Skip to main content

BIR Incident and Data Breach Response Plan

Revenue Memorandum Order No. 058-19 • Bureau of Internal Revenue (BIR) Issuances • Revenue Memorandum Orders • Nov 20, 2019

Full text

November 20, 2019 REVENUE MEMORANDUM ORDER NO. 058-19 SUBJECT : BIR Incident and Data Breach Response Plan TO : All BIR Officials, Employees and Others Concerned In fulfilling its mandate, the Bureau of Internal Revenue collects, processes, and stores Personally Identifiable Information (PII) about taxpayers, employees, and other stakeholders. Under Republic Act No. 10173, known as the Data Privacy Act of 2012, all sensitive personal information maintained by the government, its agencies and instrumentalities shall be secured and safeguarded against any accidental loss or unlawful destruction, alteration, and disclosure, as well as against any other unlawful processing. AaCTcI The importance of responding appropriately to incident or confirmed data breach is significant to secure BIR assets and data. Thus, the development of the BIR Incident and Data Breach Response Plan to provide guidance to all BIR officials and employees. This Order shall take effect immediately. (SGD.) CAESAR R. DULAY Commissioner of Internal Revenue ATTACHMENT Incident and Data Breach Response Plan Version 1.0 (November 20, 2019) EXECUTIVE SUMMARY The Bureau of Internal Revenue (BIR) upholds the protection of Personally Identifiable Information (PII) which the BIR collects, process, use, transmit and store. The protection of said PII is everyone's responsibility. Thus the creation of this Incident and Data Breach Response Plan ('Plan'),to provide guidance to the BIR officials and employees on how to respond to incident and confirmed data breaches involving PII. In addition, this Plan identifies the members of the Incident and Data Breach Response Team (IDBR Team) for National Office, Regional and District Offices. I. INTRODUCTION In fulfilling its mandate, the Bureau of Internal Revenue collects and maintains PII about taxpayers, employees, and other stakeholders. Under the Data Privacy Act of 2012, the BIR is responsible for protecting the PII from loss, theft or compromise ('breach'). Failure to adequately protect the PII, as well as to report a data breach in a timely manner, could cause significant effect to the reputation or harm to affected taxpayers, employees and other affected stakeholders and BIR as well. The importance of knowing how to respond to incident or confirmed data breach or by just being proactive in securing the BIR's critical systems, data, documents, and other important resources is needed to protect the confidentiality, integrity and availability of valuable BIR assets and information. An effective and expeditious response to an incident or breach is critical to minimize any harm to potentially affected parties and to maintain the public's trust in the ability of BIR to safeguard these valuable resources. 1.1 Purpose The BIR is committed to protect all its assets. To achieve this goal and to minimize the risk of loss, theft, or compromise of taxpayers or employee-related information, appropriate systems, operating procedures, and policies are in effect and are regularly reviewed and updated. The purpose of this Incident and Breach Response Plan is to provide a well-defined and organized approach for handling actual or potential threats to BIR's assets and information maintained electronically (on computers, servers and/or networks),or maintained physically in any other format: Recognize and respond to an incident Assess the situation quickly and effectively Notify the appropriate individuals and organizations about the incident Organize the team's response activities EcTCAD This Plan is intended to be a living document that may be amended in order to improve or clarify response processes. 1.2 Defining Incident and Data Breach A security incident is defined by the National Privacy Commission, as any event or occurrence that affects or tends to affect data protection, or may compromise the availability, integrity, and confidentiality of personal data. A data breach happens when a security incident leads to the accidental or unlawful destruction, loss, alteration, unauthorized acquisition, exposure, disclosure, use, or access to personal data transmitted, stored, or otherwise processed. II. INCIDENT AND DATA BREACH PREPARATION 2.1 The first step in the incident and data breach response life cycle is preparation. The Heads of Offices shall identify important assets/resources in their work units. A list of assets/resources such as applications, systems, databases, licenses, networks, important documents and other key assets shall be prepared and updated regularly. Periodic risk assessments of these are necessary to identify and protect critical BIR assets. 2.2 The BIR shall develop training module/s on how to identify and respond to data breach, including the internal process for reporting breach. Training on how to identify, report, and respond to a breach shall be part of the BIR mandatory annual training program (in coordination with Training Delivery Division).The training shall emphasize the individual's obligation to report incident or suspected breach, involving information in any medium or form, including paper, electronic, or verbal. Role-based and specialized training shall be made available for Service Desk Analysts and those involved in the breach response process that they understand their roles and responsibilities. III. INCIDENT AND DATA BREACH IDENTIFICATION/DETECTION 3.1 Some instances of incidents/data breaches: 3.1.1 Inappropriate use, loss or deletion of stored data access or disclosure of employees' information, or inappropriate modification, deletion or destruction of employees' information; 3.1.2 Loss or theft of computer hardware including laptops, handheld devices, portable media/removable storage containing confidential taxpayer or individually identifiable information; 3.1.3 Loss or compromise of physical equipment that stores employees',taxpayers' and other stakeholders' information; 3.1.4 Computer/Network Intrusions, Data Losses, or other Compromises, including unauthorized access, viewing, copying, forwarding, or removal of electronically stored data; or any other incidents; 3.1.5 Inadvertent or erroneous data transmission incidents, such as e-mail releases and physical and electronic data transmission. 3.2 Upon discovery of an incident or potential incident/data breach, log the issue in the BIR Service Desk. In general, the following information will be collected: 3.2.1 name and contact information of the reporting individual 3.2.2 location of the incident 3.2.3 circumstances of the incident to include involved parties 3.3 The BIR Service Desk personnel shall analyze the reported issue/incident. If there is potential breach, escalate issue to the IDBRT (National/Regional level).Otherwise, the reported incident shall go through the regular incident/issue reporting process. HSAcaE Please be guided by the Incident/Data Breach Response Process flow: IV. INCIDENT AND DATA BREACH RESPONSE TEAM COMPOSITION AND FUNCTIONS When notified of the incident, IDBRT Team shall convene to respond to incidents and breaches. The BIR Incident and Data Breach Response Team (IDBRT) is tasked to coordinate and align key resources and team members during security incident and breach to minimize impact and restore operations as quickly as possible. This includes investigation and analysis, recommend appropriate course of action, communications and documentation. 4.1 The IDBRT for National Office The Team is composed of the following BIR officials and shall be under the designated Data Protection Officer (DPO) of the BIR. (See Annex A RSO No. 278-2019): Management Lead - Assistant Commissioner, Information Systems Development & Operations Service - Chief of Staff, Office of the Commissioner Members: Office of the Commissioner - Head Revenue Executive Assistant (HREA), Project Management and Implementation Service - HREA, LT Compliance and Programs Group - HREA, Planning & Management Service Technical - HREA, Information Systems Project Management Service - HREA, Information Systems Development & Operations Service - Revenue Data Center Head, National Office Data Center Chief, Network Management and Technical Support Division - Chief, Security Management Division Resource Management - HREA, Finance Service HREA, Administrative Service HREA, Human Resource Development Service Communications - Chief, Public Information and Education Division Chief, Internal Communications Division Operations - HREA, Assessment Service HREA, Collection Service HREA, Client Support Service Chief of Staff, Operations Group Security/Legal - HREA, Legal Service - HREA, Internal Affairs Service - HREA, Enforcement and Advocacy Service - Chief, Internal Investigation Division - Chief, Personnel Adjudication Division 4.2 The IDBRT for BIR Regional Offices The Team is composed of the following BIR officials and shall be under the designated Compliance Officer on Privacy (COP).(See Annex B RSO No. 354-2019). Lead - Assistant Regional Director Members: - Chief, Legal Division - Chief, Regional Investigation Division - Chief, Finance Division - Chief, Assessment Division - Chief, Document Processing Division - Chief, Administrative and Human Resource Management Division - Chief, Collection Division - Concerned Revenue Data Center Head - Concerned Assistant Revenue District Officer 4.3 The IDBRT Functions: 4.3.1 CONTAINMENT 4.3.1.1 Conduct initial assessment of the incident or breach in order to ascertain the nature and extent thereof preliminary analysis of the facts and assessment of the situation to determine the nature and scope of the incident involve the concerned team/Process Owner in the initial and continuing incident and data breach response process 4.3.1.2 Execute measures to mitigate the adverse effects of the incident or breach ways to contain activities, stop additional information from being lost or disclosed, or to reduce the number of persons to whom information may reach depending on the nature of incident, scope, severity, magnitude, potential impact and risk to the organization, such as: o Securing or disconnecting affected systems o Securing affected records or documentation o Halting affected business processes o Pausing any processes that may rely on exposed information or that may have given rise to the incident (as necessary to prevent further use/exposure/etc.) o Disconnecting third party connections, reconfiguring firewalls, changing computer access codes o Modifying physical access controls 4.3.2 INVESTIGATE 4.3.2.1 Conduct of thorough investigation and documentation of the incident response. Thorough investigation and documentation needs to be timely, accurate, and professional to insure the most accurate information and to comply with required timeframes. HESIcT 4.3.3 RESOLUTION/RECOVERY 4.3.3.1 Develop procedure for recovery and restoration of personal data take steps to attempt to recover lost/stolen/inappropriately disclosed information based on areas of responsibility or collaboratively 4.3.3.2 As appropriate, revise written policies and procedures that may be deficient. 4.3.3.3 Assess informal/unwritten processes and practices and make changes to correct or improve them. 4.3.3.4 Follow human resources policies and disciplinary action guidelines to determine need for disciplinary action on any BIR employee involved in the incident If the incident occurred at/by a third party, determine if a legal contract/agreement exist and recommend review of the contract terms and determine the next course of action. If an internal user (authorized or unauthorized employee, contractor, consultant, etc.) was responsible for the breach, coordinate with the Internal Investigation Division for disciplinary action. 4.3.3.5 Determine the need for additional staff training. 4.3.3.6 Determine the need for increased security (physical or electronic) measures 4.3.4 REPORTING The IDBR Team shall report the incident to the DPO, who shall in turn, report to the National Privacy Commission Recommend to the DPO/COP/Regional Director the need to notify the NPC and the data subjects affected by the incident or breach within the period prescribed by law. o notify all BIR employees of the incident or affected employees/working units only o how employees will be notified (email, staff meetings, etc.) o need for external communications, i.e. ,press conference or press release, if necessary o need to post information regarding the incident to the BIR website Determine who will represent BIR publicly 4.3.4.2 n Comply with reporting requirements and protocols and ensure that proper offices/authorities in the BIR National Office are informed Submit detailed documentation of incident or breach encountered, and annual report, to the DPO/COP Document all details of the incident and actions taken regarding an incident to include all steps taken in accordance with this plan. Preserve all system and audit logs and evidence for potential criminal investigations. 4.3.5 CLOSING THE INCIDENT CASE 4.3.5.1 Before an incident case file can be closed, BIR-IDBR Team must have met the goals of incident response: Investigate the incident internally; caITAC Mitigate potential harm to affected parties; Minimize adverse impact to BIR in an ethically and legally appropriate manner, to include minimizing reduction in operations, reputational harm, and/or financial harm; Appropriately communicate the incident or data loss to the designated DPO Provide guidance or assistance in the development of specific corrective actions (including disciplinary actions when appropriate) 4.3.5.2 Update the BIR Service Desk 4.3.5.3 All documentation related to incidents/breaches must be maintained and kept confidential. File closed incident case to be retained according to BIR document retention policy Maintain a registry of all incidents/data breaches 4.3.6 POST-REVIEW 4.3.6.1 Conduct post-incident reviews, training and education, and provide internal communications in order to minimize potential future incidents Review of initial containment activities o Communication regarding containment activities taken thus far o Assessing risks to information and systems o Determination of additional containment measures o Determination of the need to inform law enforcement Communications/Public Relations Planning o Assess how the incident and the response affected BIR's reputation and public image. 4.3.6.2 Monitor and ensure closure of the reported incident/data breach Please refer to specific roles and responsibilities defined in the attached Revenue Special Order (Annexes A & B). 4.4 The IDBRT shall be guided by the severity level in prioritizing reported incidents: Severity Level Criticality Level Definition Indicators Severity Level 1 (Urgent/Critical) Incidents with "substantial security context" affecting numerous BIR assets or representing a highly significant threat to the availability or integrity of the BIR environment. Urgent/critical incidents pose an immediate threat to the BIR environment. Potentially affects large number of individuals (100 or more) or high-profile individuals; Is anticipated to create an overwhelming increase of phone or email traffic; inability or significantly reduced ability to fulfill core business functions; significant damages or costs associated with incident/breach; Has the potential to generate extensive media attention, Congressional inquiries, or other negative exposure requiring high-level coordinated response Data Loss Unauthorized changes to data/information systems Unauthorized release of/or disclosure of information to include Personally Identifiable Information and other sensitive data Data exfiltration Network intrusion Malicious Code (widespread) installation or attempted installation of software with the intent of infecting an operating system or application With major impact to BIR operation Severity Level 2 (High) Incidents with "substantial security context" affecting numerous BIR assets or representing a highly significant threat to the availability or integrity of the BIR environment. Malicious Code Sharing/stealing of passwords or other authentication token. High level incidents often pose an immediate threat to the BIR environment. Potentially affects limited or few number of individuals. Changes to privilege use settings on stand-alone or networked equipment including network profiles, local user or device configuration files that have not been approved by proper office. The operation is severely degraded or significant aspects of the end user's operations are being negatively impacted Severity Level 3 (Medium) Incidents affecting few BIR assets or a single asset with a notable security context that may affect the availability or integrity of the environment. Minor and non-emergency problems Suspicious system behavior or failure. Unknown network activities affecting/degrading network performance with increased network bandwidth usage and decreased response time, using excessive CPU, increase suspicious network requests or increased IDPS alerts leading to application crashes With minor impact to BIR operation Severity Level 4 (Low) An incident which is minor, non-disruptive operational error or function, or enhancement requests for new functionality or a change in existing functionality with little immediate operational impact. Any violation of information security policy Unconfirmed incidents that are potentially malicious or anomalous activity deemed by the reporting analyst to warrant further review V. AFTER HOURS EMERGENCIES Employees are expected to report incidents/data breach through the BIR Service Desk, but when suspected incident is severe enough to warrant an immediate urgent response, you may contact the following: OFFICIALS CONTACT NUMBER/S 1. Data Privacy Officer - Deputy Commissioner for Information Systems Group 2. Compliance Officer on Privacy - Chief of Staff Office of the Commissioner - Regional Director - Revenue District Officer 3. Service Delivery Manager - Head Revenue Executive Assistant for Information Systems Development and Operations Service 4. BIR-IDBR Team Lead/Co-Lead - Assistant Commissioner for Information Systems Development and Operations Service 5. Immediate Supervisor n Note from the Publisher: Copied verbatim from the official document. Irregular numerical sequence.

Ask what this means for your situation

The assistant quotes the passage it relies on and links the source, so you can check every figure it gives you.