Security Requirements in the Technical Computing Environment
Revenue Memorandum Order No. 44-98 • Bureau of Internal Revenue (BIR) Issuances • Revenue Memorandum Orders • May 22, 1998
Full text
May 22, 1998 REVENUE MEMORANDUM ORDER NO. 44-98 SUBJECT : Security Requirements in the Technical Computing Environment TO : All Assistant Commissioners, Regional Directors, National Division Chiefs, Regional Division Chiefs, Revenue District Officers and Others Concerned I. OBJECTIVES This Order is being issued to: 1. Develop personnel awareness on the security requirements of the Bureau relative to the technical computing environment and the consequences involved when said requirements are not met. 2. Set the guidelines in reporting and evaluating cases of security violations. 3. Set the policies for the imposition of sanctions for such cases. 4. Prescribe areas from which security violation(s) may arise. II. DEFINITION OF TERMS In order to have a common understanding of the provisions of this Order, the following are hereby defined: Security Breach/Violation refers to non-compliance to set policies and guidelines as embodied in the Physical Security Manual (see Annex A) Gravity of Offense refers to the seriousness of an offense which is classified into Grave Offense, Less Grave and Light. Technical Sanction penalties to be imposed including any of the following: suspension/deletion of account, change of assignment, etc. Functional Sanction penalties to be imposed pursuant to Executive Order No. 292 (Civil Service Law) and its implementing rules and regulations such as: suspension of personnel, dismissal from service, etc. Such cases are usually coursed through the Internal Affairs Service. III. POLICIES AND PROCEDURES 1. Any act which has adverse effects to the following areas are considered as security breach/violation ( refer to Annex A for details ): 1.1 Hardware 1.2 Software 1.3 Data 1.4 Network 1.5 Operating System 1.6 Printed Data 1.7 Computer Media 1.8 Computing Environment 2. Each Head of Office is required to designate a Security Officer who shall monitor strict implementation of the set security guidelines. prcd 3. Non-compliance to the set policies and guidelines embodied in the Security Manual (refer to Annex A) constitutes a security violation which shall be reported immediately by the Security Officer to the ACIR of Information Planning & Quality Service (IPQS) who, upon receipt of reported violation(s), shall: 3.1 Ask for written explanation from respondent. 3.2 Request to convene the Security and Access Committee (SAC) in order to determine the gravity and the nature of the violation committed and the corresponding penalty (whether technical or functional sanctions) to be imposed based on initial reports as well as respondent's explanation. 4. The Security and Access Committee shall: 4.1 Classify violation committed based on list of nature of offense(s) stated above. 4.2 Determine severity of any known violation and recommend corresponding sanctions as stated above. 4.3 Be guided by the policies set forth in Executive Order No. 292 (Civil Service Law) and its implementing rules and regulations: 4.3.1 Only one penalty shall be imposed for each case. "Each case" means one administrative case which may involve one or more charges or counts. 4.3.2 In the determination of penalties to be imposed, mitigating and aggravating circumstances may be considered. The fact that an offender is an IT personnel will be considered as an aggravating circumstance. 4.3.3 If the respondent is found guilty of two or more charges or counts, the penalty imposed should be that corresponding to the most serious charge or count and the rest may be considered as aggravating circumstances. 4.3.4 The second or third offense committed need not be the same offense previously committed but any offense of the same classification. 5. The action of the SAC shall later on be elevated to the ACIR of Internal Affairs Service (IAS) for appropriate action. 6. Infractions may be classified into Grave, Less Grave and Light Offenses. Their corresponding penalties pursuant to Executive Order No. 292, and its implementing Rules and Regulations are: 6.1 GRAVE OFFENSES: 6.2 LESS GRAVE OFFENSES: 6.3 LIGHT OFFENSES: IV. EFFECTIVITY This Order takes effect immediately and shall apply to all types of security violations. prLL LIWAYWAY VINZONS-CHATO Commissioner of Internal Revenue
Ask what this means for your situation
The assistant quotes the passage it relies on and links the source, so you can check every figure it gives you.