GIT-P-B001 账号密码管理¶
来源:GIT-P-B001 User Id and Password for IT Controlled Application signed.pdf OCR日期:2026-06-12 16:29
第 1 页¶
Sinarmas agribusiness and food GIT P BOO1 USER ID AND PASSWORD POLICY FOR IT CONTROLLED APPLICATIONS REVISION HISTORY DATE REVISION CONTENTS RATIONALE APPROVED BY 151 _ August 2018 New Policy Release Group Audit and Compliance; Chief Information Officer POLICY & STANDARD PROCEDURE 2018
第 2 页¶
Snarmas agrbusinessand faod Policy No。 GIT P B001 Date Issued 15th Aug 18 Effective Date 15th Aug 18 Revision No。 Group 厅 Polcy & Qoyeranee Group Controller USER ID AND PASSWORD POLICY FOR IT CONTROLLED Classification APPLICATIONS Page I 2 of 11 APPROVALS Io( KhooKek Yeow Chief Information Officer Pedy Hariante Group Audit and Compliance DOCUMENT CONTROL PROCESS OWNER Group IT Policy and Governance REVIEWED BY Group Controller Business Owner (Upstream, Midstream, Downstream, Corporate) DOCUMENT OWNER Group IT Infrastructure
第 3 页¶
Sinarmas agribusiness and food Policy No。 GIT P B001 Group 厅 Polcy & @oyernance_ Group Controller USER ID AND Date Issued 15t Aug 18 15th Aug 18 PASSWORD POLICY FOR IT CONTROLLED Classification APPLICATIONS Page Effective Date 仃 Revisjon No. 3 of 11 TABLE OF CONTENTS PURPOSE SCOPE DEFINITION GUIDELINES APPENDIX REFERENCE 11
第 4 页¶
Sinarmas agrbusiness and food Policy No。 GITP BO0I Date Issued 15th Aug 18 Effectjve Date 15h Aug 18 Revision No Group |T Policy & Governance Group Controller USER ID AND PASSWORD POLICY FOR IT CONTROLLED APPLICATIONS Classification Page 4 of 仇 PURPOSE TUJUAN 1 To provide guidance on the provision and Use Of User IDs and related passwords, including the requests; approvals, deletions; changes; and the naming convention. 1. Untuk memberikan panduan dalam penggunaan User ID dan password terkait; termasuk permohonan; persetujuan; penghapusan, perubahan, serta ketentuan pemberian nama User ID dan password。 2 To aVoid unauthorized aCCess to the Company's information system. 2 Menghindari akses yang tidak sah ke sistem informasi Perusahaan。 SCOPE RUANG LINGKUP User IDs and related passwords granted to internal parties and external parties to access Sinar Mas Group I ("Group IT) controlled infrastructure & applications in all Sinar Mas Agribusiness and Food where Group T operates。 User ID dan password terkait yang diberikan kepada pihak internal dan pihak eksternal untuk mengakses infrastruktur dan aplikasi yang dikendalikan Oleh Sinar Mas Group |T ("Group |T") di semua Sinar Mas Agribusiness and Food; di semua negara tempat Group |T beroperasi。 DEFINITION DEFINISI 1 User ID is an identity that is Used When accessing Group [ controlled infrastructure & applications. For example: VPN, Wireless LAN, SAP; Lotus Notes; Microsoft Outlook; CxC, etc。 (see Reference: "List of 仃 Controlled Application" No.GIT-STD-BO01-04 dated 31 May 2018) 1 User ID adalah identitas yang digunakan pada saat mengakses infrastruktur dan aplikasi yang dikendalikan oleh Group IT。 Contohnya: VPN, Wireless LAN SAP; Lotus Notes; Microsoft Outlook, CxC, dsb_ (lihat Referensi: nList of I Controlled Application" No.GIT-STD-8001-04 tanggal 31 Mei 2018). 2 Password is 匀 series of strings OF sequence of characters (letters; numbers, symbols) used 35 3 Secret key for accessing a computer system Or network。 2 Password adalah serangkaian kode ataU deretan karakter (huruf; angka; simbol) yang digunakan sebagai kunci rahasia untuk dapat mengakses sistem komputer atau jaringan. 3_ Internal parties refer to employees of Sinar Mas Agribusiness and Food who have fixed User IDs。 3 Pihak Interal mengacu kepada karyawan Sinar Mas Agribusiness and Food yang memiliki User ID tetap。
第 5 页¶
Sinarmas agrbusiness and food Policy No。 GIT P B0OI Date Issued 151 Aug 18 Effective Date 15th Aug 18 Revision No。 Group IT Policy & Goyerance_ Group Controller USER ID AND PASSWORD POLICY FOR IT CONTROLLED Classification APPLICATIONS Page 5 of 11 4 External parties refer to non-employees of Sinar Mas Agribusiness and Food who are granted a temporary User I0 4 Pihak External mengacu kepada noh karyawan Sinar Mas Agribusiness and Food yang diberikan User ID sementara。 5. Fixed User IDis a User ID given to internal parties in accordance with their duties and responsibilities, Which can be any Of the following: 5 User ID tetap adalah User ID yang diberikan kepada pihak internal Sesuaj dengan tugas dan tanggung jawabnya; yang dapat terdiri dari: 3 Name-based User ID using employee's name in the naming convention。 For example: 3 User ID berdasarkan Nama dengan menggunakan nama karyawan sebagai format penamaan. Contoh: Citra Puspita Mariana . Puspita.Dewi Citra Puspita Mariana Puspita Dewi b Employee Number-based User ID using Employee Number ("NIK) in the naming convention (this is the preferred User ID type). For example: b User ID berdasarkan Nomor Karyawan dengan menggunakan Nomor Induk Karyawan ("NIK) sebagai format penamaan (ini adalah tipe User ID yang disarankan). Contoh: 16000171 99000999 16000171 99000999 C Role-based User ID using job position in the naming convention。 For example: C User ID berdasarkan Tugas dengan menggunakan posisi jabatan sebagai format penamaan. Contoh: MDR_OPRI (for the Managing Director Operation 1) MDR_OPRI (untuk Managing Director Operation 1) CEO_JAMBI (for CEO PSM Jambi) CEO_JAMBI (untuk CEO PSM Jambi)
第 6 页¶
Sinarmas agribusiness and food Policy No。 GIT P B001 Date Issued 151 Aug 18 Effective Date 15*h Aug 18 Revision No。 Group 厅 Palicy & Qoyernance Group Controller USER ID AND PASSWORD POLICY FOR IT CONTROLLED Classification APPLICATIONS Page 6Of 11 d_ Group Name-based User I0 using name Of the grouP Or team in the naming convention. For example: d_ User I0 berdasarkan Nama Group dengan menggunakan nama group ataU t sebagai format penamaan。 Contoh: SYS_QA (for System Quality Assurance team) SYS_QA (untuk t System Quality Assurance) IT_HLPDSK (for IT Helpdesk team) IT_HLPDSK (untuk Helpdesk) tim I 8 System Name-based User ID using system name in the naming convention。 For example: e User I0 berdasarkan Nama Sistem dengan menggunakan nama sistem sebagai penamaan. Contoh; WB_SYS (for Weighbridge System application) WB_SYS (untuk Weighbridge System) aplikasi SEC_SYS (for Security System application) SEC_SYS (untuk aplikasi Security System) 6 Temporary User ID is a User ID given to external parties With a specified time period sUch as for consultant Only Name-based User ID is allowed for temporary User ID.。 6 User ID Sementara adalah User ID yang diberikan kepada pihak eksternal selama jangka Waktu tertentu, misalnya untuk konsultan。 Hanya User I0 berdasarkan Nama yang digunakan sebagai User I0 sementara。 7. Relevant Group I refers to intemal employee in Group I responsible for supporting either Upstream, Downstream; Midstream or Corporate。 7 Group IT terkait adalah karyawan internal dalam Group IT yang bertanggung jawab untuk mendukung Upstream, Downstream, Midstream atau Corporate。
第 7 页¶
Sinarmas ayrbusiness and foad Policy No。 GIT P B001 Date Issued 15t Aug 18 Effective Date 15th Aug 18 Revision No. Group |T Policy & Covernance Group Controller USER ID AND PASSWORD POLICY FOR IT CONTROLLED Classification APPLICATIONS Page 7 of 11 GUIDELINES KEBIJAKAN 1 All User ID and password requests shall be approved in accordance with te latest "User Management Approval Matrix Standard" document; No.GIT-STD- 8001-02 dated 31st May 2018. 1 Semua permohonan User ID dan password harus disetujui Sesual dengan "User Management Approval Matrix Standard" yang terbaru, No.GIT-STDB002-01 tanggal 31 Mei 2018. All requests for new User IDs or changes to existing User IDs shall be subject to checks against aCCeSS control rules Which have been defined and implemented for the particular application。 Setiap permohonan baru atau perubahan terhadap User ID yang ada; harus tunduk pada pemeriksaan aturan kontrol akses yang telah ditetapkan dan di- implementasikan untuk aplikasi tertentu. 2 User ID and password should not be shared, except for the Group Name based User ID and password Which only can be shared among members Of 3 team performing the same tasks。 2 User I0 dan password tidak boleh digunakan bersama; kecuali untuk User ID berdasarkan Nama Group dan passwordnya; yang dapat digunakan diantara karyawan yang melakukan tugas yang sama dalam satu tim. 3_ The user Will be responsible for the use of hislher own User ID and password; at any tme。 3 User harus bertanggungjawab atas penggunaan User I0 dan password tersebut setiap saat。 For the Group Name based User ID and password, the responsibility is on their relevant manager (level 15-16). Untuk penggunaan User ID dan password berdasarkan Nama Group, tanggung jawab ada pada manager terkait (level 15-16). 4 Temporary User ID and password is valid only for a maximum three (3) months; and can be extended, if necessary by creating a new request 35 mentioned in Guideline No.1 of this policy。 User ID dan password sementara hanya berlaku maksimum tiga (3) bulan; dan dapat diperpanjang apabila diperlukan dengan membuat permintaan baru sesuai Kebijakan No.1 di atas。 If the temporary User ID and password is used for less than the duration Which is stated in te request form then the requester should inform the relevant Group [T Manager (level 15-16) to lock the User ID and password. Jika User ID dan password sementara digunakan kurang dari durasi yang tercantum pada formulir permintaan; maka pemohon harus menginformasikan Group I Manajer terkait (level 1516) Untuk mengunci User ID dan password tsb. 5 If a new system is implemented; then any employee entitled to have aCCeSS to the system; Will request for the User I0 and password in accordance with the latest 5 Jka ada Sistem baru diimplementasikan; maka setiap karyawan yang berhak untuk mengakses ke dalam sistem tersebut akan meminta User I0 dan password sesuai
第 8 页¶
Sinarmas agrbusinass and food Policy No。 GIT P B001 Date Issued 154 _ Aug 18 Effective Date 15th Aug 18 Revision No. Group 厅 Policy & Governance Group Controller USER ID AND PASSWORD POLICY FOR IT CONTROLLED Classification APPLICATIONS Page 8 of 11 "User Management Approval Matrix Standard" No.GIT-STD-8001-02 dated 31st May 2018. This can be handled en-masse for project rollouts where the minimum of a Manager (level 15-16) may aPprove for staff under their organisation。 dengan "User Management Approval Matrix Standard" yang terbaru; No.GIT STD-B002-01 tanggal 31 Mei 2018. Hal ini dapat dilakukan secara masal untuk rollout project dimana minimal level Manager (level 15-16) dapat memberi persetujuan untuk jajaran staf yang ada dibawahnya。 The determination Of the User ID type used; is based on the results Of discussions and decision in the respective project Penentuan tipe User ID yang digunakan; adalah berdasarkan hasil pembahasan dan keputusan dalam project tersebut。 6. It is preferred to USe the Employee Number-based User I0. Other options below can only be used 讦 they are deemed to be more effective or practical: a) Employee Name-based User ID。 6 Tipe User ID yang disarankan adalah User I berdasarkan Nomor Karyawan。 Pilihan lain dibawah ini hanya bisa digunakan jika dianggap lebih efektif atau praktis: a) User ID berdasarkan Nama。 b) Role-based User ID, 讦 all conditions below are fulfilled: b User I0 berdasarkan Tugas; ja seluruh kondisi di bawah ini terpenuhi: the history of correspondence or its activity log remain accessible t0 whoever the position holder is, and; riwayat korespondensi maupun log aktivitas dapat tetap diakses Oleh siapapun pemegang posisi jabatan tersebut; dan; i is used for internal company only。 digunakan hanya untuk internal perusahaan saja。 Group Name-based User ID, 讦 it is used to share information or Workload among team members which have the same task。 C) User ID berdasarkan Nama Group; jika ada keperluan untuk berbagi informasi atau berbagi beban kerja di antara anggota tim yang mempunyai tugas yang sama。 System Name-based User ID, 讦 there is 匀 need for User I0 tO run activity automatically by system; sUch 35 automate invoice delivery to vendor by email。 d) User I0 berdasarkan Nama Sistem; jika ada keperluan User I0 Untuk menjalankan aktifitas secara otomatis Oleh sistem, misalnya pengiriman email otomatis untuk tagihan Ke Vendor。 e) Consultant Name based User I0, 35 identity 讦 there is a need for external consultant t0 aCCESS the Company's system。 E) User ID berdasarkan Nama Konsultan; jka ada keperluan konsultan eksternal untuk mengakses Sistem di Perusahaan。
第 9 页¶
Sinarmas agnbusinoss and faod Policy No。 GITP 8001 Group 厅 Polcy & Govemmance_ Group Controller USER ID AND Date Issued 15th Aug 18 Effective Date 15th Aug 18 Revision No: PASSWORD POLICY FOR IT CONTROLLED Classification APPLICATIONS Page | 90f 11 For all non "Employee Number'-based User IDs, such accounts must be tagged with the NIK number as an account fieldl attribute that Can only be modified by the administrator t0 facilitate tracking。 In the eVent the ID is issued to a non employee; the account must be tagged to a permanent employeeldesignated manager (ie。 sponsor)。 Untuk Semla User ID yang tidak berdasarkan Nomor Karyawan; akun tersebut harus ditandai dengan NIK sebagai feldlatribut akun yang hanya dapat dimodifikasi oleh administrator untuk memudahkan pelacakan。 Jika User I0 diberikan ke non-karyawan, akun tersebut harus ditandai ke karyawan tetaplmanajer yang ditunjuk (contoh: sponsor). 7. User ID naming convention is governed in the "ID Naming Convention" document No。 GIT-STD-8001-03 dated 31s1 May 2018. 7 Format penamaan User I0 diatur pada dokumen "ID Naming Convention" No. GIT- STD-8001-03 tanggal 31 Mei 2018. 8 Every employee shall follow the convention Of creating and changing password in accordance With the latest "Password Rules Standard" No.GIT-STD-BO01-01 dated 15th June 2016。 8 Setiap karyawan wajib mengikuti ketentuan pembuatan dan perubahan password yang sesuai dengan "Password Rules Standard" yang terbaru No.GIT-STD-B001-01 tanggal 15 Juni 2016. 9 For employees who take a planned leave and urgent leave (such as sick leave; etc ), the delegation Of the User I0 shall be arranged by his/her superior minimum manager level (level 1516). The delegation of User I0 should only be used 讦 the system does not support role-based delegation。 9 Untuk karyawan yang mengambil cuti yang terencana maupun cUti yang mendadak (misalnya sakit; dsb.) maka pengaturan pendelegasian User I0 karyawan tersebut menjadi kewenangan atasan minimal setingkat manajer (level 15-16). Pendelegasian User ID hanya dilakukan ja Sistem terkait tdak mendukung pendelegasian berdasarkan tugas。 10. | an employee resigns; is transferred Or terminated,it is the responsibility of Human Resources Business Partner ("HRBP") to notify the relevant Group IT Manager (level 15-16) in order to terminatelchange the User ID prior to the last physical day Of the employee to ensUre User IDs are terminated on tme。In certain cases; User IDs may be terminatedlchanged ahead of schedule based On information from employee's dlrect superior OF Exit Clearance。 10. Jika karyawan berhenti, mutasi ataU diberhentikan, adalah tanggung jawab dari Human Resources Business Partner ("HRBP Untuk memberitahukan kepada Group IT Manajer terkait (level 15-16) yang bertujuan untuk menghentikanl mengubah User I0 mengacu kepada hari terakhir masuk karyawan bersangkutan; untuk memastikan User I0 dinonaktifkan tepat Waktu. User ID dapat dinonaktifkanl diubah lebih cepat dari jadwal yang ditetapkan sebelumnya berdasarkan informasi dari atasan langsung karyawan bersangkutan atau Exit Clearance。
第 10 页¶
Sinarmas agribusiness and food Policy No。 GITP BO0I Date Issued 15t Aug 18 Effective Date 151 Aug 18 Revision No。 Group 厅 Policy & @oyernance _ Group Controller USER ID AND PASSWORD POLICY FOR IT CONTROLLED Classification APPLICATIONS Page 10of 11 Name-based and Employee Number User IDand password of a transferred employee will be adjusted in accordance with the new Working unit's environment。 For example: organizational unit adjustment On master data User ID, etc。 User ID dan password berdasarkan Nama dan User ID berdasarkan Nomor Karyawan atas karyawan yang dimutasi; akan disesuajkan sesuai dengan unit kerja yang baru. Misalnya penyesuaian unit organisasi pada master data User I0, dll。 Role-based User ID and password Of a resignedltransferredlterminated employee; Will be handed-over to hislher superior by the employee in concerned. User ID dan password berdasarkan Tugas atas karyawan yang mengundurkan diril mutasil diberhentikan akan diserah- terimakan ke atasannya oleh karyawan yang bersangkutan。 Group Name-based User ID's password of 3 resignedltransferredlterminated em ployee; should be reset by the employee Who is responsible for the Group Name based User ID,as stated in Guideline No.3 Of this policy。 Password User ID berdasarkan Nama Group atas karyawan yang berhentil mutasildiberhentikan; akan di reset Oleh karyawan yang bertanggung jawab atas User I0 berdasarkan Nama Group tersebut; seperti yang disebutkan dalam Kebijakan No.3 di atas。 11. Any locked User ID Or every User ID of level 16 and below Which are inactive for more than 90 days will be disabled。 After another 30 days, the disabled Used ID will be subject to permanent deletion by the relevant Group I Manager (level 1516) after obtaining approval in accordance with the "User Management Matrix Approval Standard" No.GIT-STD-8001-02 dated 31st May 2018. Employee has to resubmit 3 new request to Create te User [0, 讦 needed. 11. Setiap User ID yang terkunci atau User ID dari karyawan level 16 kebawah yang tidak aktif lebih dari 90 hari akan dinon-aktifkan。 Setelah 30 hari selanjutnya; User ID yang tidak aktf akan dihapus oleh Group |T Manajer (level 15-16) Setelah mendapatkan persetujuan sesuai dengan "User Management Matrix Approval Standard" No.GIT-STD- B001-02 tanggal 31 Mei 2018. Karyawan harus meminta permohonan baru untuk pembuatan User ID, jika diperlukan。 The user can re-activate the disabled User I0 by submitting a request to Group IT Manager (level 15-16). User dapat mengaktivasi kembali User ID yang tidak aktf dengan mengirimkan permohonan kepada Group 仃 Manager (level 15-16) 12. Guidelines regarding ID for Super User; Which is used to change any configuraton of a certain system, Will be governed by a Separate policy named "Super User I0 Policy" No.GIT- P B002 dated 31st May 2018. 12. Pengaturan I0 untuk Super User; yang digunakan Untuk mengubah konfigurasi atas SUatU sistem, akan diatur Oleh kebijakan terpisah mengenai "Super User I0 Policy' No.GIT-P-B002 tanggal 31 Mei 2018.
第 11 页¶
Sinarmas agribusiness and food Policy No。 GITP BO01 Date Issued 15th Aug 18 Effective Date 15th Aug 18 Revision No。 Group IT Policy & Governance Group Controller USER ID AND PASSWORD POLICY FOR IT CONTROLLED Classification APPLICATIONS Page 11 of 11 13. Any exception to this policy can be requested to the relevant Group IT Vice President (level 19-21) with an approval by at least the Vice President (level 19-21) together with te Senior Vice President (level 22-23) of the relevant department The exception list should be reported to the relevant Executive Vice President (level 24-26) every 3 months by at least the relevant Group IT Vice President (level 19 21). 13. Pengecualian dari kebijakan ini dapat diajukan ke Vice President Group IT terkaif (level 19-21) setelah mendapatkan persetujuan dari atasan terkait minimal setingkat Vice President (level 19-21) beserta Senior Vice President (level 22- 23). Daftar atas pengecualian ini dilaporkan Secara 3 bulan sekali ke Executive Vice President terkait (level 24-26), minimal oleh Group IT Vice President terkait (level 19-21. APPENDIX NIA LAMPIRAN NIA REFERENCE REFERENSI ID Naming Convention No.GIT-STD BO01-03 dated 31st May 2018, Which is the latest at the time of the issuance of the policy. ID Naming Convention No.GIT-STDB001-03 tanggal 31 Mei 2018, yang terbaru pada saat diterbitkannya kebijakan ini。 List Of IT Controlled Application No.GIT-STD- 8001-04 dated 3151 May 2018, Which is the Iatest at the time of the issuance of the policy. List Of IT Controlled Application No.GIT-STD 8001-04 tanggal 31 Mei 2018, yang terbaru pada saat diterbitkannya kebijakan ini. Password Rules Standard No.GIT-STD-BOOI- 01 dated 15th June 2016, Which is the latest at the time of the issuance of the policy. Password Rules Standard No.GIT-STD-8001-01 tanggal 15 Juni 2016, yang terbaru pada saat diterbitkannya kebijakan ini。 Super User ID Policy No.GIT-P-B002 dated 31s1 May 2018, Which is the latest at the time of the issuance Of the policy. Super User ID Policy No.GIT-P-8002 tanggal 31 Mei 2018, yang terbaru pada saat diterbitkannya kebijakan ini. User Management Approval Matrix Standard No.GIT-STD- B001-02 dated 31s1 May 2018; Which is the latest at the tme of the issuance Of the policy. User Management Approval Matrix Standard No.GIT-STD-B002-01 tanggal 31 Mei 2018, yang terbaru pada saat diterbitkannya kebijakan ini。