Revisions to RMO No. 20-97 dated April 16, 1997
Revenue Memorandum Order No. 09-98 • Bureau of Internal Revenue (BIR) Issuances • Revenue Memorandum Orders • Feb 6, 1998
Full text
February 6, 1998 REVENUE MEMORANDUM ORDER NO. 09-98 SUBJECT : Revisions to RMO No. 20-97 dated April 16, 1997 TO : All Internal Revenue Officials and Employees Concerned I. OBJECTIVES This Order is issued to: 1. Provide additional policies, guidelines and procedures for the granting and revocation of access to identified users 2. Define additional roles and responsibilities of personnel in the granting and revocation of user access 3. Endorse the use of the new Security & Access Matrices II. COVERAGE This Order shall apply to all employees of the Bureau and shall cover all information relating to, pertaining to and generated from the Integrated Tax System (ITS). III. DEFINITION OF TERMS 1. Regular Access Access granted to all ITS users based on their designation/functional role 2. Special Access Access that deviate from the access prescribed in the Regular Access Matrix 3. Temporary Access Type of regular access granted to ITS users requiring access to other sites. 4. Security and Access Matrices Composed of the Regular Access Matrix, which documents all regular access granted to ITS users, and the Special Access Matrix, which documents all Special Access granted 5. Granting of Access Refers to the creation of an ITS user account and the issuance of access to ITS functions dependent on the job designation of a user 6. Personnel Movement Refers to scenarios wherein personnel undergo certain movements which require changes to be made to their access or user account. There are two main types of personnel movement, namely: a. Change in Location Refers to scenarios wherein personnel must transfer from one office location to another. Such transfers may be any of the following: Permanent Transfer Refers to scenarios wherein the user is permanently transferred to a new location. Temporary Transfer Refers to scenarios wherein a user is temporarily assigned to work in a new office location. After a certain period of time, the user returns to his/her original office. Special Assignments Refers to scenarios wherein a user works across two locations, his/her original office and the other office he/she is temporarily assigned to. b. Change in Designation Refers to any of the following: Replace Designation Refers to scenarios wherein the user is granted an entirely new job designation (i.e. promotion). Add Designation Refers to scenarios wherein other job designations are added on to a user's current job designation (i.e. multi-tasking/roles). 7. Heads of Office/Assistant Heads of Office The following are collectively referred to as Head/Assistant Head of Offices under this Order: Head of Office : a. Commissioner b. Deputy Commissioner c. Assistant Commissioner National Service Head d. Regional Director Regional Service Head e. Revenue District Officer District Office f. Division Chief Division, National Office Assistant Head of Office : a. Assistant Regional Director b. HREA c. Assistant RDC Head d. ARDO e. Assistant Division Chief IV. POLICIES The following policies shall be observed in the granting and revocation of user access: 1. Access to system functions in ITS shall be limited only to BIR personnel. The level of access to system functions shall be dependent on the designation/functional role of the employee which is identified in the Security and Access Matrices (SAMs) established by the Security and Access Committee. 2. Access to ITS system functions are generally classified as follows: a. Access to Inquire Function Inquire Access to information of general interest is granted to all personnel Inquire Access to information relevant to a functional role is granted to certain personnel on a need-to-know basis b. Access to Update Function Update Access for routine tasks is granted on a two-tiered level, specifically to the staff assigned to execute the task, and to the staff's immediate supervisor Update Access relevant to sensitive tasks and functions is granted to the Head of Office and Assistant Head of Office c. Access to Approve Function Approve Access is granted only to the Head of Office. This type of access may be granted to the Assistant Head of Office only if he/she is designated as the Acting Head of Office, thereby granting him/her special access with approve function d. Access to View Function View Access to reports/correspondence of general interest is granted to all personnel View Access to reports/correspondence relevant to a functional role is granted to certain personnel on a need-to-know basis e. Access to View/Print Function View/Print Access to sensitive reports and correspondence is granted to certain Heads of Office only if it is relevant to their tasks or functions. This type of access may be granted to the Assistant Head of Office only if he/she is designated as the Acting Head of Office, thereby granting him/her special access with view/print function View/Print Access to reports and correspondence not considered as sensitive is granted to Heads of Office and Assistant Heads of Office 3. Personnel shall be granted regular access only after they have completed the appropriate training relevant to their functional role/designation. When an employee is made to assume a new functional role not related to the regular access previously granted, the employee shall be required to first undergo training relevant to his/her new functional role before the new regular access is granted. 4. There are three (3) types of access that can be granted, namely: a. Regular Access b. Temporary Access c. Special Access 5. Regular access is: a. granted for the following scenarios: Mass roll-out When new users request for an ITS account When users require new access due to a permanent transfer b. deleted for the following scenarios: End of Service (i.e. resignation, retirement) When a user permanently transfers to another office location When a temporary regular access has expired (i.e. temporary assignment, special assignment) c. suspended for the following scenarios: Administrative Cases (i.e. suspension from work) Temporary Transfer refers only to the regular access of user's original office Extended Leave duration of leave must at least be one month d. reactivated for the following scenarios: When a user is no longer suspended from work When a user returns to his/her original office from a temporary assignment (refers to the regular access of user's original office) When a user returns from an extended leave 6. Temporary Access is granted for the following scenarios: a. When users require access due to a temporary transfer based on an RSO b. When users require temporary, additional regular access due to a special assignment 7. Special Access, which refers to any access that deviates from the prescribed policies on granting of regular accesses may, in meritorious cases, be authorized by the Commissioner, upon the recommendation of the Deputy Commissioner of the Information Systems Group (DCIR, ISG). The use of special access shall only be for a specified duration and shall be revoked after the lapse of the period. For justifiable reasons, the period may be extended upon written authority from the Deputy Commissioner, Information Systems Group. 8. Maintenance of ITS user account, which includes the creation/deletion of user accounts and granting/revoking of ITS access, shall be decentralized at the RDC level. 9. The System Administrators of the ISOS and the Revenue Data Centers (RDC) shall monitor the use of access privileges based on audit trails and report any possible abuse or unauthorized entry into the ITS modules to the Assistant Commissioner, Information Systems Operation Service or Revenue Data Center Head, respectively, who shall then relay the information to the Deputy Commissioner, Information Systems Group. The manner by which the access privileges are used will be monitored, the indicators established to detect possible abuses and unauthorized entries into the ITS modules, and the general contents of the audit trail report shall be contained in a separate Revenue Memorandum Order that will be prepared by the Security and Access Committee at a later date. V. ROLES & RESPONSIBILITIES 1. Security and Access Committee The Committee shall be composed of Revenue Officials and employees that have been identified in a Revenue Special Order duly approved by the Commissioner. The Committee shall be in-charge of assigning access to all users of ITS. The Committee shall convene on an as needed basis when there is a need to update the matrices. 2. Training Management Office (TMO) TMO shall initiate the granting of access to personnel assigned to sites that will be rolled out and have already completed their required training. After every training conduct, TMO shall be responsible for supplying the System Administrators with updated and complete user training history records. 3. Head Of Office The Heads of Offices shall approve the granting and reactivation of regular access and initiate the request for revocation of access. The Heads of Offices shall also endorse the granting of Special Access. 4. System Administrator The System Administrator shall record and process all requests related to User Access. The System Administrator shall prepare monthly reports on all Regular Access or Special Access Codes that were either issued or revoked. The System Administrator shall also be responsible for verifying the training history of users requesting for regular access based on the training records and documents supplied by the TMO. 5. Information Planning Quality Service (IPQS) IPQS shall maintain the Security and Access Matrices. IPQS shall be in charge of convening the Security and Access Committee when there is a need to update the matrices (i.e. when there is a system change or organizational change). IPQS shall also meet regularly to review all Regular and Special Access requests and to resolve any issues pertaining to security and access. IPQS may recommend changes to be made to the Security and Access Matrices. 6. Database Administrator The Database Administrator shall create/delete roles and maintain the security tables. 7. Assistant Commissioner , Information Planning & Quality Service (ACIR , IPQS) The Assistant Commissioner of IPQS shall be responsible for evaluating and recommending approval for Special Access requests. The ACIR of IPQS shall also be responsible for approving any updates to be made to the Security & Access matrices. 8. Deputy Commissioner , Information Systems Group (DCIR , ISG) The Deputy Commissioner of ISG shall be responsible for evaluating and approving all requests for Special Access. The DCIR shall also review all monthly reports pertaining to Security & Access. 9. Personnel Division The Personnel Division shall provide the System Administrators with regular updates on users who have been suspended or have ended their service. The Personnel Division shall also inform Information Planning & Quality Service (IPQS) if the Bureau is to undergo any changes in assignment(s) due to any organizational change. 10. Application Support and Maintenance Group (ASM) ASM shall inform IPQS if the ITS is to undergo any system changes. VI. REPEALING CLAUSE RMO 20-97 and all other revenue issuances and/or portion(s) thereof that are inconsistent herewith are hereby revoked and/or amended accordingly. VII. EFFECTIVITY This order shall take effect immediately. LIWAYWAY VINZONS-CHATO Commissioner of Internal Revenue
Ask what this means for your situation
The assistant quotes the passage it relies on and links the source, so you can check every figure it gives you.