information assets. 3.3.4 Vulnerability Assessment 3.3.4.1 Facilitate performance of regular vulnerability assessment of application systems, critical servers and network devices and coordinate with system and network administrators to ensure that identified vulnerabilities are addressed. 3.3.5 Physical and Environmental Security 3.3.5.1 Provide and update security policies on the physical and environmental security of BIR for implementation and management of the Internal Investigation Division (IID) and General Services Division (GSD). 3.3.6 Security Solutions Monitoring 3.3.6.1 Monitor the implementation and management of security solutions such as: Firewall Antivirus cHaADC Intrusion Detection and Prevention System (IDPS) Security Information and Event Management (SIEM) Other security solutions deployed by the Bureau 3.3.7 Legal, Third Party, Regulatory and Audit Compliance 3.3.7.1 Coordinate monitoring of any new updates to legal, third party, regulatory or audit requirements and ensure that these security requirements are being met. 3.3.7.2 Conduct regular compliance reviews regarding legal, third party contracts, regulatory and audit requirements. 3.3.7.3 Monitor compliance of Bureau employees to information security policies, guidelines, standards and procedures. 3.3.7.4 Coordinate with the Personnel Adjudication Division and other parties authorized to perform audit or compliance activities over the Bureau's security environment. 3.3.8 Security Governance and Reporting 3.3.8.1 Define security performance metrics and institute regular security governance, and report to the ISSC SEHaTC The Performance Metrics may include the following: Statistics on reported incidents by category/severity. Unresolved incidents. Security programs/projects. Results of security monitoring activities. Vulnerability assessment e.g. , percentage of technology infrastructure in compliance with security baseline standards. Security updates. Review of access privileges ( e.g. , number of active accounts assigned to terminated employees). Percentage of attendance in information security awareness training. Number of IT/system projects where SMD is involved. 3.3.8.2 Conduct and/or facilitate periodic security briefings to ISSC on information security landscape e.g. , new technologies, attacks and laws and regulations TcSaHC Internal Use The information contained within is to be used solely by BIR employees, and should not be disclosed to others nor distributed outside of the Bureau without proper Management authorization.
Ask what this means for your situation
The assistant quotes the passage it relies on and links the source, so you can check every figure it gives you.