跳转至

GIT-P-B009 Non Employee Access to Companys Network Policy (May 2022)

自动提取自PDF


Page 1

GIT-P-B009 NON-EMPLOYEE ACCESS TO COMPANY’S NETWORK / IT SYSTEMS POLICY

REVISION HISTORY

DATE REVISION CONTENTS RATIONALE APPROVED BY 31st July 2018 -- New Policy Release Group Audit & Compliance, Chief Information Officer 25th May 2022 1. Revise approval for access in accordance with IT Standard No. GIT-STD-B001-02 “User Management Approval Matrix Standard”. 2. Revise the word of Sponsor to be Requester as a person who is responsible to request non-employee access and to inform/notify the Group IT Infrastructure to terminate the access if no longer used.
To align to the standard approval Group Controllership and Compliance, Chief Information Officer

POLICY 2022


Page 2

Policy No. GIT-P-B009 NON-EMPLOYEE ACCESS TO COMPANY’S NETWORK / IT SYSTEMS POLICY Group IT Policy &
Governance

Date Issued 25th May 2022 GCC-Process and Governance

Effective Date 25th May 2022 Classification IT Revision No. 1 Page 2 of 8

APPROVALS

Pedy Harianto Group Controllership and Compliance

Khoo Kok Yeow Chief Information Officer

DOCUMENT CONTROL PROCESS OWNER Group IT Applications REVIEWED BY GCC-Process and Governance DOCUMENT OWNER Group IT Policy and Governance

Kok Yeow Digitally signed by Kok Yeow Date: 2022.05.13 11:45:46 +07'00' Pedy Harianto Digitally signed by Pedy Harianto Date: 2022.05.19 03:54:25 +07'00'


Page 3

Policy No. GIT-P-B009 NON-EMPLOYEE ACCESS TO COMPANY’S NETWORK / IT SYSTEMS POLICY Group IT Policy &
Governance

Date Issued 25th May 2022 GCC-Process and Governance

Effective Date 25th May 2022 Classification IT Revision No. 1 Page 3 of 8

TABLE OF CONTENTS PURPOSE ................................................................................................................................................. 4 SCOPE ...................................................................................................................................................... 4 DEFINITION .............................................................................................................................................. 4 GUIDELINES ............................................................................................................................................. 6 APPENDIX ................................................................................................................................................ 8 REFERENCE ............................................................................................................................................ 8


Page 4

Policy No. GIT-P-B009 NON-EMPLOYEE ACCESS TO COMPANY’S NETWORK / IT SYSTEMS POLICY Group IT Policy &
Governance

Date Issued 25th May 2022 GCC-Process and Governance

Effective Date 25th May 2022 Classification IT Revision No. 1 Page 4 of 8

PURPOSE This policy provides guidelines in granting non- employees of Sinar Mas Agribusiness and Food ("Sinar Mas"), access to its network / IT systems from within the premises or remotely, to ensure that the information stored in the network / IT systems remain secured and the environment is protected from external risks. TUJUAN Kebijakan ini berfungsi sebagai pedoman bagi non-karyawan Sinar Mas Agribusiness and Food (”Sinar Mas”) yang membutuhkan akses ke jaringan / sistem IT baik dari dalam lokasi Perusahaan maupun secara jarak jauh, untuk memastikan bahwa informasi yang tersimpan di dalam jaringan / sistem IT tetap aman dan terlindungi dari risiko eksternal.

SCOPE This policy applies to all non-employees of Sinar Mas, who wish to access the Company’s network / IT systems.

RUANG LINGKUP Kebijakan ini berlaku untuk semua non- karyawan Sinar Mas, yang ingin mengakses jaringan / sistem IT Perusahaan.

DEFINITION

  1. Network refers to Sinar Mas’ network which encompasses the office network and the data center network.

  2. Requester refers to Sinar Mas’ employee who is responsible for a non-employee’s request to access Sinar Mas network / IT systems.

  3. Virtual Private Network (“VPN”) refers to the technology used to secure the connection between the external party’s network and Sinar Mas’ network.

  4. Remote Desktop Protocol (“RDP”) jump server refers to the server on Sinar Mas’ network which allows external parties to connect for using the Microsoft RDP protocol. This server functions as a single gateway into Sinar Mas’ network for external parties and is meant to ensure that the rest of Sinar Mas’ IT systems are ‘air gapped’ from viruses, malware and theft of information via copy/paste and file transfers.

DEFINISI

  1. Jaringan mengacu kepada jaringan Sinar Mas yang meliputi jaringan kantor dan jaringan data center.

  2. Pemohon mengacu kepada karyawan Sinar Mas yang bertanggung jawab atas permintaan dari non-karyawan untuk mengakses jaringan / sistem IT Sinar Mas.

  3. Virtual Private Network (”VPN”) mengacu kepada teknologi yang digunakan untuk mengamankan koneksi antara jaringan pihak eksternal dan jaringan Sinar Mas.

  4. Remote Desktop Protocol (”RDP”) jump server mengacu kepada server yang berada dalam jaringan Sinar Mas yang memungkinkan pihak eksternal untuk terhubung dengan menggunakan protokol RDP Microsoft. Server ini berfungsi sebagai gateway tunggal ke dalam jaringan Sinar Mas untuk pihak eksternal dan bertujuan untuk memastikan bahwa sistem IT Sinar Mas lainnya terlindungi dari virus, malware dan pencurian informasi melalui copy/paste


Page 5

Policy No. GIT-P-B009 NON-EMPLOYEE ACCESS TO COMPANY’S NETWORK / IT SYSTEMS POLICY Group IT Policy &
Governance

Date Issued 25th May 2022 GCC-Process and Governance

Effective Date 25th May 2022 Classification IT Revision No. 1 Page 5 of 8

  1. Production system refers to the IT systems that hold production/real data, i.e for a typical IT system such as SAP ERP, which consists of development, test and production; the production system is usually the only system which holds real information. Development and test instances do not hold production/real financial or customer data. dan pemindahan file.

  2. Production system mengacu kepada sistem IT yang menyimpan data production/ data yang sesungguhnya (real), contohnya untuk sistem IT tertentu seperti SAP ERP, yang terdiri dari tahap pengembangan, pengujian dan production; production system pada umumnya adalah satu-satunya sistem yang menyimpan informasi yang sesungguhnya. Klien pengembangan dan pengujian tidak menyimpan data-data keuangan atau pelanggan yang sesungguhnya.


Page 6

Policy No. GIT-P-B009 NON-EMPLOYEE ACCESS TO COMPANY’S NETWORK / IT SYSTEMS POLICY Group IT Policy &
Governance

Date Issued 25th May 2022 GCC-Process and Governance

Effective Date 25th May 2022 Classification IT Revision No. 1 Page 6 of 8

GUIDELINES 1. All access to Company’s network / IT systems by non-employees of Sinar Mas, must be via VPN and Sinar Mas’ RDP jump server. Direct access to any of Company’s network / IT systems is NOT allowed.

  1. Request to access Sinar Mas' network / IT systems must be submitted by the Requester in accordance with the User Management Approval Matrix Standard No. GIT-STD- B001-02.
  2. The duration of access granted is deter- mined on a case-to-case basis, with a maxi- mum of three (3) months. In the event that an extension is required, a request must be submitted in accordance with Guideline No.2. When this non-employee’s access is no longer required prior to the expiration of the access, the Requester shall notify / in- form Group IT Infrastructure to terminate the access.

Approved VPN access shall be monitored by Group IT Infrastructure and access will be terminated for any non-usage of the granted ID for consecutive of two (2) weeks.

  1. Any transfer of files to/ from Sinar Mas' net- work / IT systems by non-employees of Sinar Mas, must be approved by the Head of Group IT Infrastructure.

  2. All non-employees of Sinar Mas wishing to access Sinar Mas' network / IT system must exhibit to Group IT Infrastructure, that the devices used, meet the following criteria:

a) Up-to-date antivirus software from a rep- utable vendor such as McAfee, Syman- tec, Kaspersky, TrendMicro, and;

KEBIJAKAN

  1. Semua akses ke jaringan / sistem IT Perusahaan oleh non-karyawan Sinar Mas harus melalui VPN dan RDP jump server Sinar Mas. Akses langsung ke jaringan / sistem IT Perusahaan TIDAK diperkenankan.

  2. Permintaan untuk akses jaringan / sistem IT Sinar Mas harus diajukan oleh Pemohon sesuai dengan ”User Management Approval Matrix Standard” GIT-STD-B001-02.

  3. Durasi akses yang diberikan ditentukan kasus-per-kasus, maksimum tiga (3) bulan. Dalam hal diperlukannya perpanjangan, permintaan harus diajukan sesuai dengan Kebijakan No.2. Jika akses non-karyawan sudah tidak diperlukan lagi sebelum habis masa berlakunya, Pemohon harus memberitahukan / menginformasikan Group IT Infrastructure untuk menghentikan akses tersebut.

Akses VPN yang telah disetujui harus dimonitor oleh Group IT Infrastructure dan akses tersebut akan dihentikan jika ID terkait tidak digunakan selama dua (2) minggu berturut-turut.

  1. Setiap pemindahan file ke / dari jaringan / sistem IT Sinar Mas oleh non-karyawan Sinar Mas, harus disetujui oleh Head of Group IT Infrastructure.
  2. Semua non-karyawan Sinar Mas yang hendak mengakses jaringan / sistem IT Sinar Mas harus menunjukkan kepada Group IT Infrastructure, bahwa perangkat yang digunakan memenuhi kriteria berikut:

a) Perangkat lunak antivirus terkini dari vendor terkemuka seperti McAfee, Symantec, Kaspersky, TrendMicro, dan;


Page 7

Policy No. GIT-P-B009 NON-EMPLOYEE ACCESS TO COMPANY’S NETWORK / IT SYSTEMS POLICY Group IT Policy &
Governance

Date Issued 25th May 2022 GCC-Process and Governance

Effective Date 25th May 2022 Classification IT Revision No. 1 Page 7 of 8

b) Up-to-date operating system patches.

  1. Head of Group IT Infrastructure reserves the right to reject any requests which he/ she deems risky to the organization.

  2. Non-employees of Sinar Mas shall NOT be granted access to any of Sinar Mas’ produc- tion systems. Access is only allowed to de- velopment and test instances which do NOT hold real financial / customer data.

  3. Any exception to this policy can be requested to the Head of Group IT Infrastructure with an approval by at least the Vice President (level 19–21) together with the Senior Vice President (level 22–23) of the relevant department. The exception list should be reported to the relevant Executive Vice President (level 24-26) every end of each quarter, by the Head of Group IT Infrastructure. b) Patch sistem operasi terbaru.

  4. Head of Group IT Infrastructure memiliki hak untuk menolak setiap permintaan yang dianggap berisiko bagi organisasi.

  5. Non-karyawan Sinar Mas TIDAK akan diberikan akses ke sistem production Sinar Mas mana pun. Akses hanya diperkenankan untuk klien pengembangan dan pengujian, yang mana TIDAK menyimpan data-data keuangan/ pelanggan yang sesungguhnya.

  6. Pengecualian dari kebijakan ini dapat diajukan ke Head of Group IT Infrastructure setelah mendapatkan persetujuan minimal setingkat Vice President (level 19–21) beserta Senior Vice President (level 22–23) dari departemen terkait. Daftar atas pengecualian ini dilaporkan kepada Executive Vice President terkait (level 24– 26) setiap akhir kuartal, oleh Head of Group IT Infrastructure.


Page 8

Policy No. GIT-P-B009 NON-EMPLOYEE ACCESS TO COMPANY’S NETWORK / IT SYSTEMS POLICY Group IT Policy &
Governance

Date Issued 25th May 2022 GCC-Process and Governance

Effective Date 25th May 2022 Classification IT Revision No. 1 Page 8 of 8

APPENDIX N/A

LAMPIRAN N/A

REFERENCE User Management Approval Matrix Standard No. GIT-STD-B001-02. REFERENSI User Management Approval Matrix Standard No. GIT-STD-B001-02.