跳转至

GIT-STD-B002-02 Critical System Definition

自动提取自PDF


Page 1

GIT-STD-B002-02 CRITICAL SYSTEMS DEFINITION

REVISION HISTORY

DATE REVISION CONTENTS RATIONALE APPROVED BY 01st July 2022 -- New Standard Release Chief Information Officer

STANDARD 2022


Page 2

Procedure No. GIT-STD-B002-02 CRITICAL
SYSTEMS DEFINITION Revision No. -- Date Issued 01st July 2022 Classification IT Effective Date 01st July 2022 Page 2 of 6

APPROVAL

Khoo Kok Yeow Chief Information Officer

Kok Yeow Digitally signed by Kok Yeow Date: 2022.07.04 16:43:08 +07'00'


Page 3

Procedure No. GIT-STD-B002-02 CRITICAL
SYSTEMS DEFINITION Revision No. -- Date Issued 01st July 2022 Classification IT Effective Date 01st July 2022 Page 3 of 6

TABLE OF CONTENTS

MAIN POLICY ........................................................................................................................................... 4 PURPOSE ................................................................................................................................................. 4 DEFINITION .............................................................................................................................................. 4 REGULATION ........................................................................................................................................... 5


Page 4

Procedure No. GIT-STD-B002-02 CRITICAL
SYSTEMS DEFINITION Revision No. -- Date Issued 01st July 2022 Classification IT Effective Date 01st July 2022 Page 4 of 6

MAIN POLICY GIT-P-B002 Privileged Accounts Policy

KEBIJAKAN UTAMA GIT-P-B002 Kebijakan Akun Istimewa (Privileged)

PURPOSE To provide the definition, and list of systems deemed critical (“Critical Systems”) for which the Privileged Accounts need to be secured and handled with extra attention.

TUJUAN Untuk memberikan definisi, daftar sistem yang dianggap kritis (“Critical System”) dimana akun Istimewa (Privileged) perlu diamankan dan ditangani dengan perhatian khusus. DEFINITION Definition of critical system is as follows: a. All production systems located in the central data center which are managed by the Group IT Infrastructure team that is used by Business Users in carrying out daily business operations so that the company's business can run well, where if the system experiences problems or failures, the company can suffer financial and productivity losses;

b. Contains confidential Company information (financial data, intellectual property, employee, customer/vendor information).

DEFINISI Definisi critical system adalah sebagai berikut: a. Semua sistem produksi di dalam pusat da- ta center yang dikelola oleh tim Group IT Infrasturtuce yang digunakan oleh Bisnis User dalam menjalankan operasi bisnis sehari-hari agar bisnis perusahaan dapat berjalan dengan baik, dimana bila system tersebut mengalami kendala atau kegagalan, maka perusahaan dapat mengalami kerugian secara finansial maupun produktivitas; b. Berisi informasi rahasia perusahaan (data keuangan, kekayaan intelektual, karyawan, informasi customer/vendor).


Page 5

Procedure No. GIT-STD-B002-02 CRITICAL
SYSTEMS DEFINITION Revision No. -- Date Issued 01st July 2022 Classification IT Effective Date 01st July 2022 Page 5 of 6

REGULATION List of Critical Systems and their Privileged Account Management Systems

PENGATURAN Daftar Sistem Kritis dan Sistem Manajemen Akun Istimewa Group IT Critical Systems Access Management System Non-Access Management System No. Category & System Name GRC Cyberark 1 SAP   

a. AMS (Audit Management System)   

b. BI/BW (Business Intelligence/Information Warehouse)   

c. BPC (Business Planning and Consolidation)   

d. CLM (Contract Lifecycle Management)   

e. CRM (Contract Relationship Management)   

f. GRC (Governance, Risk and Compliance)   

g. HCM (Human Capital Management)   

h. MDG (Master Data Governance)   

i. SAP ECC   

j. SAP SRM (Customer Relationship Manage- ment)   

k. SAP LC    2 Non-SAP Systems  a. Microsoft Office 365   b. Microsoft Windows Domain/Active Directory   c. Microsoft Outlook Server   d. Weighbridge  e. Backup Servers    f. Remedy    g. Open Link    h. Open Text    i. Agiblocks    j. eFACT (Electronic Field Activity Capture & Traceability)    k. ProInt    l. Workday    m. Vmware Horizon and Smart Connect    n. Cyberark    o. SmartForm KUBE    p. CXC    q. Robotic Process Automation    r. Land Transport System    s. B2B Cash Flow    t. Bonded Area Document System (BASYS)    u. Online Daily Cash (ODC)    v. Jetty Information Management System (JIMS)    w. MPP Budget (Budget Payroll)   


Page 6

Procedure No. GIT-STD-B002-02 CRITICAL
SYSTEMS DEFINITION Revision No. -- Date Issued 01st July 2022 Classification IT Effective Date 01st July 2022 Page 6 of 6

Group IT Critical Systems Access Management System Non-Access Management System No. Category & System Name GRC Cyberark 3 Networking Systems    a. Firewalls   b. Core Switches   