Implementation of the Information Asset Classification Guidelines
Revenue Memorandum Order No. 012-14 • Bureau of Internal Revenue (BIR) Issuances • Revenue Memorandum Orders • Aug 13, 2013
Full text
August 13, 2013 REVENUE MEMORANDUM ORDER NO. 012-14 SUBJECT : Implementation of the Information Asset Classification Guidelines TO : All Internal Revenue Officials, Employees and Others Concerned As a public office tasked to perform collections from the taxpayers of the Philippines, the Bureau of Internal Revenue (BIR) recognizes the minimum requirements to secure its most valuable assets through classification. This approach is essential in maintaining the confidentiality, integrity and availability of assets entrusted to the Bureau. These guidelines are vital as services and information are offered in multiple channels. The Information Asset Classification Guidelines (Annex A) aims to establish a standard approach to classify information assets across all delivery mechanisms of on-line and physical 'over-the-counter' services for both electronically and non-electronically stored information. The guideline includes the security classification schema and the security classification process ( i.e., identification of information assets, owner identification, limiting duration of classification). It also established the basic security controls ( i.e., filing and marking, reclassification of information, storage) which serves as protection when handling and dealing with the Bureau's information assets. Henceforth, to ensure faithful compliance and awareness on the classification of assets owned by and entrusted to the Bureau, the revenue officials, employees and related third parties are enjoined to read the same and be familiar with its provisions. AISHcD This Order shall take effect immediately. (SGD.) KIM S. JACINTO-HENARES Commissioner of Internal Revenue ANNEX A Information Asset Classification Guidelines Revision History Version Date Author(s) Revision Notes 1.0 November 21, 2012 Security Management Aligned the classifications Division (SMD) based on legal provisions and provided general information asset controls applicable to the entire Bureau. __________ ________________ _________________ _____________________ __________ ________________ _________________ _____________________ __________ ________________ _________________ _____________________ __________ ________________ _________________ _____________________ __________ ________________ _________________ _____________________ __________ ________________ _________________ _____________________ __________ ________________ _________________ _____________________ __________ ________________ _________________ _____________________ Table of Contents 1 Purpose 2 Scope 3 The Security Classification Schema 3.1 Public Information 3.2 Non-Public Information 3.3 Security Classification Roles 4 Security Classification Process 4.1 Identification of Information Assets 4.2 Owner Identification 4.3 Determination of Security Classification 4.4 Limiting Duration of Classification 4.5 Application of Controls 4.6 Documentation of Classified Information Assets in Register 5 Security Controls 5.1 Filing and Markings 5.2 Reclassification of Information 5.3 Minimum Baseline Controls cAHIST 5.4 Non General Security Controls 6 Waiver Criteria 7 Compliance Measurement 8 Non-Compliance 9 Repealing Clause 10 Executive Sponsor 1 Purpose The Bureau of Internal Revenue Information Security Classification Guidelines (BIRISCG) sets the minimum requirements for information asset security classification. It also provides a standard process to allow units to evaluate their information assets and determine the appropriate level of security classification that must be applied, addressing the need for a consistent approach to dealing with the sensitivity and confidentiality of information assets across the BIR's network. By providing a standard approach to information asset security classification, the guideline facilitates improved interoperability and consistency within the BIR's network. The implementation of electronic service delivery has accelerated the need for a consistent approach to security classification, particularly as the BIR seeks to integrate its services and information. The BIRISCG also specifies the schema for security classification of information, and related controls that are in accordance with the National Internal Revenue Code (NIRC), BIR's Information Security Manual, Freedom of Information Act (FOI) and Data Privacy Act. 2 Scope This document provides a process and direction for determining the security classification of information assets. Other security functions that are not directly related to the security classification of information assets are outside the scope of this document. The document is intended to address the classification of information assets across all delivery mechanisms, including both on-line services and physical 'over-the-counter' services, and to apply to both electronically and non-electronically stored information. A single guideline for all delivery mechanisms is vital because services and information are increasingly offered on multiple channels. This document is intended for the use of employees within the Bureau of Internal Revenue. It will be in particular reference to: a. Information owners and users who are responsible for the classification and control of BIR's information assets b. Information asset custodians c. Any people who are designing BIR services such as business process specialists, service designers, and system architects cITAaD d. Business managers and service stakeholders e. Information security managers and auditors who may assess security of service f. Office Heads and employees who have responsibility for managing classified information assets over time g. ICT Heads and employees responsible for the supply and operation of information systems All users are required to read, understand and comply with the other Information Security policies, guidelines, standards, and procedures of the BIR. If any user does not fully understand anything in these documents, he should consult with his immediate Head of Office, or Human Resource Development Service, as applicable, who will contact the Security Management Division (SMD). The Chief of SMD should resolve any conflicts arising from this Guideline. 3 The Security Classification Schema This section outlines the schema to be used for security classification of information assets within BIR. Any information received or collected by, or on behalf of, the BIR through its office and contractors is official information. As it is a valuable official resource, official information: must be handled with due care and in accordance with authorized procedures, must be made available only to people who have a legitimate 'need-to-know' to fulfill their official duties or contractual responsibilities, and must only be released in accordance with the policies, legislative requirements and directives of the BIR and the courts. Official information held within the BIR typically fall into two broad categories: Official information intended for public use/consumption; and Official information which, because of the adverse consequences of unauthorized disclosure, requires appropriate controls to protect its confidentiality. The following diagram provides a representation of the various security classifications of official BIR Information. 3.1 Public Information Public information are information assets that has been explicitly authorized by the owner for public access, through the Internal Communications Division. This classification of information is directly and principally relating to the dissemination of information to the public and its various stakeholders. Such information asset must be clearly labeled as PUBLIC in order to distinguish it from INTERNAL USE information assets. CcTIAH Although confidentiality is not a requirement of this information asset, it is still necessary to maintain its integrity (accuracy and completeness) prior to its release and its availability upon release. Assuring the integrity and availability of a PUBLIC document comes with a cost. As such, an information asset should not be classified as PUBLIC until they are assessed and required to be made available. Some information assets that require disclosure to the public may have confidentiality requirements before the actual release. As such, the point of the asset's lifecycle, where it needs to be reclassified as PUBLIC, must also be determined and explicitly indicated. 3.2 Non-Public Information Information assets that are not classified as public can be divided into two categories: internal use information and security classified. 3.2.1 Internal Use information Information assets that are generally used in the conduct of the BIR's operations and do not need special security controls may remain unlabelled and left unclassified. An explicit authorization should be obtained from the information asset owner (process owner) before releasing INTERNAL USE information to the public, effectively re-classifying the asset into PUBLIC. 3.2.2 Security classified information Security classified information are assets that require a certain degree of confidentiality depending on its potential effect to the BIR. It should be protected with additional security controls as determined by its owner. This classification can be divided into the following: 3.2.2.1 RESTRICTED The most private and sensitive information asset which requires a substantial degree of protection as compromise could cause serious damage to the BIR and the nation, regulatory or contractual liability, severe damage to operations and loss of public trust and confidence and foreign relationship issues. This type of information classification should be used sparingly as its protection requires a substantial degree of investment. RESTRICTED information assets are usually within the executives (Chief Executive of the Philippines, Secretary of Department of Finance, Commissioner and Deputy Commissioners of Internal Revenue). 3.2.2.2 CONFIDENTIAL Information assets, whose compromise could cause moderate to limited damage to the BIR, should be classified as CONFIDENTIAL. This classification may be used in relation to the Group, Division or Section within the BIR that owns and requires the protection of the information asset. SaIACT Examples of CONFIDENTIAL classification may be used as follows: PERSONNEL-IN-CONFIDENCE: includes all BIR employee information where access would be restricted to the Personnel Division. Examples are employee evaluations, employee 201 files and grievances. AUDIT-IN-CONFIDENCE: includes all audit-related information that are not yet intended or re-classified as PUBLIC document. ISG-IN-CONFIDENCE: includes all ISG related information where access would be restricted to the ISG officials and other authorized staff. These may include, but may not be limited to, Windows Baseline Security Standards, UNIX Baseline Security Standards and Current Firewall Rules. 3.3 Security Classification Roles 3.3.1 Information Asset Owner All information gathered and used by the government agencies are owned by the Republic of the Philippines. This responsibility is passed on to the agencies of the government. For the Bureau of Internal Revenue, the ownership is passed on by the Chief Executive to the Commissioner of Internal Revenue (CIR). The CIR therefore, has the direct authority and accountability over the information asset. The CIR has the responsibility to protect the information asset by ensuring that proper controls are in place. In order to ensure that proper attention is given to information assets, the Commissioner may further delegate the ownership to the officials of each group and/or division. Information asset ownership should generally be assigned to a BIR Item and not to a natural person to ensure continuity of responsibilities. The roles and responsibilities of an Information Asset Owner are shown as follows: Maintain an inventory of their information assets. Perform risk analysis to determine, identify and document the classification of the information assets owned. Inform the Security Management Division (SMD) of all the information assets identified as confidential. Ensure appropriate controls are applied based on the classification of an information asset. More stringent controls for each information asset may be implemented by the owner. Authorize access privileges to those needing access to their data. Review annually the privileges authorized. Determine the retention period of an information asset. AECIaD 3.3.2 Information Asset Custodian Information asset custodian has the physical or logical possession of the information asset. They are responsible for the implementation and maintenance of the security controls set by the information asset owner. This is to ensure that confidentiality, integrity and availability criterion is met throughout the information asset's lifecycle. The roles and responsibilities of an information asset custodian are as follows: Implementation of physical and/or logical access control systems to protect the information assets. Provide and administer general controls such as back-up and recovery systems consistent with the BIR's Information Security Policy and applicable baseline standards. Custodians are responsible in establishing, monitoring and operating information systems, containing the information assets of the BIR, consistent with BIR information security policy. This should be in consultation with the information asset owners. Custodians should not change or alter the information asset in their custody as well as the agreed security controls unless they have received an explicit authorization from the information asset owner. 3.3.3 Information Asset User Information Asset User is an individual with explicit authorization to use the information asset. Information Asset User is responsible for implementing controls and executing due care in utilizing information assets. The following are the roles and responsibilities of the information asset user: Users should use information only for the purposes specifically approved by the Information Asset Owner. Users should comply with all security measures defined by the Information Asset Owner, implemented by the Custodian, and/or defined by the SMD. Users should refrain from disclosing information in their possession (unless it has been designated as Public) without first obtaining permission from the Information Asset Owner. Users should report all situations, where they believe an information security vulnerability or violation may exist, to the SMD. Users should accomplish the Acceptable Use Policy (attachment A in ICT Security Policy), and user acknowledgment should be renewed annually. HASDcC 4 Security Classification Process 4.1 Identification of Information Assets Information assets are data, information or material generated, gathered, compiled, stored or utilized by the Bureau in the conduct of its operations. These include, but are not limited to, taxpayer information, electronic messages, documents, policies, guidelines and procedures. 4.2 Owner Identification Each group is responsible for ensuring that information assets are securely classified by the information asset owner and is implemented and maintained by the information asset custodian. Information assets shall be classified by the information asset owner or delegate at the earliest possible opportunity and as soon as the information asset owner is aware of the sensitivity of the information asset. The Information Asset custodian shall ensure that proper care is regarded in handling information assets assigned to them. All assets shall be included in the Bureau's inventory maintained by the Information Asset Owners and shall have a designated owner and when necessary, a custodian. SMD should be given a copy and keep the complete inventory. 4.3 Determination of Security Classification Security classification of an asset should be based on legal provisions and its impact to the Bureau. 4.3.1 Benchmarking to Legal Provision Relevant laws, regulations, issuances and other references should be considered in determining the classification. The following may serve as basis of classifying the information assets of the Bureau. a. National Internal Revenue Code b. Data Privacy Act of 2011 c. Freedom of Information Act of 2012 (for approval) d. BIR existing Information Security Policy Additional relevant laws, regulations, issuances or any other reference that eventually becomes applicable should be considered in classifying assets. Below are legal provisions BIR may use to classify assets based on relevant laws, regulations and issuances. Legal Provision Classification Basis The information directly relates to national security or internal Restricted FOI and external defense of the state The information pertains to foreign affairs of the state. Revelation Restricted FOI of which shall unduly weaken the negotiating position or the diplomatic relations of the Philippines with other states. The information contains records of minutes and advice given Restricted FOI during decision making or policy formulation invoked by the Chief Executive to be privileged by reason of the sensitivity of the subject matter. If information pertains to internal/external defense, law Confidential FOI enforcement and border control, when disclosure thereof, would: compromise or interfere with legitimate military or law enforcement operation deprive a person of a right to fair trial or an impartial adjudication disclosure of identity of confidential source, including governments or foreign agencies where information was given on a confidential basis disclose techniques and procedures for law enforcement investigations or prosecutions endanger the life of any individual Drafts of orders, resolutions, decisions, memoranda or audit Confidential FOI reports by any executive, administrative, regulatory, constitutional, judicial or quasi-judicial body in the exercise of their regulatory, audit and adjudicatory function. Information obtained by House of Congress in executive session Confidential FOI If it is personal information of a natural person Confidential FOI Information contains trade secrets and commercial or financial Confidential FOI information obtained from a natural or juridical person The information is classified as privileged information in legal Confidential FOI proceedings. The information requested is exempted by law or the Constitution, Confidential FOI in addition to those provided in this section. Sensitive Personal Information may be: Confidential Data Privacy 1. About an individual race, ethnic origin, color and religious, Act philosophical or political affiliations; 2. About an individual's health, genetic or sexual life of a person, or to any judicial proceeding for any offense committed or alleged to have been committed by such person, the disposal of such proceedings, or the sentence of any court in such proceedings; 3. Issued by Philippine government agencies peculiar to an individual which includes, but not limited to, Social Security numbers, previous or current health records, licenses or its denials, suspension or revocation, and tax returns; and 4. Specifically established by an executive order or an act of Congress to be kept classified. Rules of procedures and description of available forms Public FOI Instructions as to the scope and contents of all papers, reports Public FOI and examinations Substantive rules of general applicability adopted as authorized Public FOI by law Statements of general policy or interpretations of general Public FOI applicability formulated and adopted by the Bureau and amendments thereof Public Interest Documents Public FOI Annual Budget of the BIR Itemized Monthly collections and disbursement Summary of income and expenditures Component of IRA (Internal Revenue Allotments) Utilization Annual Procurement Plan and Procurement List Items to Bid Bid results Abstract of Bids Procurement contracts Construction or concession agreements Public funding extended to any private entity Bilateral or multilateral agreements and treaties in trade, economic partnership, investments, cooperation and similar binding commitments Statement of Assets and Liabilities of BIR officials 4.3.2 Impact Assessment If there are no laws, regulations, issuances and other references that could identify the classification of information assets, impact of it being compromised should be considered. An impact assessment matrix may be used as a guide to evaluate the classification of information assets. Below is an impact assessment matrix which may be used by the Bureau. HaIATC Impact Criteria Minor/Negligible Moderate Major Distress caused to any No impact Short term Damage Long term party Damage Damage to a party's No impact Short term Damage Long term reputation Damage Public order No impact Can cause slight Can cause confusion chaos Financial Loss to agency No impact Minor, Less than 2% > 2% of /service provider of monthly budget. monthly budget. Threat to BIR's systems or No impact Can cause slight Can cause capacity to operate efficiency issues major efficiency issues or total stoppage of operation Impact on development No impact Can cause slight Can cause or operation of major confusion chaos or government policy failure to operate policy Potential Information Consider for Internal Use Confidential Asset Classification Internal Use/Public 4.4 Limiting Duration of Classification Asset classification may vary at a point in time. Duration of classification may be determined up to a specific date or event. An event may trigger an increase or decrease in sensitivity or change in target audience. For instance, a revenue memorandum in its draft state shall be considered CONFIDENTIAL and be classified as PUBLIC on Commissioner's approval. Protection applied to information assets may change when classified or declassified. 4.5 Application of Controls Pertinent controls shall be applied to ensure that appropriate protection is given to information assets in accordance with the determined security classification. Confidentiality, integrity and availability of information shall be considered in applying specific controls on information assets. These controls are outlined in Section 5 of this document. 4.6 Documentation of Classified Information Assets in Register BIR should maintain an information asset inventory that records all information assets of the Bureau with corresponding security classification. Information asset inventory shall be maintained in a centralized location and should cover all information assets of the BIR, readily accessible to BIR Management. At a minimum, an information asset register should include: a. Unique identifier of asset (unique control number) b. Description of information asset c. Location of information asset d. Information asset owner CIaDTE e. Security classification f. Date of security classification and name of who approved the classification g. Reason for the security classification The following may be considered in maintaining an information asset register: a. Date to review security classification b. Users and usage of information c. Number of copies in circulation d. Disposal details where information has been disposed In the event that information asset is identified as confidential, the Information Asset Owner should inform SMD and make the necessary updates in the information asset inventory. The SMD may apply necessary controls. 5 Security Controls 5.1 Filing and Markings Information assets are distinguished among information classification through their respective filing and markings. Appropriate protective filing and markings are the following: Public An archive of public documents accessible to the public must be maintained. Information must be marked "Approved for Public Release". Internal Use Information must be marked "Internal Use Information". Filing must be in accord with normal records management practices. Security Classified Information must be marked "Confidential". Additional markings should be labelled to indicate its sub classification such as "(Office)-in Confidence" or "Restricted". Sub-classified information assets must be filed separately and a distinctive file must be maintained accordingly. 5.2 Reclassification of Information Information assets may change its state of criticality and sensitivity. Therefore, information assets may be reclassified at a point in time or when necessary. For instance, public information may be held as confidential prior to its release. Any reclassification must be done by the information asset owner. Reclassification may be considered in the following scenarios: aDHCcE A legal, legislative, regulatory, policy or any other provision requires reclassification of the information asset. There is a change in the state of information ( e.g., criticality, sensitivity). Significant changes occurred affected the impact of information assets ( e.g., change of government, change strategic priorities). User believes that there is a need to reclassify the information asset. User must advise the information asset owner who may consider the reclassification. In the event that the information asset changes and become confidential, the Information Asset Owner should inform the SMD and make the necessary updates in the information asset inventory. 5.3 Minimum Baseline Controls Appropriate controls must be established to ensure that appropriate protection is applied to information assets. Controls are applied according to the determined asset classification. 5.3.1 Public Information a. Available to the public b. Information accessed by the public should not be modifiable. Modifications and updates is limited to information asset owner c. Contents to be published are authorized by the Internal Communications Division 5.3.2 Internal Use Information a. Available within the Bureau b. Available to any employee or third party ( e.g., vendor, consultants, other government agencies, AABs, OJTs) upon approval from the immediate head or, if appropriate agreements are in place, an employee who can disclose or share this information with the extended enterprise c. Default privilege is read only 5.3.3 Security classified information 5.3.3.1 Restricted a. Access is limited to those approved by the Commissioner b. Information is not disclosed to extended enterprises c. Modifications and updates are limited to the information asset owner cSTDIC d. Electronic documents are protected with a strong password 5.3.3.2 Confidential a. Access is given to a limited audience within the Bureau b. Information is disclosed to an extended enterprise with appropriate agreements in place c. Modifications and updates are limited to the information asset owner d. Electronic documents are protected with a strong password 5.4 Non General Security Controls 5.4.1 Discussing security classified information Discussions of security classified information should be taken with care to ensure that leakage is prevented from people without a need-to-know. The following shall be observed in conducting meetings involving security classified information: a. Meetings should occur behind closed doors ensuring area is secured b. Roster of attendees should be approved by the information asset owner c. Meeting materials should have classification markings d. Information written on whiteboards or stored on equipment should be removed prior to vacating the meeting room 5.4.2 Voice conferences and presentations Data or voice transmission of restricted information on voice conferences and presentations are not allowed unless both ends are provided with encryption. Cordless or mobile phones are not allowed to be used to discuss restricted information unless allowed and approved by the information asset owner. 5.4.3 Copying classified information Copying of classified information may be prohibited by the information asset owner. Copies of the information should be numbered and labelled per information asset classification. 5.4.4 Storage of classified information Physical documents should be stored and locked in secure locations. Also, clear desk policy should be practiced at all times. TaDSCA For electronic documents, logical access should be restricted and information should be stored in a common directory accessible to persons with a need-to-know. 5.4.5 Electronic authentication and access Access to information should be validated through electronic authentication. Information should be protected, at a minimum, with a strong password in compliance with Password and Login Control Guidelines. Additional authentication mechanisms that may be implemented are the following: e. Tokens f. Biometrics g. Access badge h. Radio-frequency Identification (RFID) 5.4.6 Audit logs Audit logs should be enabled in the system. Monitoring of audit logs should be conducted regularly. 5.4.7 Digital transmission Data Transmission Information may be passed over appropriately classified internal networks. Data should be encrypted when sent to other agencies or any organizations outside the BIR authorized to receive the information. Email Email messages containing classified information should be sent to recipients with a need-to-know and encrypted with digital signature. Also, email attachments should be password-protected. Fax The following controls should be performed when sending or receiving facsimile: a. Facsimile received should be attended b. Receipt or non-receipt of document should be advised c. Destination number should be verified d. Fax to and from a physically secure location DISTcH e. Transmission to third parties should be approved by the information asset owner 5.4.8 Physical transmission Within the Bureau Documents should be sealed in a single opaque envelope indicating its classification. It should not be left unattended on recipient's desk. There must be a confirmation from recipient upon delivery of authorized BIR personnel/messenger. Outside the Bureau Document should be sealed in double envelope. Sealed inner envelope should indicate classification placed within a single opaque outer envelope that does not indicate classification. It should not be left unattended on recipient's desk. Documents should be sent via registered mail or by authorized BIR personnel/messenger with confirmation of receipt. 5.4.9 Archiving and Disposal Electronic Documents a. Information retained based on defined retention period of information asset owner b. Media should be destroyed and sanitized (delete files/demagnetized media) c. Immediately delete after a defined retention period Physical Documents d. Information retained based on defined retention period of information asset owner e. Shred or erase all documents and files or place in secure receptacle for future shredding 6 Waiver Criteria This document is intended to address information security requirements. Requested waivers must be formally submitted to the SMD, including justification and benefits attributed to the waiver, and must be approved by the DCIR-ISG. The waiver shall only be used in exceptional situations and only after performing risk analysis examining the implications of noncompliance. The waiver shall be granted for a specific period of time, subject to a maximum period of 1 year. At the completion thereof, the need for another or extended waiver must be reassessed and re-approved, if necessary. The terms of the waiver shall be limited to three (3) consecutive terms only. The waiver must be monitored by SMD to ensure its compliance with the specified period of time and exception. ADSTCa 7 Compliance Measurement Compliance with the Information Asset Classification Guidelines is mandatory. The Head of Office shall ensure compliance within their areas of responsibility. The initial investigation shall be conducted by the SMD. Violations of the policies, standards, guidelines and procedures of the Bureau shall result in corrective action by concerned offices. The assigned user and immediate superior shall be held liable, in accordance to Section 12-B of the BIR Revised Code of Conduct, should there be any damage caused to BIR-provided computers, network and equipment caused by misuse, abuse, negligence and other unauthorized activity. 8 Non-Compliance Non-compliance with the information security policies, standards, guidelines and procedures shall subject the offender to immediate disciplinary and/or legal actions. 9 Repealing Clause All memoranda, guidelines and/or related issuance inconsistent with this document are hereby repealed, revised, amended and/or superseded accordingly. Unaffected portions thereof shall remain in full force and effect. 10 Document Management and Maintenance SMD and ITPSD are responsible for the management, maintenance and accuracy of the guidelines. Any questions regarding the guidelines should be directed to the SMD. Internal Use The information contained within is to be used solely by BIR employees, and should not be disclosed to others nor distributed outside of the Bureau without proper Management authorization. <ftp://ftp.bir.gov.ph/webadmin1/pdf/83434RMO%20No%2012-2014.pdf> last visited March 3, 2014.
Ask what this means for your situation
The assistant quotes the passage it relies on and links the source, so you can check every figure it gives you.