GIT-STD-B002-02 Critical System Definition¶
自动提取自PDF
Page 1¶
GIT-STD-B002-02 CRITICAL SYSTEMS DEFINITION
REVISION HISTORY
DATE REVISION CONTENTS RATIONALE APPROVED BY 01st July 2022 -- New Standard Release Chief Information Officer
STANDARD 2022
Page 2¶
Procedure No.
GIT-STD-B002-02
CRITICAL
SYSTEMS
DEFINITION
Revision No.
--
Date Issued
01st July 2022
Classification
IT
Effective Date
01st July 2022
Page
2 of 6
APPROVAL
Khoo Kok Yeow Chief Information Officer
Kok Yeow Digitally signed by Kok Yeow Date: 2022.07.04 16:43:08 +07'00'
Page 3¶
Procedure No.
GIT-STD-B002-02
CRITICAL
SYSTEMS
DEFINITION
Revision No.
--
Date Issued
01st July 2022
Classification
IT
Effective Date
01st July 2022
Page
3 of 6
TABLE OF CONTENTS
MAIN POLICY ........................................................................................................................................... 4 PURPOSE ................................................................................................................................................. 4 DEFINITION .............................................................................................................................................. 4 REGULATION ........................................................................................................................................... 5
Page 4¶
Procedure No.
GIT-STD-B002-02
CRITICAL
SYSTEMS
DEFINITION
Revision No.
--
Date Issued
01st July 2022
Classification
IT
Effective Date
01st July 2022
Page
4 of 6
MAIN POLICY GIT-P-B002 Privileged Accounts Policy
KEBIJAKAN UTAMA GIT-P-B002 Kebijakan Akun Istimewa (Privileged)
PURPOSE To provide the definition, and list of systems deemed critical (“Critical Systems”) for which the Privileged Accounts need to be secured and handled with extra attention.
TUJUAN Untuk memberikan definisi, daftar sistem yang dianggap kritis (“Critical System”) dimana akun Istimewa (Privileged) perlu diamankan dan ditangani dengan perhatian khusus. DEFINITION Definition of critical system is as follows: a. All production systems located in the central data center which are managed by the Group IT Infrastructure team that is used by Business Users in carrying out daily business operations so that the company's business can run well, where if the system experiences problems or failures, the company can suffer financial and productivity losses;
b. Contains confidential Company information (financial data, intellectual property, employee, customer/vendor information).
DEFINISI Definisi critical system adalah sebagai berikut: a. Semua sistem produksi di dalam pusat da- ta center yang dikelola oleh tim Group IT Infrasturtuce yang digunakan oleh Bisnis User dalam menjalankan operasi bisnis sehari-hari agar bisnis perusahaan dapat berjalan dengan baik, dimana bila system tersebut mengalami kendala atau kegagalan, maka perusahaan dapat mengalami kerugian secara finansial maupun produktivitas; b. Berisi informasi rahasia perusahaan (data keuangan, kekayaan intelektual, karyawan, informasi customer/vendor).
Page 5¶
Procedure No.
GIT-STD-B002-02
CRITICAL
SYSTEMS
DEFINITION
Revision No.
--
Date Issued
01st July 2022
Classification
IT
Effective Date
01st July 2022
Page
5 of 6
REGULATION List of Critical Systems and their Privileged Account Management Systems
PENGATURAN Daftar Sistem Kritis dan Sistem Manajemen Akun Istimewa Group IT Critical Systems Access Management System Non-Access Management System No. Category & System Name GRC Cyberark 1 SAP
a. AMS (Audit Management System)
b. BI/BW (Business Intelligence/Information Warehouse)
c. BPC (Business Planning and Consolidation)
d. CLM (Contract Lifecycle Management)
e. CRM (Contract Relationship Management)
f. GRC (Governance, Risk and Compliance)
g. HCM (Human Capital Management)
h. MDG (Master Data Governance)
i. SAP ECC
j. SAP SRM (Customer Relationship Manage- ment)
k. SAP LC 2 Non-SAP Systems a. Microsoft Office 365 b. Microsoft Windows Domain/Active Directory c. Microsoft Outlook Server d. Weighbridge e. Backup Servers f. Remedy g. Open Link h. Open Text i. Agiblocks j. eFACT (Electronic Field Activity Capture & Traceability) k. ProInt l. Workday m. Vmware Horizon and Smart Connect n. Cyberark o. SmartForm KUBE p. CXC q. Robotic Process Automation r. Land Transport System s. B2B Cash Flow t. Bonded Area Document System (BASYS) u. Online Daily Cash (ODC) v. Jetty Information Management System (JIMS) w. MPP Budget (Budget Payroll)
Page 6¶
Procedure No.
GIT-STD-B002-02
CRITICAL
SYSTEMS
DEFINITION
Revision No.
--
Date Issued
01st July 2022
Classification
IT
Effective Date
01st July 2022
Page
6 of 6
Group IT Critical Systems Access Management System Non-Access Management System No. Category & System Name GRC Cyberark 3 Networking Systems a. Firewalls b. Core Switches