Corporate IT frameworks, access controls, network boundaries, and general security posture settings.
INFORMATION SYSTEM POLICY
Policy Overview
| Field | Details |
| Reference No. | DJTMPL/IT/POL/ISP |
| Document Name | Information System Policy |
| Policy Owner | Chief Operation Officer |
| Policy Approving Authority | Board Of Directors |
| Version No. | 2.0 |
| Document Status | Definitive |
| Issue Date | 01-04-2026 |
| Compliance Status | Mandatory |
| Next Review Period | One year from the date of release or earlier if required |
| Security Classification | Internal Use Only |
| Distribution | DJTMPL |
Document Revision History
| Version | Release Date | Change Description |
| 1.0 | 01-06-2024 | First version |
| 2.0 | 01-04-2026 | Second version |
Table Of Contents
| S. No | Particulars |
| 1 | Introduction |
| 2 | Information Systems Security Policy Document |
| 3 | Information Systems Security Policy Document Framework |
| 4 | Information Systems Security Set Up |
| 5 | Information Systems Security Policy Exception |
| 6 | Physical Security |
| 7 | Separate Development and Production Environment |
| 8 | Source Code Management |
| 9 | Security in Application Systems |
1. Introduction
DJTMPL information systems, and the information and data they contain, are fundamental for its daily operations and effective service provision. DJTMPL shall implement procedures and controls at all levels to protect the confidentiality and integrity of information stored and processed on its systems and shall ensure that information is available to authorized persons when required.
1.1 Information Systems Policy Document
This document provides the framework to ensure the protection of DJTMPL information assets, and to allow the use, access and disclosure of such information in accordance with appropriate standards, laws and regulations.
All existing policies related to personnel, administration, protection of confidential information, and other areas would apply equally to the information systems environment.
1.2 Information Systems Policy and Procedure ('ISPP') Coverage
The security policies and standards contained in this document have been established to cover information, data, software, hardware and networks used by DJTMPL and its group entities, globally.
This security policy applies to all persons (employees, Administrator/ In-charge, users, auditors, contractors, consultants, third parties and others) who access information using the DJTMPL information systems.
1.3 Objectives of ISPP
The overall objective of the ISPP is to provide guidance and direction to DJTMPL Corp for the protection of its information systems against accidental or deliberate damage or destruction.
The specific objectives of the ISPP are:
- To prevent unauthorised disclosure of information stored or processed on DJTMPL information systems (CONFIDENTIALITY)
- To prevent the accidental or unauthorised deliberate alteration or deletion of information (INTEGRITY)
- To ensure that information is available to authorised persons whenever required (AVAILABILITY)
- To ensure the authenticity, accountability, non-repudiation and reliability of information
DJTMPL intends to honor privacy of personal information of employees as long as the same does not affect the work. However, DJTMPL reserves the right to audit and/ or monitor the personal information stored in information systems of DJTMPL. The policy will provide guidance to ensure that DJTMPL information systems comply with relevant laws and regulations like the Information Technology Act, guidelines/ circulars from Telecom Regulatory Authority of India ('TRAI'), industry good practices and international standards like ISO/IEC 27001:2005 on information security management.
1.4 Information Security Process
To achieve the objective of Information systems security policy, the following information security processes must be considered:
- Identification – the process of distinguishing one user from all others
- Authentication – the process of identifying the identity of the user
- Authorization and Access control – the means of establishing and enforcing rights and privileges allowed to users
- Administration – the functions required to establish, manage and maintain security
- Audit – Information Security Management Systems ('ISMS') audit shall be planned at regular intervals to determine whether the control objectives, controls, processes and procedures:
- Conform to requirements of legislation and regulations
- Are effectively implemented and maintained as per ISO/IEC 27001:2005 standard
1.5 Responsibility for Information Systems Security
All employees, external contractors, and other third parties (Internal & External auditors, concurrent auditors, consultants, etc) who require access to the DJTMPL information systems, are responsible for ensuring that information systems security policies are adhered to and they operate systems in such a manner, to ensure its security. The delegated authority to approve to add to the list of authorised users would be with Senior Manager - ISS.
Management at all levels is responsible for ensuring that staff are aware of, and adhere to, this policy and the standards there under.
The Senior Manager -ISS is responsible for facilitating and driving the overall information security requirements within DJTMPL. For effective governance and control, Senior Manager will be reporting directly to MD.
Senior Manager - ISS may involve other functional heads for their participation in training, updating the policy or implementation thereof like Administration Department, Operations Department, Finance Department, Human resources Department, Vigilance Department, Support Departments, etc.
IT team is responsible to ensure that following objectives are taken care for the key staff having special system privilege:
- Proper hand-over/ take-over formalities before the key staff having special privileges are transferred
- Smooth succession arrangements for timely implementation of new projects in the event of non-availability of key staff having special privileges due to retirement, resignation, suspension or cessation of employment due to other reasons
- Respective department Heads or immediate superior should report to IT, in the event of any changes due to retirement, resignation, etc of key staff having special privileges
1.6 Ethics in the field of security
The basis for all work with security consists of the shared ethical norms and attitudes relating to ownership and the respect for each other and each other's possessions that are shared at the work place.
It is ethical to:
- As an official, clarify prevailing rules
- As an employee, respect DJTMPL possessions, working hours, and resources, and make sure they are used correctly
- Protect sensitive information
It is unethical to:
- Actively study information one has gained access to by mistake
- Actively hide one's identity
- Authority or rights in excess of those granted
2. Information Systems Security Policy Document
2.1 Organization of the Policy Document
The Policy document is organised under the following sections:
- Information Systems Security Policy Framework
- Information System Security Set-up
- Information Systems Security Policy Exception
- Information Systems Security Policy Violation
- Information Security Policy Statements
2.2 Maintenance Procedures
Information Security policy revision shall be controlled as per the DJTMPL Document numbering system document.
3. Information Systems Security Policy Document Framework
3.1 Policy Statement
A security policy statement is an overall declaration of DJTMPL security expectations, which will allow effective utilisation of information systems to foster DJTMPL goals.
3.2 Procedure
Security procedures are derived from the policy statement and provide the overview of necessary actions to achieve the objectives of the policy statement.
3.3 Acceptable Use Guideline
Acceptable Use Guidelines are derived from the policy standards and are issued to employees and third parties as DJTMPL directives on information security. This part of Information Systems Security Policy should be circulated to all employees and third parties who are required to access DJTMPL information systems.
3.4 Level of Security to be Provided
The level of security required for information and information assets is dependent upon the business value of the information or the impact of the loss of assets to DJTMPL, the risks to which they are exposed and the extent to which they are affected by legal and regulatory requirements.
The standards provided in this document shall be implemented for all information systems used in DJTMPL. CISG of DJTMPL will review where existing systems do not comply with these standards; the risks associated with non-compliance and the expected life of the system, and determine what action is appropriate.
3.5 Independent Review of Information Security Implementation
The information security policy manual defines the policy and responsibilities for information security. Its implementation must be reviewed independently to provide assurance that the practices properly reflect the policy and that it is effective. The internal audit function, an independent officer or an external agency may carry out such a review on a continuous basis. A full-fledged review must be conducted at least once in a year by an independent audit function, whether internal or external.
4. Information Systems Security Set Up
4.1 Corporate Information Security Group
The Corporate Information Security Group ('CISG') would be headed by the Senior Manager - ISS and would provide support for design, development, implementation and maintenance of the Information Security Program for protecting DJTMPL information assets & technology infrastructure.
The senior manager will have the following responsibilities:
- Roll out & maintain Information Security Management Systems within DJTMPL
- Based on the requirements of an Information Security project, lead a team to implement and rollout projects
- In concurrence with the Information Security Management Forum and Internal Audit function, carry out audits of the security policy and security controls in place
- Provide advice to management on security issues
- Define and document security controls that need to be implemented on individual information systems
- Define and document metrics for measuring performance and adherence to standards
- Define and monitor the Incident Management Process
- Design & Review (on a periodic basis) Business Continuity Plan and Disaster Recovery Plans for various IT assets within DJTMPL
- Help in defining and conducting security training and awareness programs for users and specific groups from time to time
- Converting Process related Security Requirements Specifications into detailed security controls
The manager will have the following responsibilities:
The Manager-Infra shall be a part of the Information Security Management Forum. The manager will be entrusted with the responsibility of managing security related operations on a day-to-day basis and coordinating the activities of Corporate Information Security Group. He/ she will have the following responsibilities:
- Manage the overall Information Security program in DJTMPL
- Responsible for developing and maintaining the Information Security Policies, Procedures and Standards for use throughout DJTMPL
- Get involved at the planning stage for major IT initiatives for ensuring that security considerations are kept in mind
- Ensuring that all critical operations are carried out in accordance with the security guidelines
- Working with the business managers to ensure that an effective process for implementing and maintaining the security controls is in place
- Remain current/up-to-date on the threats against the information assets and align security initiatives with the same
- Review audit and examine reports dealing with the information security issues and ensure that they are submitted to the Information Security Forum at pre-determined intervals
- The manager should be involved in the formulation of the management's response to the audit findings and follow-up to ensure that the security controls and procedures, as required, are implemented within the stipulated time frame
- Is responsible for the coordination of any Incident Response procedures undertaken in response to the potential security breaches. Co-ordinate or assist in the investigation of security threats or other attacks on the information assets. Reporting security incidents and violations to the Information Security Management Forum
- Is responsible for preparation, maintenance, and testing of contingency plans or disaster recovery plans
- Is responsible for creating security awareness within DJTMPL
4.2 System Administrator
Technical Administrator / In-charge are responsible for the following:
- Implementing the policy and standards on workstations and networks
- Monitoring the security of systems and advising their immediate superiors about the security problems, as and when occurred
- Audit or remote login the user's desktop/ Laptop after prior information
- Recommending improvements to security, Security Policies and Standards to next higher authority
- Providing security advice to users
4.3 Asset Owners
Asset Owners shall be responsible for:
- Ensuring that the minimum security requirements are implemented as identified by the Asset custodian for all information systems and equipments under their control
- Determine access right processes for their applications and data
- Satisfying themselves that the applications and data under their control are being administered and operated in a secure fashion
- Software installed on their PC other than the business applications (e.g. SAP, MS Office etc.)
4.4 Asset Custodian
Asset Custodian shall be responsible for:
- Identifying minimum security required for all information systems and equipments under their control
- Performing Asset Classification based on sensitivity of Information Asset
- Ensuring that back-ups are taken as per the schedule and periodicity prescribed by the Asset Owner
4.5 Help Desk and Other Technical Support Staff
Help Desk and other technical support staff are responsible for the following in addition to approved customer support duties:
- Taking action only in accordance with Security Policies and Standards
- Providing advice to users on how to implement routine aspects of security
- Referring non-routine security matters to the next higher authority
4.6 Information Systems Users
Users (includes employees, trainees, third party staff, contractors, etc) are responsible for:
- Ensuring that they are aware of, and understand, the security procedures for the specific systems they use
- Taking all reasonable precautions to protect information systems against unauthorised access, use, disclosure, modification, duplication or destruction
- Using information systems only when required for their job responsibilities
- Using available mechanisms and procedures to protect their own data and data under their control
- Assisting and co-operating in the protection of the systems they use
- Complying with DJTMPL security policy
- Using the system only for its intended purpose
- Using information systems in a manner which ensures it is:
- Lawful, by obeying all laws relating to electronic activity, confidentiality, copyrights, licenses and contractual obligations
- Respectful, by using network access in a responsible and informed manner, conforming to network etiquette, customs and respect
- Responsible, by not abusing DJTMPL computer resources for non-work related activities
- Reporting security problems or issues to the relevant Departmental Head, Technical Administrator / In-charge, Help Desk as appropriate
5. Information Systems Security Policy Exception
5.1 Introduction
There may be instances where there is a justifiable business need to perform actions that are in conflict with DJTMPL Information Systems Security Policies, Procedures and Standards. DJTMPL recognises that policies cannot be created and enforced which address all business issues. In order to provide flexibility in such instances, this component of Information systems security policy framework should be referred to get details of actions that are required to obtain a waiver from compliance to a specific policy.
5.2 Standards
Any person, who identifies any exception to Information System Security Policies, that must occur in order to successfully complete business operations, must immediately inform his/ her immediate superior authority, as the case may be, who shall initiate immediate action that may be required to obtain a waiver from compliance to a security policy as per the Information System Security Policy Implementation/ Compliance hierarchy.
5.3 Procedure
- Requests for exceptions to policies must have a justifiable business case documented and associated risk should be identified with the necessary approvals. Exceptions must be approved and signed by the appropriate officials as decided by the Top Management. Once approved, exceptions to policy shall be valid for a pre-decided period after which it must be re-evaluated and re-approved
- If policy exceptions are likely to circumvent existing, internal controls then "Mitigating Controls" or "Compensating Controls" must be implemented and followed. The Information Systems Security committee must be involved in all instances where internal security controls are bypassed
5.4 Non-compliance of the Information Security Policy
Non-compliance to the minimum requirements or violation of this information systems security policy could result in action that may include, but is not limited to, the following:
- Suspension
- Termination
- Other disciplinary action
- Civil and/ or criminal prosecution
6. Physical Security
Statement
Access to information system facilities should be controlled to prevent unauthorised access, damage, and interference with information services. Physical access controls should be in place to deter unauthorised access to all critical systems, servers, databases and applications. This includes controls guarding against unauthorised access by external parties such as visitors, contractors or technicians who may have access to the premises.
Purpose and Objectives
Information processing facilities must be housed in secure areas. Such facilities must be physically protected from unauthorised access, damage and interference. Facilities to be protected include server and computer rooms, tape library, tapes, disks and all magnetic media, off-site backup file storage facility, communication closet, power sources and networks, etc. They must be located in secure areas and protected by a defined security perimeter with appropriate entry controls.
The Physical Security Policy defines the minimum standards, which should be followed to provide adequate physical safeguards to information processing facilities.
Procedure
- Server and Equipment Room
- Access to server and equipment rooms is controlled and restricted to authorised personnel who need access to perform their duties
- Authentication mechanisms (e.g. proximity cards, and/ or biometrics) are used for server and equipment rooms housing critical applications/ servers
- Closed circuit cameras are installed for monitoring movements of personnel around server rooms
- Server and Equipment rooms are equipped with doors, which are resistant to forcible entry
- Signs indicating "Authorised Personnel Only" or a similar message are prominently posted at all entrances to server and equipment rooms
- All server and equipment rooms are located in a secluded area, which is not visited by unauthorized personnel
- Mobile phones with cameras are not permitted in server room (Don't carry mobile phone or any USB drive while visiting server room)
- Visitors and Third Parties [Facilities management providers, vendors]
- Visitors and third parties are allowed entry to server and equipment rooms for authorized and specific purposes only
- Visitors and third parties are not permitted unsupervised access to server and equipment rooms. This arrangement excludes employees of outsourcing agencies who are responsible for owning or operating an information processing facility and they do it with proper identification valid for a specified period
- The date and time of entry and departure of visitors and third parties and the purpose of visit is recorded in a visitor's log
- The date and time of entry and departure and the purpose of entry of authorised personnel (including employees of outsourcing agencies) outside normal business hours or assigned hours of work is recorded in a log
- Camera (still or moving pictures) is not permitted within DJTMPL premises. Permission from authorised DJTMPL official is taken for any exceptional case
- Identification Badges
- Smart identification badges are used to restrict access of employees, visitors and third parties to the premises. Usage of the badges is logged at the various entry/ exit points. The log is reviewed by security incharge on a daily basis
- Access to various sites/ floor/ area within the premises is controlled based on the 'need to know' and 'need to access' basis
- All employees, visitors and third parties are required to wear visible identification badges within DJTMPL premises
- Visitors and third parties have to return badges to security personnel while moving out of the premises. Badges are returned to security personnel after obtaining signatures of DJTMPL officials visited by them
- Security personnel verifies the identification with the inward entry and accepts it before allowing the visitor to leave the premises
- Reconciliation of badges issued to visitors and third parties is done at the end of each day
- The employee badge access list is checked on a quarterly basis by manager -Infra to verify ongoing accuracy with the valid employees on company roll. Any discrepancies found are immediately corrected
- It is the responsibility of each employee or third-party personnel, who has been issued an identification badge to immediately report lost or stolen badges
- The original identification badge is taken back wherever possible (e.g. broken, damaged cards) while issuing a duplicate card
- Identification badges are returned by an employee, when retired or terminated, and by personnel of outsourcing agencies at the end of the contract
- Wireless Devices
- Wireless access point has the latest firmware installed to take advantage of more secure encryption mechanisms
- The SSID of wireless access point is changed from the default manufacturer set SSID
- Wireless access point is configured to prevent broadcasting its SSID
- The default administrator account password is changed so that no one can compromise the wireless access point
- WPA2 is enabled on access point with a passphrase having alphanumeric characters and special characters. If the wireless access point does not support WPA2, then WPA or WEP is enabled
- MAC address filtering is enabled to provide a "trusted" communication channel to wireless network
- Wireless network is switched off when not in use
- Router is placed in a physically secured location
- Wireless networks are regularly scanned for rogue or unknown access points
- Wireless LAN network do not directly connect to the wired LAN. The connection is made through a Firewall
7. Separate Development and Production Environment
Statement
Segregation of development (testing and quality) and production environment should be maintained.
Purpose and Objectives
Development and testing activities may result in unintended or unauthorized changes to software and data. Segregation of development and production environment should therefore be done to reduce the above risk.
Procedure
- General Standards
- Development and production software run on different computer processors or in different domains or directories
- Different logon procedures are used for development and production environment. Users are encouraged to use different passwords for these systems, and menus display appropriate identification messages
- Development staff do not have access to the production environment, unless there are specific business reasons with adequately documented authorization, where segregation is not possible
- Development does not have data from the live production system
- Programmers/ Software vendors do not carry out on-site modifications to programs/ applications in live environment without formal testing, approval and release of the suggested changes by appropriate authorities
Computer Virus / Worm Control
Policy Statement
All PCs, workstations, laptops, servers and other information processing equipment should be adequately protected against viruses/ worms.
Purpose and Objectives
Computer viruses / worms may affect the stability of a system and may cause damage or loss of valuable business information. Adequate protection from viruses / worms should be provided, as that would ensure that information, data and software are protected.
Procedure
- General Standards
- Latest version of anti-virus software is installed on all workstations, laptops and servers
- The anti-virus software is kept current by obtaining the latest updates from the anti-virus vendor and distributed promptly across the organisation
- Personal computers (e.g. laptops, workstations) is scanned daily for viruses either automatically from the centralised anti-virus server or manually by the users themselves. Bypassing of the in-built scanning process is strictly prohibited
- All removable disks are scanned before use
- Administrator/ In-charge runs anti-virus software on all network file servers on a daily basis
- All information or files downloaded from the Internet onto a workstation and all mail attachments are scanned for viruses before use
- Users are advised against using disks containing unauthorised data and programs from outside the organisation, unless duly authorized by the department Head
- If a virus attack is suspected, the following is observed:
- Suspect personal computer is disconnected immediately from the network. The computer is reconnected only after complete scanning and removal of virus
- The System Administrator/ CISO is immediately informed about the incident
- User starts scanning of system on virus attack before System Administrator comes on site
- System Administrator downloads alternate patches or virus removal tools, if required
- SA updates the status to IT team about new tool and virus, if any
- Senior Manager - ISS is responsible to spread awareness about latest threats and malware via mail or bulletin board
- Manager – Infra is responsible for securing the email system from viruses and spam. The SA filters incoming emails with necessary utilities and periodically updates virus signatures and patches
- Antivirus software is password protected and is not shared with any user
- All server level settings are locked, and a user cannot modify the settings locally
- Email Server Antivirus Policy
- The email server has additional protection against malware as email with malware must be prevented from entering the network
- The antivirus software scans all incoming and outgoing mails. If a virus or malware is found, the policy deletes that particular attachment from the email and sends notification to users
Email Use Policy
Statement
DJTMPL Internet systems should be used for official and authorised purposes only.
Purpose and Objectives
DJTMPL has an email system for all employees to facilitate better communication. However, the use of Internet email is fraught with risks to confidentiality and integrity of information. The purpose of Email Security Policy is to define necessary standards with respect to approved use of DJTMPL email system.
Procedure
- General
- Mass mailing is strictly prohibited, except in some special cases, where prior permission has been obtained from the MD (Creation of DL should be under administrator)
- Users do not make any alteration in their mail client settings/ mailbox settings/ access control list etc., without the proper knowledge or intimation or specific instruction from IT/IS
- Mail on mobile should be restricted and only allow after BUH approval
- Users are prohibited from sending 'Strictly Confidential'/ 'Confidential' classes of information or data via internal or Internet email, unless strong encryption or message authentication techniques are used
- Approved Use
- The email systems are intended for use in the conduct of DJTMPL business. All email messages are considered as DJTMPL records and there must be no expectation of personal privacy
- Incidental and occasional personal use of DJTMPL email system is permitted. However, information and messages stored in these systems are treated in the same manner as business-related information and messages
- Unauthorised Use
- Unauthorised use of email includes, but is not limited to:
- Transmitting or storing offensive material
- Compromising the security of information contained on DJTMPL computers
- Soliciting for political, personal, religious or charitable causes or other commercial ventures outside the scope of the user's employment and the user's responsibilities to DJTMPL
- 'Spamming': sending unsolicited messages, promotions, sending or forwarding chain letters
- 'Letter bombing': re-sending the same email repeatedly to one or more recipients
- Users are not to auto-forward their emails to any personal email ID
- Creating, sending, receiving or storing materials that infringe the copyright or other intellectual property right of any third parties
- Sending, transmitting or distributing proprietary information, data or other confidential DJTMPL information
- DJTMPL Access to Email Systems
- DJTMPL reserves the right to inspect and review any data maintained in its email system without prior consent of, or notification to, the employee
- DJTMPL discloses contents of email either internally or to external parties, where necessary, for a legitimate business reason, without any permission of the employee
- IT Helpdesk and other individuals are not permitted to read another individual's email without the individual's permission or without explicit authorization from the MD, Senior Manager or respective Department Head
- Approved Users
- Email facility is granted to users only after receiving approval from the immediate supervisory authority
- All email users (including contractors and consultants) sign an Email Acceptable Use agreement prior to using the email facility
- Backup of the Email System
- A complete set of backup tapes can help to restore the email system if the need arise. If the security of information contained on DJTMPL computers is compromised, the backup tapes can provide evidence
- Email message is backed up on a daily basis
- Complete system backups are taken on a weekly basis
- Email Viruses
- Users install and use anti-virus software to scan any attachment before opening it
- User do not open email attachments unless they are sure about its contents and they know their senders well
- Email Footer
- All emails carry an automatic standard footer banner. The banner indicates that:
- The mail is intended for the use of the recipient to whom it is addressed
- The mail is not be acted upon and destroyed promptly if a person, to whom it is not intended, receives it
- Opinions, conclusions and other information in the message that do not relate to the official role of the sender is understood as neither given nor endorsed by DJTMPL
- Users of Personal Digital Assistants ('PDA') ensure that access to information within the PDA is controlled by a password
- All external outgoing emails sent through PDA carry an automatic standard footer. This indicates that:
- Message has been sent using the PDA
- Standard disclaimers and conditions as per DJTMPL email security policy apply
8. Source Code Management
Policy Statement
Access to source codes of software should be controlled.
Purpose and Objectives
Production source code programs should be stored in a secure manner so that they are protected from any unauthorised access. This would ensure that the source code is not examined for exploring possible security vulnerabilities in the system. A backup copy of the latest source code should be stored offsite in a secure location so that application executables could be reproduced in the event of a disaster.
Procedure
- General Standards
- There is a repository for production source code. Developers retrieve the source code from this repository when modifying programs, wherever possible
- Only an authorised person has update access to the production source code
- No person from the development team is authorised for the deployment of changes into the production environment
- The source code is readily available to reproduce application execution code in the event of a disaster or problem with the production environment. The updated source code accurately reflects the current processing
- A backup copy of the source code is properly safeguarded in a secure off-site location
- Source codes are maintained by an automated version control system. The version control system ensures that the appropriate versions of source modules are mapped to each application release
Version Control Policy
Same version of an application should be used by all the users in their respective places of work. All applications will have facility to display version no. and date, month and year of release.
Purpose and Objectives
Version control of software should be strictly ensured. This ensures that all users work on the same and latest version of the applications uniformly across DJTMPL and its other vertical.
Procedure
- General Standards
- Software is held in secure libraries and the libraries are qualified using the release and/ or version number to distinguish different versions, wherever possible
- DJTMPL uses a version control tool or process (e.g., check-out) to maintain the integrity of program code and other project documentation such as requirements, architecture, design specification, and configuration documents
- Modified programs are assigned a higher version number following a change
- The software components are identified by means of a unique name and assigned a release and version number
- The content of each version are documented providing a brief description of the system elements that are included
- System documentation are subjected to version control and versions of documentation are related to the corresponding software versions
- Version controls are periodically reviewed by the delegated authority or any other official as deemed appropriate to ensure that they remain effective
Unit Testing
Unit testing of software/ equipment should be carried out and details of the test cases, expected results, actual results, gaps if any and testers sign-off should be formally documented and preserved.
Purpose and Objectives
Unit testing of software/equipment should be carried out for all modifications and for new software/ equipment. The testing should be done in a controlled manner and thorough review of test results should be performed. This reduces the potential for possible errors / malfunction in the software/ equipment.
Procedure
- General Standards
- The developers/ peer conduct unit testing in the programmer's development library
- The developer's manager performs an independent review of unit test results
- Module testing of equipments is performed and the results of the same are documented
- The immediate controlling authority performs an independent review to assess whether the module testing has been carried out adequately
- Unit test results are documented and kept on file
- Tests are performed using a complete and representative set of test data instead of production data
Integration Testing
Integration testing of software/ equipment should be carried out in a protected and controlled manner to ensure that different applications, programs, interfaces cohesively perform as expected.
Purpose and Objectives
Integration testing of software/ equipment should be carried out for all significant modifications and for new systems. Integration testing should be conducted on the basis of a formal integration test plan. This would reduce the potential of future malfunctioning of the software/ equipment.
Procedure
- General Standards
- All significant modifications, major enhancements and new systems undergo integration testing prior to installation of the software/ equipment in production
- For major enhancements and new systems, a formal integration test plan is prepared
- Integration testing is conducted in a separate, independently controlled test environment
- If problems are noted, then the developer/ vendor makes appropriate modifications and submits it to testing engineer for re-testing
- Copies of production data or pre-designed test data sets are used for testing purposes
- Integration test results are documented and kept on file
User Acceptance Testing
Policy Statement
All significant modifications and enhancements of systems should undergo acceptance testing by end users prior to installation or deployment.
Purpose and Objectives
End users should conduct acceptance testing for all significant modifications and enhancements of systems. The testing should be conducted based on a formal testing plan. This would help to ensure that modified or new systems meet end user requirements.
Procedure
- General Standards
- All significant modifications, major enhancements and new systems are tested by appropriate end users prior to installation of the software/ equipment in production
- Test plans used have been approved by business owners and development management for program and system development
- User acceptance testing is conducted in a separate, independently controlled test environment. This is performed only after the receiving satisfactory results from Unit and Integration testing
- Tests are performed using a complete and representative set of test data instead of production data
- For major enhancements and new systems, a formal user acceptance plan is prepared. The plan includes tests of all major functions, processes and interfacing systems
- End user indicates acceptance through a formal sign-off
- User acceptance testing team comprises of experienced users having in-depth knowledge of DJTMPL procedures and regulatory requirements
- During acceptance testing, logical access restrictions ensure that developers have no update access and that the code being tested cannot be modified without the written consent of the user
9. Security in Application Systems
Policy Statement
Application controls should be designed to prevent loss, modification or misuse of user data in application systems.
Purpose and Objectives
To prevent loss, modification or misuse of user data in application systems:
Appropriate controls and audit trails or activity logs should be designed into application systems, including user written applications. These should include the validation of input data, internal processing and output data.
Additional controls may be required for systems that process, or have an impact on, sensitive, valuable or critical organizational information assets. Such controls should be determined on the basis of security requirements and risk assessment.
Procedure
- Input Data Validation
- Input checks to detect the following errors are considered:
- Out-of-range values
- Invalid characters in data fields
- Missing or incomplete data
- Exceeding upper and lower data volume limits
- Unauthorized or inconsistent control data
- Periodic review of efficiency and adequacy of input validations and processing controls to ensure data integrity is done
- Verification of audit trails and exceptional reports for any unauthorized changes to input data is done
- All applications follow maker-checker principle by incorporating suitable transaction authorization routines as well as segregation of conflicting duties
- Control of Internal Processing
- Session or batch controls, to reconcile data file balances after transaction updates, is incorporated in the application, wherever possible
- Balancing controls are incorporated in the application, wherever possible, to check opening balances against previous closing balances, namely:
- run-to-run controls
- file update totals
- program-to-program controls
- Hash totals of records and files are done, wherever possible
- Output Data Validation
- Checks are incorporated, wherever possible, to test whether the output data is reasonable
- Reconciliation control counts are incorporated, wherever possible, to ensure that the data is completely, and accurately processed and same data is not processed repeatedly
- The responsibilities of all personnel involved in the data output process are defined
- Application Control
- All applications are developed on the basis of the requests from users and budgetary approvals
- SA is the facilitator in the application development process
- All change management requests efforts are signed off by Senior Manager -ISS
- All changes are closed with a sign off on a user acceptance document
- Every major application has an application business owner
- SAP authorization checking is included in custom programs. Procedures are in place to confirm such programs and help ensure the necessary security checking is performed
- Custom SAP programs as well as custom tables are assigned to authorization groups
- SAP Application Monitoring
- Opening and closing of client/warehouse is only post approval of management, and the entire log of opening till closing is recorded, periodically reviewed and signed-off by the management, to ensure that proper control and validation for the same exists
- There are sixteen (16) posting periods in an SAP system. For control purposes, the SAP system allows that only specific periods (years) are open. Opening and closing of posting periods is, like opening and closing of clients, only post approval by respective vertical's finance head. The entire process is also recorded, reviewed and signed-off by management, to ensure that transactions are posted in the proper periods