GIT-P-B002 Privileged Accounts Policy¶
自动提取自PDF
Page 1¶
reA
GIT-P-B002 PRIVILEGED ACCOUNTS POLICY
POLICY 2022
Page 2¶
Policy No. GIT-P-B002 PRIVILEGED ACCOUNTS POLICY Group IT Policy and Governance
Date Issued 15th August 2022 GCC - Program and Governance
Effective Date 15th August 2022 Classification IT Revision No. -- Page 2 of 12
APPROVALS
Pedy Harianto Head of Group Controllership and Compliance
Khoo Kok Yeow Chief Information Officer
DOCUMENT CONTROL
PROCESS OWNER
Group IT (Infrastructure, Applications and Digital)
REVIEWED BY
GCC - Program and Governance
DOCUMENT OWNER
Group IT Policy and Governance
Pedy Harianto Digitally signed by Pedy Harianto Date: 2022.08.05 17:01:40 +07'00' Kok Yeow Digitally signed by Kok Yeow Date: 2022.08.08 09:47:56 +07'00'
Page 3¶
Policy No. GIT-P-B002 PRIVILEGED ACCOUNTS POLICY Group IT Policy and Governance
Date Issued 15th August 2022 GCC - Program and Governance
Effective Date 15th August 2022 Classification IT Revision No. -- Page 3 of 12
TABLE OF CONTENTS PURPOSE ................................................................................................................................................. 4 SCOPE ...................................................................................................................................................... 4 DEFINITION .............................................................................................................................................. 5 GUIDELINES ............................................................................................................................................. 7 REFERENCE .......................................................................................................................................... 12
Page 4¶
Policy No. GIT-P-B002 PRIVILEGED ACCOUNTS POLICY Group IT Policy and Governance
Date Issued 15th August 2022 GCC - Program and Governance
Effective Date 15th August 2022 Classification IT Revision No. -- Page 4 of 12 PURPOSE The purpose of this policy is to govern rules for the creation, use and storage of Privileged Accounts to ensure proper control of elevated access rights to systems identified as critical to the operations (“Critical Systems”) of Sinar Mas Agribusiness and Food.
TUJUAN
Tujuan dari kebijakan ini adalah untuk mengatur
ketentuan untuk membuat, menggunakan dan
penyimpanan Akun Istimewa (Privileged Account)
untuk memastikan kontrol yang tepat atas hak
akses tinggi ke sistem yang diidentifikasi sebagai
penting untuk operasi (“Sistem Kritikal”) di Sinar
Mas Agribusiness and Food.
SCOPE
The scope of this policy is limited to Critical
Systems belonging to Sinar Mas Agribusiness
and Food, in all countries where Sinar Mas
Group IT (“Group IT”) operates.
RUANG LINGKUP
Ruang lingkup kebijakan ini terbatas pada sistem
kritikal milik Sinar Mas Agribusiness and Food, di
semua negara tempat Sinar Mas Group IT (”Group
IT”) beroperasi.
Gilbert Viernes Digitally signed by Gilbert Viernes Date: 2022.08.08 10:52:52 +07'00'
Page 5¶
Policy No. GIT-P-B002 PRIVILEGED ACCOUNTS POLICY Group IT Policy and Governance
Date Issued 15th August 2022 GCC - Program and Governance
Effective Date
15th August 2022
Classification
IT
Revision No.
--
Page
5 of 12
DEFINITION
1. Privileged Accounts are those which have
system privileges or permissions beyond
those granted to a normal user. They may be
one of the following types:
a. A non-personal identity (“ID”) to access a
Critical System which has the role of an
Administrator, or is capable to change
any configuration in the related system;
or,
b. A non-personal identity (“ID”) with
sufficient privileges to change a Critical
System’s settings which would typically
need to be validated by a process
maker/checker; or,
c. A personal or non-personal identity (“ID”)
that can be used to view confidential
company information which typically
should only be made available to limited
and authorized personnel (i.e. trade
secrets, formulas, employee salaries); or,
d. A personal or non-personal identity (“ID”)
that
provides
elevated
and/or
administrative access to a local instance
such as PCs and Laptops.
2. Whenever possible, the following types of
Privileged Accounts should be created for
Critical Systems:
a. Master Super User ID: A Super User ID
which has the highest authorization and
has complete access to the system. On
most systems, Super User ID Master is
the
default
administrator/root/admin
account.
b. Emergency Super User ID: A Super
User
ID
which
has
per-module
authorization
for
solving
emergency/critical problems.
c. Operational Super User ID: A Super
User
ID
which
has
per-module
authorization which is used for solving
DEFINISI
1. Akun Istimewa (Privileged) adalah akun yang
memiliki hak atau izin istimewa pada sistem
apapun yang dimiliki pengguna normal. Berikut
merupakan tipe dari akun istimewa:
a. Identitas non pribadi (“ID”) untuk mengakses
Sistem Kritikal yang memiliki peran sebagai
Administrator, atau yang dapat mengubah
konfigurasi apapun di dalam sistem terkait;
atau,
b. Identitas non pribadi (“ID”) dengan hak
istimewa yang memadai untuk mengubah
pengaturan Sistem Kritikal yang biasanya
perlu divalidasi oleh pembuat/pemeriksa
proses; atau,
c. Identitas pribadi atau non pribadi (“ID”) yang
dapat digunakan untuk melihat informasi
rahasia perusahaan yang pada umumnya
hanya
disediakan
untuk
orang
yang
berwenang dan terbatas (misal: rahasia
dagang, formula, gaji karyawan); atau,
d. Identitas pribadi atau non pribadi (“ID”) yang
menyediakan
akses
tinggi
dan/atau
administratif ke perangkat lokal seperti PC
dan Laptop.
2. Dimana dimungkinkan, beberapa tipe Akun
Istimewa berikut ini harus dibuat untuk Sistem
Kritikal:
a. Super User ID Master: Merupakan Super
User ID yang memiliki otorisasi paling tinggi
dan memiliki akses lengkap ke dalam
sistem. Pada kebanyakan sistem, Super
User
ID
Master
adalah
akun
administrator/root/admin default.
b. Super User ID Emergency: Merupakan
Super User ID yang memiliki otorisasi per-
module untuk penyelesaian masalah yang
bersifat darurat/kritis.
c. Super User ID Operational: Merupakan
Super User ID yang memiliki otorisasi per-
module yang digunakan untuk penyelesaian
Gilbert
Viernes
Digitally signed by
Gilbert Viernes
Date: 2022.08.08
14:00:34 +07'00'
Page 6¶
Policy No. GIT-P-B002 PRIVILEGED ACCOUNTS POLICY Group IT Policy and Governance
Date Issued 15th August 2022 GCC - Program and Governance
Effective Date
15th August 2022
Classification
IT
Revision No.
--
Page
6 of 12
daily support problems, Change Request
(CR),
or
project
that
are
not
emergency/critical.
Note:
Every Production server shall have a Super
User ID, at least a Master Super User ID.
3. Password is a sequence of characters
(letters, numbers, symbols) used as a secret
key for unlocking the abilities of User ID’s on
computer system or network. The password
complexity requirement for critical systems
should comply with “GIT-P-B001 User ID and
Password
Policy
for
IT
Controlled
Applications.”
4. Critical System refers to all production
systems located at the central data center
which
contains
confidential
Company
information
(financial
data,
intellectual
property,
employee,
customer/vendor
information), and are managed by the Group
IT Infrastructure team. These are used by
Business
Users
in
carrying
out
daily
operations. System failures or problems may
cause the Company to suffer financial and
productivity losses.
The list of Critical Systems refers to “GIT-
STD-B002-02 Critical Systems Definition”.
5. Cyberark Password Vault (“Cyberark”) is a
software of access management system
which is used to manage privilege User ID or
User ID which have administrator privilege.
6. SAP Governance Risk Control (“GRC”) is
a tool of access management system which is
used to facilitate the management and access
control of SAP Super User IDs.
masalah support harian, Change Request
(CR), atau proyek yang sifatnya bukan
darurat/kritis.
Catatan:
Setiap server Production wajib memiliki Super
User ID, setidaknya Super User ID Master.
3. Password adalah serangkaian kode atau
deretan karakter (huruf, angka, simbol) yang
digunakan sebagai kunci rahasia sebagai akses
bagi User ID terhadap system computer dan
jaringan. Persyaratan kompleksitas password
untuk sistem kritikal harus mematuhi kebijakan
“GIT-P-B001 User ID and Password Policy for IT
Controlled Applications”.
4. Critical System mengacu pada semua sistem
produksi di dalam pusat data center yang berisi
informasi rahasia perusahaan (data keuangan,
kekayaan
intelektual,
karyawan,
informasi
customer/vendor), dan yang dikelola oleh tim
Group
IT
Infrasturtuce.
Critical
System
digunakan oleh Bisnis User dalam menjalankan
operasi
bisnis
sehari-hari.
Kendala
atau
kegagalan pada sistem dapat menyebabkan
Perusahaan
mengalami
kerugian
secara
finansial maupun produktivitas.
Daftar Critical Systems merujuk pada kebijakan
“GIT-STD-B002-02 Critical System Definition”
5. Cyberark
Password
Vault
(“Cyberark”)
adalah
perangkat
lunak
berupa
sistem
manajemen akses yang digunakan untuk
mengatur User ID yang memiliki hak istimewa
atau User ID yang memiliki keistimewaan
sebagai administrator.
6. SAP Governance Risk Control (“GRC”)
adalah sarana (tool) berupa sistem manajemen
akses
yang
digunakan
untuk
membantu
pengelolaan dan kontrol akses Super User ID
pada aplikasi sistem SAP.
Gilbert Viernes Digitally signed by Gilbert Viernes Date: 2022.08.08 10:53:12 +07'00'
Page 7¶
Policy No. GIT-P-B002 PRIVILEGED ACCOUNTS POLICY Group IT Policy and Governance
Date Issued 15th August 2022 GCC - Program and Governance
Effective Date 15th August 2022 Classification IT Revision No. -- Page 7 of 12 GUIDELINES
A. PROVISION OF PRIVILEGED ACCOUNT USAGE 1. Master Super User ID a. It will only be used if the required system maintenance activities cannot be performed using Emergency and Operational Super User ID. b. For certain systems such as SAP, after performing a change process which directly in the Production server, it shall be synchronized/transported from server of Development Quality Assurance Production. c. All performed activities are logged to be reviewed by IT Internal Audit. 2. Emergency Super User ID a. Used to solve problems for emergency/critical conditions and require immediate improvement action directly on the Production server.
b. The use of Emergency Super User ID shall be substantiated by an emergency ticket/issue. c. For certain systems such as SAP, after performing a change process which directly in the Production server, it shall be synchronized/transported from server of Development Quality Assurance Production. KEBIJAKAN
A. KETENTUAN PENGGUNAAN AKUN
ISTIMEWA
1. Super User ID Master
a. Hanya
akan
digunakan
apabila
aktivitas pemeliharaan sistem yang
diperlukan tidak dapat dilakukan
menggunakan
Super
User
ID
Emergency dan Operational.
b. Untuk sistem tertentu seperti SAP,
setelah perubahan yang dilakukan
secara
langsung
di
server
Production, wajib melakukan proses
sinkronisasi/transport
dari
server
Development Quality Assurance
Production.
c. Seluruh aktivitas yang dilakukan
terdokumentasi untuk diperiksa oleh
IT Internal Audit.
2. Super User ID Emergency
a. Digunakan
untuk
menyelesaikan
masalah
untuk
kondisi
yang
darurat/kritis dan membutuhkan
tindakan
perbaikan
secepatnya
secara
langsung
di
server
Production.
b. Penggunaan
Super
User
ID
Emergency wajib dilengkapi dengan
tiket/permasalahan darurat.
c. Untuk sistem tertentu seperti SAP,
setelah perubahan secara langsung
di
server
Production
selesai
dilakukan, wajib melakukan proses
sinkronisasi/transport
dari
server
Development Quality Assurance
Production.
Gilbert
Viernes
Digitally signed by
Gilbert Viernes
Date: 2022.08.08
10:53:32 +07'00'
Page 8¶
Policy No. GIT-P-B002 PRIVILEGED ACCOUNTS POLICY Group IT Policy and Governance
Date Issued 15th August 2022 GCC - Program and Governance
Effective Date 15th August 2022 Classification IT Revision No. -- Page 8 of 12 d. All performed activities are logged to be reviewed by IT Internal Audit. 3. Operational Super User ID a. Used for daily business activities such as providing daily support, working on Change Requests and activities related to business projects which are not in an emergency/critical situation. b. The use of Operational Super User ID shall be substantiated by a ticket, number of change request or project. c. The use of Operational Super User ID is not allowed to make changes which are required a transport process on the server of Development Quality Assurance Production. 4. IT Group’s Head of MDM, Policy Compliance and Authorization shall ensure that Super User ID and all activities related to authorization are in accordance with this policy.
d. Seluruh aktivitas yang dilakukan
terdokumentasi untuk diperiksa oleh
IT Internal Audit.
3. Super User ID Operational
a. Digunakan untuk aktivitas bisnis
sehari-hari seperti untuk memberikan
support
harian,
mengerjakan
permintaan
perubahan
(Change
Request)
dan
aktivitas
yang
berhubungan dengan proyek bisnis
yang
bukan
dalam
keadaan
darurat/kritis.
b. Penggunaan
Super
User
ID
Operational wajib dilengkapi dengan
tiket, nomor permintaan perubahan
(Change Request) atau proyek.
c. Penggunaan
Super
User
ID
Operational
tidak
diperbolehkan
untuk melakukan perubahan yang
memerlukan proses transport pada
server
Development
Quality
Assurance Production.
4. IT Group’s Head of MDM, Policy
Compliance and Authorization wajib
memastikan bahwa Super User ID dan
seluruh kegiatan yang berhubungan
dengan otorisasi sesuai dengan yang
diatur didalam kebijakan ini.
Gilbert Viernes Digitally signed by Gilbert Viernes Date: 2022.08.08 10:58:58 +07'00'
Page 9¶
Policy No. GIT-P-B002 PRIVILEGED ACCOUNTS POLICY Group IT Policy and Governance
Date Issued 15th August 2022 GCC - Program and Governance
Effective Date 15th August 2022 Classification IT Revision No. -- Page 9 of 12 B. APPROVAL OF PRIVILEGED ACCOUNT USAGE ON CRITICAL SYSTEMS B. PERSETUJUAN PENGGUNAAN AKUN ISTIMEWA PADA SISTEM KRITIKAL 1. Approval Matrix for Critical System Access Managed by Access Management System Super User ID Authorization Approver SAP Systems Non-SAP Systems
(Microsoft Office 365, Microsoft Windows Domain / Active Directory, Microsoft Outlook Server, Weighbridge, and Backup Servers) Networking Systems
(Firewalls and Core Switches)
Master
Head of Group Controllership
and Compliance and
Head of IT Apps
Head of Group Controllership and Compliance and
Head of IT Infrastructure/Head of IT Digital Delivery
Emergency
Head of IT Apps
Head of IT Infrastructure/Head of IT Digital Delivery
Operational
Support/CR
IT Head of
related module
Support/CR
Head of Site IT/ Head of IT Digital
Delivery
Project
Head of IT Apps
Project
Head of Data Center Operation/Head of
Network Operation/ Head of IT Digital
Delivery
Basis
Head of IT Apps
*) Persetujuan disesuaikan berdasarkan aplikasi/sistem yang dikelola oleh IT Infra/IT Digital.
Approval is adjusted based on the applications/systems which are managed by IT Infra/IT Digital.
2. Approval Matrix for Critical System Access Which Not Managed by Access Management System
Super User ID
Authorization Approver
Master
Head of Group Controllership and Compliance and Head of IT Apps
Operational
Support
Head of IT Apps
CR
Project
Gilbert Viernes Digitally signed by Gilbert Viernes Date: 2022.08.08 10:59:20 +07'00'
Page 10¶
Policy No. GIT-P-B002 PRIVILEGED ACCOUNTS POLICY Group IT Policy and Governance
Date Issued 15th August 2022 GCC - Program and Governance
Effective Date
15th August 2022
Classification
IT
Revision No.
--
Page
10 of 12
C. PROVISION FOR CRITICAL SYSTEM
ACCESS USING SUPER USER ID
1. Provisions for Critical System access using
Super User ID which go through an access
management system (such as Cyberark
and GRC), as follows:
a.1. All granted Super User IDs requests
are registered to the Requestor’s NIK
ID.
a.2. A request of Super User ID usage
shall be submitted through an access
management system.
a.3. The reason for requesting a Super
User ID usage is a mandatory
requirement.
a.4. The approvals matrix for the Super
User ID usage request are set in this
policy (section B, point 1).
a.5. A notification email will be sent to the
Requestor after the usage request of
Super User ID is approved by the
authorized officers.
a.6. NIK ID of the approver, time and date
stamp will be logged by the access
management system.
a.7. Every action or activity based on the
User’s NIK ID from usage request,
approval process until the activities
performed by the Requestor are
logged in the access management
system.
C. KETENTUAN AKSES SISTEM KRITIKAL MENGGUNAKAN SUPER USER ID 1. Ketentuan untuk akses Sistem Kritikal menggunakan Super User ID yang dilakukan melalui sistem manajemen akses (seperti Cyberark and GRC), sebagai berikut: a.1. Semua permintaan Super User ID yang diberikan didaftarkan menggunakan NIK ID Pemohon. a.2. Permintaan penggunaan Super User ID wajib diajukan melalui sistem manajemen akses. a.3. Alasan permintaan atas penggunaan Super User ID wajib dicantumkan. a.4. Matriks persetujuan untuk penggunaan Super User ID telah diatur di dalam kebijakan ini (bagian B, butir 1). a.5. Email notifikasi akan dikirimkan kepada Pemohon setelah permintaan penggunaan Super User ID disetujui oleh pejabat berwenang. a.6. NIK ID pemberi persetujuan, waktu serta tanggal akan terdokumentasi di dalam sistem manajemen akses. a.7. Setiap aktivitas berdasarkan NIK ID pengguna mulai dari permintaan penggunaan, proses persetujuan hingga aktivitas yang dilakukan oleh Pemohon terdokumentasi di dalam sistem manajemen akses.
Gilbert Viernes Digitally signed by Gilbert Viernes Date: 2022.08.08 10:59:49 +07'00'
Page 11¶
Policy No. GIT-P-B002 PRIVILEGED ACCOUNTS POLICY Group IT Policy and Governance
Date Issued 15th August 2022 GCC - Program and Governance
Effective Date 15th August 2022 Classification IT Revision No. -- Page 11 of 12 2. Provisions of Critical Systems access which are not managed by access management system, as follows: a. Only available for using Master Super User ID and Operational Super User ID. b. A request of Master Super User ID and Operational Super User ID usage shall be submitted manually via email to the authorized officers (refers to section B, point 2) for approval process which in detail will be separatelly regulated in GIT-SOP-B002-50 Super User ID Procedure. c. Especially for Operational Super User ID usage, after being approved, IT Admin will manually assign the access to the related Requestor’s User ID with the specific time period.
- Ketentuan akses Sistem Kritikal yang tidak dikelola melalui sistem manajemen akses, sebagai berikut: a. Hanya dapat menggunakan Super User ID Master dan Super User ID Operational. b. Permintaan penggunaan Super User ID Master dan Super User ID Operational wajib diajukan secara manual melalui email kepada pejabat berwenang (mengacu pada bagian B, poin 2) sebagai proses persetujuan yang secara detail diatur terpisah di dalam GIT-SOP-B002-50 Super User ID Procedure. c. Khusus pada penggunaan Super User ID Operational, setelah mendapatkan persetujuan, IT Admin akan memberikan akses secara manual pada User ID Pemohon dengan periode waktu tertentu.
Gilbert Viernes Digitally signed by Gilbert Viernes Date: 2022.08.08 11:00:22 +07'00'
Page 12¶
Policy No. GIT-P-B002 PRIVILEGED ACCOUNTS POLICY Group IT Policy and Governance
Date Issued 15th August 2022 GCC - Program and Governance
Effective Date
15th August 2022
Classification
IT
Revision No.
--
Page
12 of 12
REFERENCE
GIT-STD-B001-01
Password
Rules
Standard.
GIT-SOP-B002-50
Super
User
ID
Procedure.
GIT-P-B001 User ID and Password Policy
for IT Controlled Applications.
GIT-STD-B002-02
Critical
System
Definition.
GIT-SOP-B002-51 Cyberark Dual Control
Procedure.
REFERENSI
GIT-STD-B001-01
Password
Rules
Standard.
GIT-SOP-B002-50
Super
User
ID
Procedure.
GIT-P-B001 User ID and Password Policy
for IT Controlled Applications.
GIT-STD-B002-02
Critical
System
Definition.
GIT-SOP-B002-51 Cyberark Dual Control
Procedure.