跳转至

GIT-P-B002 Privileged Accounts Policy

自动提取自PDF


Page 1

reA

GIT-P-B002 PRIVILEGED ACCOUNTS POLICY

POLICY 2022


Page 2

Policy No. GIT-P-B002 PRIVILEGED ACCOUNTS POLICY Group IT Policy and Governance

Date Issued 15th August 2022 GCC - Program and Governance

Effective Date 15th August 2022 Classification IT Revision No. -- Page 2 of 12

APPROVALS

Pedy Harianto Head of Group Controllership and Compliance

Khoo Kok Yeow Chief Information Officer

DOCUMENT CONTROL PROCESS OWNER Group IT (Infrastructure, Applications and Digital)
REVIEWED BY GCC - Program and Governance DOCUMENT OWNER Group IT Policy and Governance

Pedy Harianto Digitally signed by Pedy Harianto Date: 2022.08.05 17:01:40 +07'00' Kok Yeow Digitally signed by Kok Yeow Date: 2022.08.08 09:47:56 +07'00'


Page 3

Policy No. GIT-P-B002 PRIVILEGED ACCOUNTS POLICY Group IT Policy and Governance

Date Issued 15th August 2022 GCC - Program and Governance

Effective Date 15th August 2022 Classification IT Revision No. -- Page 3 of 12

TABLE OF CONTENTS PURPOSE ................................................................................................................................................. 4 SCOPE ...................................................................................................................................................... 4 DEFINITION .............................................................................................................................................. 5 GUIDELINES ............................................................................................................................................. 7 REFERENCE .......................................................................................................................................... 12


Page 4

Policy No. GIT-P-B002 PRIVILEGED ACCOUNTS POLICY Group IT Policy and Governance

Date Issued 15th August 2022 GCC - Program and Governance

Effective Date 15th August 2022 Classification IT Revision No. -- Page 4 of 12 PURPOSE The purpose of this policy is to govern rules for the creation, use and storage of Privileged Accounts to ensure proper control of elevated access rights to systems identified as critical to the operations (“Critical Systems”) of Sinar Mas Agribusiness and Food.

TUJUAN Tujuan dari kebijakan ini adalah untuk mengatur ketentuan untuk membuat, menggunakan dan penyimpanan Akun Istimewa (Privileged Account) untuk memastikan kontrol yang tepat atas hak akses tinggi ke sistem yang diidentifikasi sebagai penting untuk operasi (“Sistem Kritikal”) di Sinar Mas Agribusiness and Food.
SCOPE The scope of this policy is limited to Critical Systems belonging to Sinar Mas Agribusiness and Food, in all countries where Sinar Mas Group IT (“Group IT”) operates. RUANG LINGKUP Ruang lingkup kebijakan ini terbatas pada sistem kritikal milik Sinar Mas Agribusiness and Food, di semua negara tempat Sinar Mas Group IT (”Group IT”) beroperasi.

Gilbert Viernes Digitally signed by Gilbert Viernes Date: 2022.08.08 10:52:52 +07'00'


Page 5

Policy No. GIT-P-B002 PRIVILEGED ACCOUNTS POLICY Group IT Policy and Governance

Date Issued 15th August 2022 GCC - Program and Governance

Effective Date 15th August 2022 Classification IT Revision No. -- Page 5 of 12 DEFINITION 1. Privileged Accounts are those which have system privileges or permissions beyond those granted to a normal user. They may be one of the following types: a. A non-personal identity (“ID”) to access a Critical System which has the role of an Administrator, or is capable to change any configuration in the related system; or,
b. A non-personal identity (“ID”) with sufficient privileges to change a Critical System’s settings which would typically need to be validated by a process maker/checker; or, c. A personal or non-personal identity (“ID”) that can be used to view confidential company information which typically should only be made available to limited and authorized personnel (i.e. trade secrets, formulas, employee salaries); or,
d. A personal or non-personal identity (“ID”) that provides elevated and/or administrative access to a local instance such as PCs and Laptops. 2. Whenever possible, the following types of Privileged Accounts should be created for Critical Systems:
a. Master Super User ID: A Super User ID which has the highest authorization and has complete access to the system. On most systems, Super User ID Master is the default administrator/root/admin account. b. Emergency Super User ID: A Super User ID which has per-module authorization for solving emergency/critical problems. c. Operational Super User ID: A Super User ID which has per-module authorization which is used for solving DEFINISI 1. Akun Istimewa (Privileged) adalah akun yang memiliki hak atau izin istimewa pada sistem apapun yang dimiliki pengguna normal. Berikut merupakan tipe dari akun istimewa: a. Identitas non pribadi (“ID”) untuk mengakses Sistem Kritikal yang memiliki peran sebagai Administrator, atau yang dapat mengubah konfigurasi apapun di dalam sistem terkait; atau, b. Identitas non pribadi (“ID”) dengan hak istimewa yang memadai untuk mengubah pengaturan Sistem Kritikal yang biasanya perlu divalidasi oleh pembuat/pemeriksa proses; atau, c. Identitas pribadi atau non pribadi (“ID”) yang dapat digunakan untuk melihat informasi rahasia perusahaan yang pada umumnya hanya disediakan untuk orang yang berwenang dan terbatas (misal: rahasia dagang, formula, gaji karyawan); atau,
d. Identitas pribadi atau non pribadi (“ID”) yang menyediakan akses tinggi dan/atau administratif ke perangkat lokal seperti PC dan Laptop. 2. Dimana dimungkinkan, beberapa tipe Akun Istimewa berikut ini harus dibuat untuk Sistem Kritikal: a. Super User ID Master: Merupakan Super User ID yang memiliki otorisasi paling tinggi dan memiliki akses lengkap ke dalam sistem. Pada kebanyakan sistem, Super User ID Master adalah akun administrator/root/admin default.
b. Super User ID Emergency: Merupakan Super User ID yang memiliki otorisasi per- module untuk penyelesaian masalah yang bersifat darurat/kritis.
c. Super User ID Operational: Merupakan Super User ID yang memiliki otorisasi per- module yang digunakan untuk penyelesaian Gilbert Viernes Digitally signed by Gilbert Viernes Date: 2022.08.08 14:00:34 +07'00'


Page 6

Policy No. GIT-P-B002 PRIVILEGED ACCOUNTS POLICY Group IT Policy and Governance

Date Issued 15th August 2022 GCC - Program and Governance

Effective Date 15th August 2022 Classification IT Revision No. -- Page 6 of 12 daily support problems, Change Request (CR), or project that are not emergency/critical.
Note: Every Production server shall have a Super User ID, at least a Master Super User ID. 3. Password is a sequence of characters (letters, numbers, symbols) used as a secret key for unlocking the abilities of User ID’s on computer system or network. The password complexity requirement for critical systems should comply with “GIT-P-B001 User ID and Password Policy for IT Controlled Applications.” 4. Critical System refers to all production systems located at the central data center which contains confidential Company information (financial data, intellectual property, employee, customer/vendor information), and are managed by the Group IT Infrastructure team. These are used by Business Users in carrying out daily operations. System failures or problems may cause the Company to suffer financial and productivity losses. The list of Critical Systems refers to “GIT- STD-B002-02 Critical Systems Definition”. 5. Cyberark Password Vault (“Cyberark”) is a software of access management system which is used to manage privilege User ID or User ID which have administrator privilege.
6. SAP Governance Risk Control (“GRC”) is a tool of access management system which is used to facilitate the management and access control of SAP Super User IDs.

masalah support harian, Change Request (CR), atau proyek yang sifatnya bukan darurat/kritis.
Catatan: Setiap server Production wajib memiliki Super User ID, setidaknya Super User ID Master. 3. Password adalah serangkaian kode atau deretan karakter (huruf, angka, simbol) yang digunakan sebagai kunci rahasia sebagai akses bagi User ID terhadap system computer dan jaringan. Persyaratan kompleksitas password untuk sistem kritikal harus mematuhi kebijakan “GIT-P-B001 User ID and Password Policy for IT Controlled Applications”. 4. Critical System mengacu pada semua sistem produksi di dalam pusat data center yang berisi informasi rahasia perusahaan (data keuangan, kekayaan intelektual, karyawan, informasi customer/vendor), dan yang dikelola oleh tim Group IT Infrasturtuce. Critical System digunakan oleh Bisnis User dalam menjalankan operasi bisnis sehari-hari. Kendala atau kegagalan pada sistem dapat menyebabkan Perusahaan mengalami kerugian secara finansial maupun produktivitas. Daftar Critical Systems merujuk pada kebijakan “GIT-STD-B002-02 Critical System Definition” 5. Cyberark Password Vault (“Cyberark”) adalah perangkat lunak berupa sistem manajemen akses yang digunakan untuk mengatur User ID yang memiliki hak istimewa atau User ID yang memiliki keistimewaan sebagai administrator. 6. SAP Governance Risk Control (“GRC”) adalah sarana (tool) berupa sistem manajemen akses yang digunakan untuk membantu pengelolaan dan kontrol akses Super User ID pada aplikasi sistem SAP.

Gilbert Viernes Digitally signed by Gilbert Viernes Date: 2022.08.08 10:53:12 +07'00'


Page 7

Policy No. GIT-P-B002 PRIVILEGED ACCOUNTS POLICY Group IT Policy and Governance

Date Issued 15th August 2022 GCC - Program and Governance

Effective Date 15th August 2022 Classification IT Revision No. -- Page 7 of 12 GUIDELINES

A. PROVISION OF PRIVILEGED ACCOUNT USAGE 1. Master Super User ID a. It will only be used if the required system maintenance activities cannot be performed using Emergency and Operational Super User ID. b. For certain systems such as SAP, after performing a change process which directly in the Production server, it shall be synchronized/transported from server of Development  Quality Assurance  Production. c. All performed activities are logged to be reviewed by IT Internal Audit. 2. Emergency Super User ID a. Used to solve problems for emergency/critical conditions and require immediate improvement action directly on the Production server.

b. The use of Emergency Super User ID shall be substantiated by an emergency ticket/issue. c. For certain systems such as SAP, after performing a change process which directly in the Production server, it shall be synchronized/transported from server of Development  Quality Assurance  Production. KEBIJAKAN

A. KETENTUAN PENGGUNAAN AKUN ISTIMEWA 1. Super User ID Master a. Hanya akan digunakan apabila aktivitas pemeliharaan sistem yang diperlukan tidak dapat dilakukan menggunakan Super User ID Emergency dan Operational. b. Untuk sistem tertentu seperti SAP, setelah perubahan yang dilakukan secara langsung di server Production, wajib melakukan proses sinkronisasi/transport dari server
Development  Quality Assurance  Production. c. Seluruh aktivitas yang dilakukan terdokumentasi untuk diperiksa oleh IT Internal Audit. 2. Super User ID Emergency a. Digunakan untuk menyelesaikan masalah untuk kondisi yang darurat/kritis dan membutuhkan tindakan perbaikan secepatnya secara langsung di server Production. b. Penggunaan Super User ID Emergency wajib dilengkapi dengan tiket/permasalahan darurat. c. Untuk sistem tertentu seperti SAP, setelah perubahan secara langsung di server Production selesai dilakukan, wajib melakukan proses sinkronisasi/transport dari server
Development  Quality Assurance  Production. Gilbert Viernes Digitally signed by Gilbert Viernes Date: 2022.08.08 10:53:32 +07'00'


Page 8

Policy No. GIT-P-B002 PRIVILEGED ACCOUNTS POLICY Group IT Policy and Governance

Date Issued 15th August 2022 GCC - Program and Governance

Effective Date 15th August 2022 Classification IT Revision No. -- Page 8 of 12 d. All performed activities are logged to be reviewed by IT Internal Audit. 3. Operational Super User ID a. Used for daily business activities such as providing daily support, working on Change Requests and activities related to business projects which are not in an emergency/critical situation. b. The use of Operational Super User ID shall be substantiated by a ticket, number of change request or project. c. The use of Operational Super User ID is not allowed to make changes which are required a transport process on the server of Development  Quality Assurance  Production. 4. IT Group’s Head of MDM, Policy Compliance and Authorization shall ensure that Super User ID and all activities related to authorization are in accordance with this policy.

d. Seluruh aktivitas yang dilakukan terdokumentasi untuk diperiksa oleh IT Internal Audit. 3. Super User ID Operational
a. Digunakan untuk aktivitas bisnis sehari-hari seperti untuk memberikan support harian, mengerjakan permintaan perubahan (Change Request) dan aktivitas yang berhubungan dengan proyek bisnis yang bukan dalam keadaan darurat/kritis. b. Penggunaan Super User ID Operational wajib dilengkapi dengan tiket, nomor permintaan perubahan (Change Request) atau proyek. c. Penggunaan Super User ID Operational tidak diperbolehkan untuk melakukan perubahan yang memerlukan proses transport pada server Development  Quality Assurance  Production. 4. IT Group’s Head of MDM, Policy Compliance and Authorization wajib memastikan bahwa Super User ID dan seluruh kegiatan yang berhubungan dengan otorisasi sesuai dengan yang diatur didalam kebijakan ini.

Gilbert Viernes Digitally signed by Gilbert Viernes Date: 2022.08.08 10:58:58 +07'00'


Page 9

Policy No. GIT-P-B002 PRIVILEGED ACCOUNTS POLICY Group IT Policy and Governance

Date Issued 15th August 2022 GCC - Program and Governance

Effective Date 15th August 2022 Classification IT Revision No. -- Page 9 of 12 B. APPROVAL OF PRIVILEGED ACCOUNT USAGE ON CRITICAL SYSTEMS B. PERSETUJUAN PENGGUNAAN AKUN ISTIMEWA PADA SISTEM KRITIKAL 1. Approval Matrix for Critical System Access Managed by Access Management System Super User ID Authorization Approver SAP Systems Non-SAP Systems

(Microsoft Office 365, Microsoft Windows Domain / Active Directory, Microsoft Outlook Server, Weighbridge, and Backup Servers) Networking Systems

(Firewalls and Core Switches) Master Head of Group Controllership and Compliance and Head of IT Apps Head of Group Controllership and Compliance and Head of IT Infrastructure/Head of IT Digital Delivery Emergency Head of IT Apps Head of IT Infrastructure/Head of IT Digital Delivery Operational Support/CR IT Head of related module Support/CR Head of Site IT/ Head of IT Digital Delivery Project Head of IT Apps Project Head of Data Center Operation/Head of Network Operation/ Head of IT Digital Delivery Basis Head of IT Apps *) Persetujuan disesuaikan berdasarkan aplikasi/sistem yang dikelola oleh IT Infra/IT Digital. Approval is adjusted based on the applications/systems which are managed by IT Infra/IT Digital. 2. Approval Matrix for Critical System Access Which Not Managed by Access Management System Super User ID Authorization Approver Master
Head of Group Controllership and Compliance and Head of IT Apps Operational Support Head of IT Apps CR Project

Gilbert Viernes Digitally signed by Gilbert Viernes Date: 2022.08.08 10:59:20 +07'00'


Page 10

Policy No. GIT-P-B002 PRIVILEGED ACCOUNTS POLICY Group IT Policy and Governance

Date Issued 15th August 2022 GCC - Program and Governance

Effective Date 15th August 2022 Classification IT Revision No. -- Page 10 of 12 C. PROVISION FOR CRITICAL SYSTEM ACCESS USING SUPER USER ID 1. Provisions for Critical System access using Super User ID which go through an access management system (such as Cyberark and GRC), as follows: a.1. All granted Super User IDs requests are registered to the Requestor’s NIK ID. a.2. A request of Super User ID usage shall be submitted through an access management system. a.3. The reason for requesting a Super User ID usage is a mandatory requirement. a.4. The approvals matrix for the Super User ID usage request are set in this policy (section B, point 1).
a.5. A notification email will be sent to the Requestor after the usage request of Super User ID is approved by the authorized officers. a.6. NIK ID of the approver, time and date stamp will be logged by the access management system. a.7. Every action or activity based on the User’s NIK ID from usage request, approval process until the activities performed by the Requestor are logged in the access management system.

C. KETENTUAN AKSES SISTEM KRITIKAL MENGGUNAKAN SUPER USER ID 1. Ketentuan untuk akses Sistem Kritikal menggunakan Super User ID yang dilakukan melalui sistem manajemen akses (seperti Cyberark and GRC), sebagai berikut: a.1. Semua permintaan Super User ID yang diberikan didaftarkan menggunakan NIK ID Pemohon. a.2. Permintaan penggunaan Super User ID wajib diajukan melalui sistem manajemen akses. a.3. Alasan permintaan atas penggunaan Super User ID wajib dicantumkan. a.4. Matriks persetujuan untuk penggunaan Super User ID telah diatur di dalam kebijakan ini (bagian B, butir 1). a.5. Email notifikasi akan dikirimkan kepada Pemohon setelah permintaan penggunaan Super User ID disetujui oleh pejabat berwenang. a.6. NIK ID pemberi persetujuan, waktu serta tanggal akan terdokumentasi di dalam sistem manajemen akses. a.7. Setiap aktivitas berdasarkan NIK ID pengguna mulai dari permintaan penggunaan, proses persetujuan hingga aktivitas yang dilakukan oleh Pemohon terdokumentasi di dalam sistem manajemen akses.

Gilbert Viernes Digitally signed by Gilbert Viernes Date: 2022.08.08 10:59:49 +07'00'


Page 11

Policy No. GIT-P-B002 PRIVILEGED ACCOUNTS POLICY Group IT Policy and Governance

Date Issued 15th August 2022 GCC - Program and Governance

Effective Date 15th August 2022 Classification IT Revision No. -- Page 11 of 12 2. Provisions of Critical Systems access which are not managed by access management system, as follows: a. Only available for using Master Super User ID and Operational Super User ID. b. A request of Master Super User ID and Operational Super User ID usage shall be submitted manually via email to the authorized officers (refers to section B, point 2) for approval process which in detail will be separatelly regulated in GIT-SOP-B002-50 Super User ID Procedure. c. Especially for Operational Super User ID usage, after being approved, IT Admin will manually assign the access to the related Requestor’s User ID with the specific time period.

  1. Ketentuan akses Sistem Kritikal yang tidak dikelola melalui sistem manajemen akses, sebagai berikut: a. Hanya dapat menggunakan Super User ID Master dan Super User ID Operational. b. Permintaan penggunaan Super User ID Master dan Super User ID Operational wajib diajukan secara manual melalui email kepada pejabat berwenang (mengacu pada bagian B, poin 2) sebagai proses persetujuan yang secara detail diatur terpisah di dalam GIT-SOP-B002-50 Super User ID Procedure. c. Khusus pada penggunaan Super User ID Operational, setelah mendapatkan persetujuan, IT Admin akan memberikan akses secara manual pada User ID Pemohon dengan periode waktu tertentu.

Gilbert Viernes Digitally signed by Gilbert Viernes Date: 2022.08.08 11:00:22 +07'00'


Page 12

Policy No. GIT-P-B002 PRIVILEGED ACCOUNTS POLICY Group IT Policy and Governance

Date Issued 15th August 2022 GCC - Program and Governance

Effective Date 15th August 2022 Classification IT Revision No. -- Page 12 of 12 REFERENCE  GIT-STD-B001-01 Password Rules Standard.
 GIT-SOP-B002-50 Super User ID Procedure.  GIT-P-B001 User ID and Password Policy for IT Controlled Applications.  GIT-STD-B002-02 Critical System Definition.  GIT-SOP-B002-51 Cyberark Dual Control Procedure.

REFERENSI  GIT-STD-B001-01 Password Rules Standard.  GIT-SOP-B002-50 Super User ID Procedure.  GIT-P-B001 User ID and Password Policy for IT Controlled Applications.
 GIT-STD-B002-02 Critical System Definition.
 GIT-SOP-B002-51 Cyberark Dual Control Procedure.