Policies and Guidelines in the Issuance and Revocation of Security Access to Identified Users
Revenue Memorandum Order No. 20-97 • Bureau of Internal Revenue (BIR) Issuances • Revenue Memorandum Orders • Apr 16, 1997
Full text
April 16, 1997 REVENUE MEMORANDUM ORDER NO. 20-97 SUBJECT : Policies and Guidelines in the Issuance and Revocation of Security Access to Identified Users TO : All Internal Revenue Officials and Employees Concerned I. OBJECTIVE : This Order is issued to establish the policies and procedures for the issuance and revocation of regular and special security access to identified users. II. POLICIES : In order to attain the above objective, the following policies are to be observed : A. Access to system functions in ITS shall be limited only to BIR personnel identified in the Security Access Matrices (SAMs) established by the Security Access Committee. However, these personnel shall be granted access only after they have completed the appropriate training on the application systems relevant to his her functional role. Should any employee previously granted access be made to assume a new functional role not related to the access previously granted, said access shall be disengaged and the employee shall be required to first undergo training on the application systems relevant to his/her new functional role, before new access is granted. B The level of access shall be dependent on the position/functional role of the employee as specified in the Security Access Matrices. However, special accesses which deviate from the prescribed accesses may, in meritorious cases, be authorized by the Commissioner, upon recommendation of the Deputy. Commissioner, Information Systems Group (DCIR, ISG). C. The use of special access shall only be for a specified duration and shall be revoked automatically after the lapse of the period. For justifiable reasons, the period may be extended upon written authority by the Deputy Commissioner, Information Systems Group. D. The Systems Administrators of the ISOS and the Revenue Data Centers shall monitor the use of access privileges based on audit trails and report any possible abuse or unauthorized entry into the ITS modules to the Assistant Commissioner, Information Systems Operation Service or Revenue Data Center Head respectively, who shall then relay the information to the Deputy Commissioner, Information Systems Group. The manner by which the use of access privileges will be monitored, the indicators established to detect possible abuses and unauthorized entries into the ITS modules, and the general contents of the audit trail report shall be contained in a separate Revenue Memorandum Order to be prepared by the Security and Access Committee at a later date. III. GUIDELINES AND PROCEDURES : Hereunder are the procedures to be followed in the issuance and revocation of security access to identified users: A. Head, Training Committee/HRDS 1. Prepare list showing the name, designation and place of assignment of personnel who have undergone appropriate training on application systems relevant to his/her functional role; 2. Forward above-mentioned list to the appropriate Systems Administrator for issuance of access codes to said personnel; 3. Notify appropriate Systems Administrator of any transfer, promotion, or movement of personnel which will involve assumption of a new functional role for the employee/s concerned. B. Head of Office (NO, RO, RDO, RDC) 1. Prepare request for special access (Annex "A" hereof) to specified personnel and forward the same to the Deputy Commissioner, Information Systems Group for approval. 2. Notify Systems Administrator of any re-assignment or movement of personnel within the Office which will involve assumption of a new functional role for the employee/s concerned. C. System Administrator 1. Receive from the Training Committee/HRDS list of personnel who have undergone appropriate training on application systems; 2. Check whether the personnel's position/functional role is in accordance with those specified in the Security Access Matrices; 3. Issue/activate the access codes to specified personnel covered by 1 and 2 above: cdll 4. Receive from the Deputy Commissioner, Information Systems Group approved requests for special access and issue the access code to personnel specified therein: 5. Prepare monthly Reports on Regular Access Code Issued (RACI) and Reports on Special Access Code Issued (SACI) (Annexes "B" & "C" hereof) and transmit to the Deputy Commissioner, Information Systems Group on or before the 5th day of each month. 6. Disengage, upon receipt of notice from the ACIR, HRDS or from a Head of Office as mentioned in A(3) and B(2) above, access privileges of employees who will be made to assume new functional roles for which they have not been previously trained. D. Deputy Commissioner, Information Systems Group 1. Receive from concerned Head of Office requests for Special Access (i.e. deviation from the Security Access Matrices; 2. Evaluate the merits of the request; 3. Send back to originating office disapproved request for special access; forward approved request to Systems Administrator for appropriate action, copy furnished the Head of Office. 4. Receive and evaluate monthly RACI and SACI reports. E. Upon approval of the Security Access Matrices prepared by the Security and Access Committee, amendments thereto as well as the implementation and maintenance thereof shall hereafter be the responsibility of the Information Systems Group (ISG). IV. REPEALING CLAUSE : This Order supersedes all revenue issuances and/or portions thereof inconsistent herewith. V. EFFECTIVITY : This Order shall take effect immediately. LIWAYWAY VINZONS-CHATO Commissioner of Internal Revenue
Ask what this means for your situation
The assistant quotes the passage it relies on and links the source, so you can check every figure it gives you.