revenue_memorandum_order RMO No. 10-2025RMO No. 10-2025 2025-03-04

RMO No. 10-2025 — Policies and Guidelines on the Use of BIR Internet Browsing Facilities Digest | Full Text | Annex A

BUREAU OF INTERNAL REVENUE REPUBLIC OF THE PHILIPPINES DEPARTMENT OF FINANCE

Bringing In Revenues for Nation-Building PILIPINAS BAGONG January 31, 2025

REVENUE MEMORANDUM ORDER NO. 0 1 0 - 2 0 2 5

Subject POLICIES AND GUIDELINES ON THE USE OF BIR INTERNET BROWSING

FACILitIES

TO ALL INTERNAL REVENUE OFFICIALS, EMPLOYEES AND OTHERS CONCERNED

1 OBJECTIVE

This Order prescribes the policies, guidelines and procedures on the implementation and use of BIR internet service by authorized users to prevent misuse, ensure confidentiatity and protection of data, maintain productivity, and safeguard the agency's reputation.

POLICIES AND GUIDELINES

2.1. BiR internet services shall strictly be for official use only.

2.2 Internet users shail be mindful of their online activities and ensure responsible and

productive use of BiR internet facility

2.3 Users shall undergo Information Security Awareness Briefing (ISAB) prior to internet

access processing and approval.

2.4 -Granting of Internet Access

2.4.1 Internet services shall be granted based on the user's role/current job

2.4.1.1 Use and access of wired internet account shall be granted but not description. limited to the following users: 2.4.1.1.1 2.4.1.1.2 Officials/Employees with Webmail ticense Officials/Employees required to perform on-line system

related activities

RECORDS MANAGEMENTDIVISION BUREAU OF INTERNAL REVENUE 2.4.1.1.3 2.4.1.1.4 Officials/Employees with constant research activities Officials/Employees involved in inter-agency projects

A H 323 approved by Assistant Commissioner of Information MAR 0 4 2025 Systems Deveiopment and Operations Service (ACiR ISDOS) or Deputy Commissioner of Information Systems

TADMINUNIT-I"I4DOM M 2.4.1.1.5 Other employees and third parties within the BiR Group (DCiR ISG).

organization recommended by Head of Office and

BIR National Office Bidg., Senator Miriam Defensor-Santiago Avenue, Diliman, Quezon City Trunkline: 8981-7000 ; 8929-7676 Website: www.bir.gov.ph Page 1 of 6 AaE

JREAU OF INTERi ANA SFMFNT DIVISION RFVFNUE

aeh 3e 3

MAR 0 4 2025

Admin unit 3 40 2.4.1.2 Use and access of wireless internet account shall be granted but not Pm approved by ACIR iSDOS or DCIR ISG

limited to the following users: 2.4.1.2.2 2.4.1.2.3 2.4.1.2.1 endorsed by ACiR ISDOS and approved by DC!R ISG Officials/Employees involved in inter-agency projects Guest/External Users Officials/Employees with BIR issued faptop

2.4.2 BiR Officials and select employees with webmail, performing online system

related activities, and constant research activities shall automatically be given privilege to access the internet upon submission of duly accomplished B!R Form No. 0041-Office Automation Request (Annex A) to Network Management and Technical Support Division (NMTSD).

2.4.3User requesting for wired internet access shall submit duly accomplished

Annex A to Chief, NMTSD for endorsement I recommendation for approval of ACIR iSdOS.

2.4.4 User requesting for wireless internet access for BiR issued equipment shall log

a ticket thru Service Desk for internet account activation and configuration upon approval of ACIR ISDOS.

2.4.5 User requesting for wireless internet access for their personal device/s shall

comply first to the policy on the implementation of Bring Your Own Device (BYOD) before given the privilege to access the internet.

2.4.6 In case of transfer to another office, users with approved wired/wireless internet

access shall request for reactivation by submitting a duly accomplished Annex A to Chief, NMTSD.

2.5. The internet administrator shall keep an updated inventory of all internet users/access.

2.6. All internet activities are being monitored and subject to inspection and/or sanction in case of violation.

2.7. Resource Usage

2.7.1 All users shall follow the Bureau principles regarding resource usage and

exercise good judgment in using internet services.

2.7.2: Acceptable use of the internet for performing job functions may include, but not

limited to:

Page 2 of 6

2.7.2.1 Downloading of software upgrades and patches by Systems

Administrators and other authorized users: 2.7.2.2 Review of possible vendor web sites for product information; 2.7.2.3 Research or reference for regulatory and technical information; 2.7.2.4 Use of Voice over internet Protocol (VolP) and 2.7.2.5 Accessing of personal email account.

2.7.3 Acceptabie use of the internet for guest/external user may inciude, but not

timited to: 2.7.3.1 Accessing BIR eServices and other government agencies services 2.7.3.2 Research for tax related information 2.7.3.3 Accessing personal email account

2.8. Prohibition

2.8.1 Acquisition, storage, and dissemination of data through the internet which is illegal, pornographic, or which negatively depicts race, sex or creed is

specifically and strictly prohibited; 2.8.2 The Bureau aiso prohibits the conduct of a personal or private business

enterprise, political activity, engaging in any form of intelligence collection from Bureau facilities, engaging in fraudulent activities, or knowingly disseminating false or otherwise libelous materials: 2.8.3 Automatic updating of software or information on the Bureau's information

assets via background "push" internet technology are prohibited, unless the involved vendor's system has first been tested and approved by the NMTSD; 2.8.4 Downloading files directly into a network server or production machine from

untrusted.or.unauthorizec Irces.is-prohibited; 2.8.5 forums and other Employees or individual nterne offices are prohibited from creating websites, blogs, offerings containing the Bureau information

independent of 1T ficial web infrastructure unless otherwise duly authorized/approve G Btroal u Managemeni 2.8.6 Other sper THCGT strictly prohibited include but are not limited to:

2.8.6.1 Acces artatc that is not within the scope of one's work (e.g..

Inauthort rsonnel t0 information,accessing information that is ded for the proper execution of job functions): 2.8.6.2 Misusing, disclc information (e.g.. ckint g unauthorized changes to a personnel file, or per authorization, or altering personnel

sharing electronic 0 nel data with unauthorized personnel): 2.8.6.3 Any unauthorized, deliberate action that damages or may cause damages or disrupts computing systems or networks, alters their

Finr aw ee tt ECORDSMANAGEMINY JREAUOE INTERNAL DEVENU V{SIO}N 1 normal performance, or causes them to malfunction regardless of location or duration;

MAR 0 4 2025 2.8.6.3.1 music piracy: Perpetrate any form of fraud, and/or software, film or

Haud AnMiN UNIt[:LO0m Ii Page 3 of 6

2.8.6:3.3 2.8.6.3.2 Willful or negligent introduction of computer viruses, Hacking activities; Trojan or other destructive programs into Bureau

systems or networks or into external systems and

2.8.6.3.4 networks: Unauthorized decryption or attempt at decryption of any system or user passwords or any other user's encrypted

files: 2.8.6.3.5 Packet sniffing, packet spoofing, or use of any other

means to gain unauthorized access to a computing

2.8.6.3.6 Use, transmission, duplication, or voluntary receipt of material that infringes on the copyrights, trademarks. system or network;

trade secrets, or patent rights of any person or

2.8.6.3.7 2.8.6.3.8 organization; Downloading of any shareware or freeware programs or files Any conduct that constitutes or encourages a criminal

offense, leads to civil liability, or otherwise violates any national or international laws, and regulations; 2.8.6.3.9 Deliberate pointing or hyper linking of Bureau Websites

to other internet sites whose content may be inconsistent with or in violation of the aims or policies of the Bureau; 2.8.6.3.10 Transmission of any proprietary, confidential, or

otherwise sensitive information without the proper controls; 2.8.6.3.11 Browsing,- creating,--posting,--transmitting,--or--voluntary

receipt of any unlawful, offensive, fibelous, threatening. harassing materiai, including but not limited to comments based on race, national origin, sex, sexual orientation, age, disability, religion, gambling, anti-religion, violence, racism or political befiefs; 2.8.6.3.12 Unauthorized ordering (shopping) of items or services on

the internet; 2.8.6.3.13 Online gambling and gaming through the internet: 2.8.6.3.14 2.8.6.3.15 Unauthorized participation in any online contest, online Unauthorized subscription to mailing list or mail services;

business or promotion; 2.8.6.3.16 In no case shall social networking sites (e.g., Pinterest,

R RFAULDE INTFRNAL REVENU CORS MANAGEMENT DIVISIDN MAR 0 4 2025 P #n t Yahoo Messenger, FB Messenger, Gtalk) and file officials/employees and sharing sites (e.g., Limewire, Bittorent, Mediafire) be allowed for access over the internet except for authorized Tagged, Tumblr, LinkedIn), instant messaging tool (e.g. A

AADN ON [:LOO TIME Page 4-of 6

2.8.6.3.17All other anaiogous acts.

2.8.7 Automatic scanning for virus shall be installed on all PCs and servers accessing the internet and shall not be turned off by the user or the System Administrator; 2.8.8 All PCs, servers, and other network components shall comply with guidelines

on the prevention, detection, and removal of computer viruses, worms, trojan. and other forms of malicious programs.

2. . Anti-malware Protection

2.9.1 All authorized software downloaded from non-Bureau sources through the

internet shall be screened with virus detection and protection software before installation;

2.10. Maintaining Organization's Image

2.10.1 Whenever employees state an affiliation to the Bureau, they shall also clearly

indicate that the opinions expressed are their own and not necessarily those of the Bureau.

I ROLES AND RESPONSIBILITIES

3.1 Requester/User (BIR employees/third party personnel) shall: 3.1.1. Submit duly accomplished BIR Form No. 0041-Office Automation Request

(Annex A) and duly signed by concerned Head of office to NMTSD 3.1.2. Request reactivation of internet access in case of office transfer by submitting a

.duly-accomplished-Annex-A-to-NMTSD. 3.2 Concerned Head of Office shall: 3.2.1 Recommend approval of wired/wireless internet access request/s of BiR employees/third party personnel. 3.3. Network Management and Technical Support Division (NMTSD) shall:

3.3.1 Validate and recommend approval of internet access requests of BIR

3.3.2 3.3.3 3.3.4 Approve automatic updating of software or information on the Bureau's information assets via background "push" internet technology and Administer proxy server/s, firewall architecture, and other network systems as employees and third party personnel to ACIR ISDOS Grant approved wired/wireless internet access request/s

far as internet access and internet security are concerned as well as maintain its documentation and configuration details. 3.3.5 3.3.6 Monitor internet usage, bandwidth consumption, download/upload speeds, Maintain an up-to-date record of all users with internet access.

BBUREAU OE INTTINAL 8ECO8SSMANAGE ..r t.elDn access time, potential security threats thru network monitoring tools:

m MAR 0 4 2I25 Page 5 of 6 iY / ADMIN UNIT -I M

3.4 Assistant Commissioner -- ISDOS (ACIR-ISDOS) shall:

3.4.1 Approve/Disapprove wired/wireless internet access requests of BlR employees and third party personnel endorsed by NMTSD; 3.4.2 Endorse/Recommend approvai of wired/wireless internet access request/s to

the Deputy Commissioner, Information Systems Group, as necessary.

3.5. Deputy Commissioner -- ISG shall:

3.5.1 Approve/Disapprove wired/wireless internet access request/s endorsed by ACIR-ISDOS as necessary.

I SANCTIONS

and/or legal actions based on RMO 67-2010 Policies & Guidelines on Information & Communication Technology Security Offense. Non-compliance with the Internet Security Guidelines shall be subject to immediate disciplinary

V REPEALING CLAUSE

amended accordingly. All other issuances and/or portions thereof inconsistent herewith are hereby revoked and/or

V EFFECTIVITY

This Order shall take effect immediately.

1H4 U, JR. missioner of Internal Revenue

G

DBUREAU OF INTERNAL REVENUE RECORDS MANAGEPENT DIVISION T

MAR 0 4 2025

IAMtNuNtt. e

Page 6 of 6

Want an analysis of this document?

Ask ASG Legal AI to summarize it, compare it with other rulings, or explain how it applies to your situation — it researches from this same library.