跳转至

Cyberark 双人控制流程

来源:Cyberark Dual Control Procedure signed.pdf OCR日期:2026-06-12 17:11

第 1 页

Sinarmas agnbusiness and food GIT SOP 8002 51 CYBERARK DUAL CONTROL PROCEDURE REVISION HISTORY ReV No。 REVISION CONTENTS DATE RATIONALE APPROVEDBY July 27, 2018 New Procedure Release Head Of IT Infrastructure Changes at Scope section May 31,2019 to add Microsoft Office 365 System Office 365 administrator information Head of IT Infrastructure POLICY & STANDARD PROCEDURE 2019

第 2 页

Sinarmas agnbusiness and food Procedure No。 GIT SOP 8002-51 CYBERARKDUAL Alex Wong CONTROL Head of IT Infrastructure PROCEDURE Classification I Page 2 Of 7 Date Issued May ^ 31 2019 Effective Date May 31 2019 Revision No。 TABLE OF CONTENTS OBJECTIVE SCOPE DEFINITION PROCEDURE APPENDIX。

第 3 页

Sinarmas agnbusiness and food Procedure No。 GIT SOP 8002-51 Ak CYBERARK DUAL AlexWonq CONTROL Head of |T Infrastructure PROCEDURE Classification I Page 3 Of7 Date Issued May 31 2019 Effective Date May 31 2019 Revision No。 OBJECTIVE To describe the dual control procedure used to manage the Cyberark privilege identity management application。 TUJUAN Untuk mendeskripsikan prosedur dual kontrol yang digunakan untuk mengatur aplikasi manajemen identitas khusus Cyberark。 SCOPE The sCOpe Of Cyberark encompasses the following type's of IT user ID's Within the Sinar Mas Agribusiness and Food ("Sinar Mas' environment,in all countries Where Sinar Mas operates。 a) Microsoft Exchange administrator b) Microsoft Active Directory Domainl Enterprise administrator C) Local operating system administrator accounts for production Windows and Unix servers d) Microsoft Office 365 administrator RUANG LINGKUP Ruang lingkup Cyberark meliputi User I0 berikut ini yang ada di Sinar Mas Agribusiness and Food ("Sinar Mas"), di seluruh negara dimana Sinar Mas beroperasi。 a) Administrator Microsoft Exchange b) Administrator Microsoft Active Directory Domainl Enterprise C) Akun administrator Operating System lokal untuk production Windows and Unix serers d) Administrator Microsoft Office 365

第 4 页

Sinarmas agnbusinoss and food Procedure No. GIT-SOP B002-51 CYBERARKDUAL AlexWong CONTROL Head Of IT Infrastructyre PROCEDURE Classification 仃 Page 4 0f 7 Date Issued May 31 2019 Effective Date May 31 2019 Revision No。 DEFINITION 1. Cyberark Password Vault (Cyberark) Cyberark is a privilege identity management software used to manage privilege user ID's Or USer ID's Which have administrator privilege。 (Reference: GIT-SOP B002-50 Super User ID Procedure). DEFINISI 1 Brankas Kata Sandi Cyberark (Cyberark) Cyberark adalah Soffware manajemen identitas khusus (istimewa) yang digunakan untuk mengatur User ID yang memiliki hak istimewa ataU User I0 yang memiliki keistimewaan sebagai administrator。 (Referensi: GIT SOP 8002-50 Prosedur Super User ID) 2. Requestor A user (normally IT system administrators Or auditors) Who requests for passwords which are stored in Cyberark。 2. Pemohon Adalah pengguna (umumnya adalah administrator sistem 仃 atau auditor) yang mengajukan permohonan untuk kata sandi yang disimpan dalam Cyberark。 3. Approver A user in Cyberark Whose role is to review the Requestor's request and perform approval rejection of the request。 3. Pemberi Persetujuan Adalah pengguna dalam Cyberark yang peranannya adalah melakukan review atas pengajuan pemohon dan memberikan persetujuan penolakan atas permohonan dari Pemohon。 4. Safe A folder in Cyberark used to categorize the different passwords used by different teams。 For example: Serer team safe, network team safe, etc. The format for Safe name will be: 4 Safe Adalah folder di dalam Cyberark yang digunakan untuk mengkategorikan kata sandi yang berbeda untuk tim yang berbeda。 Sebagai contoh: safe untuk tim server; safe untuk tim jaringan, dan lain sebagainya。 Format penamaannya adalah: GRP_DIV_# of Approver Group Contoh GAR INFRA2A GRP_DIV_# of Approver Group Examples GARINFRA_2A 5. Approver Groups Approver Groups are groups of users Which are permitted to approvelreject 3 request。 There Will always be 2 (two) groups Of approver's required to approve any request and are defined as follows: (specific details in Appendix 1.1) 5. Grup Pemberi Persetujuan Group Pemberi Persetujuan adalah sekelompok pengguna yang diperkenankan untuk menyetujui menolak SUatu permohonan。 Akan selalu ada 2 (dua) grup pemberi persetujuan sebagai persyaratan untuk menyetujui permohonan apapun dan didefinisikan sebagai berikut: (detail spesifik ada pada Lampiran 1.1)

第 5 页

Slnarmas agnbusiness and food Procedure No. GIT-SOP B002-51 CYBERARK DUAL 从_ AlexWong CONTROL Head gf IT Infrastructyre_ PROCEDURE Classification I Page 5of 7 Date Issued May 31 2019 Effective Date May 31 2019 Revision No。 Group A 3 (three) persons from I Infrastructure decided by Head of | Infrastructure. Grup A 3 (tiga) personil dari 仃 Infrastructure yang ditentukan oleh Head of IT Infra- Structure. Grup B 3 (tiga) personil dari Internal I Audit yang ditentukan oleh Head of Internal IT Audit Group 8 3 (three) persons from Internal IT Audit decided by Head of Internal IT Audit。 6. System Administrator 6. Administrator Sistem An individual responsible for managing the Personil yang bertanggungjawab dari tim servers and network devices. (Part of Group Data Center dan Jaringan sebagai bagian I Infrastructure). dari |T Infrastructure. 7. Security Team The IT Security team are individuals that play the role of the administrator of Cyberark application。 7. Tim Security Tim keamanan IT adalah individu individu yang menjalankan tugas sebagai administrator dari aplikasi Cyberark。 Procedure Approval Workflow The approval Workflow is described as follows: Prosedur Bagan Alur Persetujuan Bagan alur persetujuan dideskripsikan sebagai berikut: 1 . Saat pemohon mengajukan permohonan di Cyberark; email notifikasi akan terkirim kepada seluruh pemberi persetujuan di Grup A dan B. 2 Dua persetujuan dibutuhkan untuk me nyetujuj SatU permohonan, dimana Satu persetujuan berasal dari Grup A dan satu persetujuan berasal dari Grup B。 3 Ketika salah satu anggota dari masing masing grup sudah menyetujui Suatu permohonan; persetujuan tersebut sudah mewakili persetujuan dari satu grup。 Maka dari itu, persetujuan dari anggota lain dalam Satu grup yang sama tidak lagi diperlukan。 Selanjutnya; seluruh anggota dalam grUp terkait akan mendapat notifikasi persetujuan melalui email。 1 When 3 requestor submits 3 request in Cyberark, an email notification will be sent to all approvers of Group Aand B。 2_ Two approvals are required to approve 3 request with one approval from Group A and one approval from Group B 3. Once a member of each group has approved the request; 计 represents 3 single group approval。 Therefore; approvals from other members within the Same group are 00 longer required. Subsequently, all members in the respective group will be notified Via email。

第 6 页

Slnarmas agrbusiness and food Procedure No. GIT SOP B002-51 CYBERARK DUAL 4仄 AlexWong CONTROL Head of IT Infrastructure PROCEDURE Classification 仃 Page 6of 7 Date Issued May 31 2019 Effective Date May 31 2019 Revision No。 4 AII approvers in Group A and Group B Will receive an email notification once the entire approval process is completed. 4 Seluruh pemberi persetujuan di Grup A dan Grup Bakan menerima email notifikasi keti- ka seluruh proses persetujuan telah selesai dilakukan。 5. Dalam kondisi dimana salah satu pemberi persetujuan menolakltidak menyetujui permohonan; maka permohonan tersebut akan batal dan tidak diproses。 5. In the event that any approver rejects the request, the request will be Void and will be not processed。 Permission and Utilization After the request has been approved, the permission will be granted as follows: 1. Once the permission is granted, the requestor Will be able to aCCeSS the approved System With the privilege I0 requested by clicking On the (connect access" button Without needing to know Or key i the password。 In the event that 3 password is required for manual login, the responsibility of retrieving 3 password from Cyberark lies with "Group A". Izin dan Penggunaan Setelah permohonan disetujui, penggunaan Cyberark dideskripsikan sebagai berikut: 1 Ketika izin telah diberikan, pemohon dapat melakukan akses langsung ke dalam sistem yang disetujui menggunakan ID khusus yang diminta dengan menekan tombol "connect access" tanpa perlu mengetahui atau mengetik kata sandi。 Dalam situasi dimana kata sandi dibutuhkan untuk login manual; "Grup A bertanggung jawab untuk mendapatkan kembali kata sandi tersebut。 2 If required; "Group A" Would be able to request for the approved password and send i to the Requestor to be entered manually Where needed. "Group A" users will not be able to approve their OWn requests。 For example; Michael Of Group A wants tO request for password; S0 the approvers i Group A will be Alex and Gary only. 2. Jika diperlukan; "Grup A dapat membuat permohonan untuk mendapatkan kata sandi yang disetujui dan mengirimkannya kepada Pemohon untuk login Secara manual ke dalam Sistem ketika diperlukan. "Grup A tidak dapat menyetujui permohonan yang diajukan Oleh dirinya sendiri。 Sebagaj contoh; jika Michael mengajukan permohonan untuk kata sandi; maka pemberi persetujuan di "Grup A yang berhak hanya Alex dan Gary saja。 3 Untuk kata sandi non-exchange seperti administrator lokal admin domain dan VM host root serta lainnya hanya memerlukan persetujuan Grup A Namun, auditor bertanggungjawab untuk melakukan review terhadap detail permohonanl persetujuan dan dokumentasi rekaman sesi。 4 "Grup B" tidak dapat mengajukan permohonan untuk mendapatkan kata sandi。 3 For the non-exchange passwords like local administrator, domain admin and VM host root etc only required Group A approval。 However auditor accountable to review the requestlapproval details and session recordings。 4 "Group B" users Will not be able to request for a password。

第 7 页

Sinarmas agnbusiness and food Procedure No. GITSOP 8002-51 GYBERARKDUAL Alex Wong CONTROL Head Of IT Infrastructure PROCEDURE Classification I Page 7 of 7 Date Issued May 31 2019 Effective Date May 31 2019 Revision No。 5 All passwords are one-time passwords. Cyberark will reset the password after the duration of use has expired. 5. Seluruh kata sandi adalah kata sandi yang hanya dapat digunakan satu kali saja (one time passwords). Cyberark akan melakukan reset kata sandi setelah durasi penggunaan telah kadaluwarsa。 6 Cyberark akan melakukan Verifikasi kata sandi setiap hari setelah jam kerja kantor berakhir mulai dari pukul 01.00 dini hari sampai dengan pukul 07.00 pagi。 Tim Security akan dinformasikan apabila terjadi kegagalan verifikasi kata sandi, dan tim akan melakukan tindak lanjut dengan pemilik Sistem terkait untuk mengidentifikasi dan memperbaiki masalahnya。 Pemantauan sesi dan pencatatan aktivitas pemohon dalam Cyberark akan disimpan selama 12 (dua belas) bulan。 8. Proses menyalin kata sandi dan seluruh aktivitas yang dilakukan di luar Cyberark tidak akan dicatat。 9. Persetujuan dapat dilakukan melalui Telepon Seluler namun membutuhkan akses VPN untuk dapat terhubung dengan jaringan perusahaan。 6 Cyberark Will verify passwords eVery day after office hours between 1amto 7am。 The Security team will be alerted in the event of any failed password verifications; and the team Will follow Up With the respective System Owner to identify and rectify the issue。 7 Session monitoring and recording Of the Requestor's activities in Cyberark Will be saved for a period of 12 (twelve) months。 8 The process of copying password and all activities done out of Cyberark will not be recorded。 9 Approvals Can be performed remotely Via VPN access to the corporate network。 Accounts List List Of accounts that ruled by Cyberark can be found in Appendix 1.3. Accounts List Daftar akun akun yang diatur oleh Cyberark dapat dilihat pada Lampiran 1.3. Appendix Lampiran See Appendx Lampiran 1 Reference Referensi NIA