Skip to main content

Revision to RMO 9-98 dated February 6, 199

Revenue Memorandum Order No. 33-01 • Bureau of Internal Revenue (BIR) Issuances • Revenue Memorandum Orders • Nov 29, 2001

Full text

November 29, 2001 REVENUE MEMORANDUM ORDER NO. 33-01 SUBJECT : Revision to RMO9-98 dated February 6, 1998 TO : All Internal Revenue Officials and Employees Concerned I. OBJECTIVES This Order is being issued to: 1. Provide new policies, guidelines and procedures for the granting and revocation of access to identified users and 2. Define new roles and responsibilities of personnel in the granting and revocation of user access. II. DEFINITION OF TERMS 1. Regular Access refers to the type of access granted to all ITS users based on their designation/functional role who have undergone the necessary training(s) 2. Special Access refers to the type of access that deviate from the access privileges defined in the Regular Access Matrix 3. Security and Access Matrix (SAM) document which shows user access privileges based on designation/office which is the basis of granting user access. 4. Generic Account refers to a standard account created for a group of users having the same access privileges to non-sensitive system functions to the Integrated Tax System (ITS) (e.g. purely inquiry access) 5. Account Swapping Activity refers to the activity wherein user account deemed least used/priority' is revoked to be able to create another user account where function is more of a priority to the office. 6. Account Revocation refers to the act of revoking/deleting a user account due to any of the following: retirement, resignation, dormant account, etc. 7. Dormant Account refers to user account that is inactive for one (1) month which shall be automatically deleted by the site System Administrator except for those who have officially filed their leave of absence. III. POLICIES AND PROCEDURES The following policies and procedures shall be observed in the granting and revocation of user access: 1. Regular and Special Access Regular Access: User/Requestor shall accomplish the Regular Access Request Form and forward it to Head of Office Head of Office shall approve the request and forward it to Security Management Division (SMD). Creation of new account will be ensured if Revocation of Access Request Form is also submitted for 'account swapping' to be done. Otherwise, new account will only be created once another user (from any office) requests for an account revocation. SMD shall validate and evaluate the Regular Access request together with the attached Revocation of Access request (if any). System Administrator shall grant, delete, suspend or reactivate access depending on the type of request. Special Access: User/Requestor shall accomplish the Special Access Request Form (SARF) and forward it to Head of Office Head of Office shall approve the request and forward it to Security Management Division (SMD) Additional user will be ensured if Revocation of Access Request Form is also submitted for 'account swapping' to be done. Otherwise, new account will only be created once another user (from any office) requests for an account revocation. SMD shall determine if an existing special role exists or if a new special role must be created by referring to the current matrix for special access. For new roles, prepares request for role definition to be forwarded to the Database Administrator. ACIR IPQS shall approve the request. System Administrator shall receive, log, grant, and delete user access as per request details. 2. Account Revocation Head of Office shall request for the deletion of account or suspension of access by accomplishing the Revocation of Access Request Form and forward the accomplished form to SMD. SMD shall validate and evaluate revocation of Access Request for deletion or suspension of user account(s). System Administrator shall revoke/delete user account based on details in request form. In cases of resignation and/or termination, the System Administrator shall ensure that account is deleted before signing clearance form of user to attest that access has been revoked. 3. Creation of Account Creation of account shall only be done by the National Office (NO) System Administrator. However, the Site System Administrator will be responsible for the modification to access privileges as well as account deletion of their respective users. 4. Issuance of Generic Accounts Generic Accounts are issued for designations whose access privileges are not granted towards sensitive data (e.g. Inquiry Accounts). However, the immediate Supervisor of users using generic accounts shall be held accountable for activities using said user accounts. Attached are the list of offices who have been granted Generic Accounts (please refer to Annex A). 5. Dormant Account The Site System Administrator even without prior notice shall automatically delete user logins that have become 'dormant' for one (1) month. This activity will result to the creation of user accounts for others who need to access ITS. However, exceptions are the user/s who officially filed their leave of absence. 6. Inventory of ITS Users All rolled out Revenue District Offices (RDOs) are required to submit their Inventory of Active ITS Users to SMD on a quarterly basis (every 3rd working day of January/April/July/Oct). This is being done to ensure that active users have been granted access privileges that are in line with their functional role (please refer to Annex B). IV. ROLES AND RESPONSIBILITIES 1. Security Management Division, Information Planning and Quality Service (SMD, IPQS) shall: Maintain the Security and Access Matrices , Evaluate and recommend approval for all Special, Regular and Revocation of Access requests and Resolve any issue pertaining to security and access 2. Head of Office shall: Endorse request for the granting and reactivation of regular/special access, Initiate the request for revocation of access and Provide the Security Management Division (SMD) with an Inventory of Active ITS Users on a quarterly basis. 3. System Administrator shall: Record and process all requests related to User Account Creation/Revocation, Prepare monthly reports on all Regular Access Codes, Special Access Codes or Report on Revoked User Access that were either issued or revoked and submit these to the Security Management Division of IPQS and Verify the training history of users requesting for regular access based on the training records and documents supplied by the Training Management Office (TMO). 4. Database Administrator shall: Create/modify/delete roles (as per SMD request) which are assigned by System Administrators to user accounts created. 5. Assistant Commissioner, Information Planning and Quality Service (ACIR, IPQS) shall: Approve request for Regular/Special Access. V. REPEALING CLAUSE RMO 9-98 and all other revenue issuances and/or portion(s) thereof that are inconsistent herewith are hereby revoked and/or amended accordingly. VI. EFFECTIVITY This Order shall take effect immediately. (SGD.) REN G. BAEZ Commissioner of Internal Revenue ATTACHMENT Revision to RMO 9-98 dated February 6, 1998 ANNEX A List of Generic Accounts ANNEX B Inventory of Active ITS Users

Ask what this means for your situation

The assistant quotes the passage it relies on and links the source, so you can check every figure it gives you.