RMO No. 24-2025 — Implementation of Bring Your Own Device (BYOD)
BUREAU OF INTERNAL REVENUE REPUBLIC OF THE PHILIPPINES DEPARTMENT OF FINANCE
Bringing In Revenues for Nation-Building Quezon City PILAPH MA 2025 BAGONG
REVENUE MEMORANDUM ORDER NO._0_2 4 - 2 0 2 5
Subject IMPLEMENTATION OF BRING YOUR OWN DEVICE (BYOD)
TO ALL INTERNAL REVENUE OFFICIALS, EMPLOYEES, AND OTHERS CONCERNED
With the rapid advancement of mobile technology and the growing demand for flexible BACKGROUND work environments, the BIR will implement BYOD strategy to allow employees and other authorized third parties (partner, consultant, and contractor / service provider) to use their compliance. To address these, BYOD policies and guidelines are hereby prescribed to personal devices for work-related activities offering more convenience, flexibility, and productivity. This approach can improve the satisfaction of employees and other parties allowed to use personal device/s by enabling the use of said devices. Howeverj implementing BYOD also introduces challenges related to data security, privacy and ensure secure and effective integration into the BIR workplace
OBJECTIVE
a. Ensure security, confidentiality and integrity of information when accessing BIR b. Prescribe policies, guidelines and procedures on the implementation and use of This Order is issued to: network through personal device/s;
III. POLICIES AND GUIDELINES personal device/s. * &
A. The following persons shall be allowed to use personal:device/s: Employees
Consultant/Contractor/Service Provider
ADMIN UNTME: SAT MAY 0 7 2025 NAERMEN FENEN RUREADS B E 0 A The following personal device/s shall be allowed to be connected to the BIR network/resources: 1 Laptop Partner government agencies, and Other Third Parties except those accessing BIR network for one-day presentation purposes only
G5 2 3 4 Printer (applicable only if allocation of printer by Property Division is insufficient) Desktop Computer Smartphone/tablet
F1 BiR National Office Bldg., Senator Miriam Defensor-Santiago Avenue, Diliman, Quezon City Trunkline: 8981-7000 ; 8929-7676 Website: www.bir.gov.ph Page 1of 5
C.BYOD Users shall strictly: A Abide by the Policies and Guidelines on Revised Information and
Communications Technology (ICT) Security Policy (RMO 15-2014) and Republic Act 10173 (Data Privacy Act of 2012). 2 Adhere to the Acceptable Use Policy (AUP). 3 Undergo Information Security Awareness and Data Privacy Act briefings in order
to register and use their personal devices (applicable only to BiR employees and contractors) Users who need to connect their personal device/s to the BIR's internet shall
5. Allow authorized IsG personnel to access/inspect registered personal device/s, register first their devices and comply to this issuance before requesting and be given access to the internet using their personal devices.
including conduct of vulnerability assessment (VA). However, employees accessing BIR network (WiFi) using smartphone/tablet shall not undergo VA 6 Ensure that:
6.1 updates are regularly applied to the operating system and primary applications such as email client, web browser and security
6.2 personal and BIR-related files/application systems are encrypted software. Updates shall be the responsibility of the user. and separated from one another (i.e. a dedicated folder/storage
used as a repository for official/work related files and/or application
1 Secure the device/s to prevent sensitive data from being loss or compromised. systems)
9. 8 Handle other issues not related to BIR network/resources. Report to authorized BIR personnel lost or stolen device/s within 24 hours. Be fully liable for the loss of BIR data stored therein. BIR shall not be responsible for the loss of the registered device/s.
10. Ensure removal/deletion of work-related data prior to disposal/pullout of the
registered device.
D. Personal device/s to be connected to the BIR network/resources of: 1. Third party/guest shall: 1.1 be limited to a single device access.
1.2 be allowed for one-day connectivity if purpose of connection is for
E D ADMiN uN A H MAY O :225 :} US OF INAEMEN EENUT B Y L 2 BIR employees and All Other Users shall: 2.3 2:4 1.3 2.1 2.2 be disconnected from the network in case of anomaly or suspicious activity presentation only. without prior notice. b. encryption of data stored therein (e.g bitlocker) be registered with BIR by accomplishing BYOD application form except for those requesting for one-day connectivity and for presentation item/position) shall be allowed access to three (3) devices have an advance endpoint security solution (e.g. Malwarebytes, eScan) and activated the following security features of the device: a. password/Personal Identification Number (PIN)/biometrics protection be limited to a single device access; further, BIR officials (holding director undergo vulnerability assessment (VA) for (aptops/Desktop PC purposes only.
F1 Page 2 of 5
2.5 2.6 be subjected to the following, once approved: be allowed only for a maximum of three (3) months network connection. 2.6.1 installation of Endpoint Detection and Response (EDR) 2.6.2 regular onsite inspection and/or post audit by authorized agent/solution. Revenue Data Center (RDC)/Network Management and Technical Support Division (NMTSD) technical support
2.6.3 be disconnected from the network in case of anomaly or personnel.
suspicious activity without prior notice.
E. Application to use the Personal Device and Conduct of VA 1. Application Form for BYOD, AUP and submission of certificate of attendance to the Information Security Awareness and Data Privacy Act Briefing shall be digitally submitted by the requestor by accessing the QR code or link as provided
on a separate memorandum. 2. 3. technical support personnel or Regional Tech support personnel. Approval/Disapproval of BYOD application is done thru the workflow, included in Conduct of VA shall be done by Security Management Division (SMD), RDC the MS Forms submitted by requestor.
IV. ROLES AND RESPONSIBILITIES
A. User/Requestor
2. Fill-up the online forms and upload the Certificate of Attendance to the Information 1. Access the QR Code/Link for request of more than one (1) day connectivity; otherwise create a ticket on Servicedesk thru coordination with the point person from BIR for 1 day connectivity for presentation purposes only.
Security Awareness and Data Privacy Act Briefing (applicable only to BIR
3. Resolve vulnerabilities found in the device, if any. Provide additional requirement 4. Receive email notification on the status of BYOD application. as may be required (applicable to laptop/desktop PC) employees and contractors).
B. RDC-CONED / NODC-CONED/NMTSD 1. Receive email notification of user's request for BYOD of more than one (1) day 2. Validate completeness and accuracy of request. 3. Evaluate the request as to the: for 1 day connectivity- connectivity; otherwise receive email notification from Servicedesk for request valid
a. reason/justification for the request b. inventory of desktop computers/printers provided to their office, c. conformance of the device/s to the security features requirement including the
advance endpoint security solution
@) Rureay gF internaLrevenue ECORDS MANAGFMENTHIVISION e
MAY 0 7 2025
F Y At\MiN UNi7 II.r.. 9 Page 3 of 5
6. Implement connection of the device to the BIR network if approved by the RDC 4. Conduct vulnerability assessment (VA) if the device is laptop or desktop Pc 5. Approve request if it pass the evaluation, otherwise, disapprove the request. a. If with vulnerabilities, inform and/or assist user/requestor on the resolution of b. Re-conduct VA if vulnerabilities have been resolved. (applicable to RDC-CONED/NODC-CONED only). Head/NMTSD Chief. vulnerabilities.
7. Provide assistance to SMD on the installation of EDR 8. Prepare the following monthly inventory list and submit to Office of AClR- ISDOS/SMD:
10. Prepare onsite inspection / post audit report and submit to OACIR-ISDOS, copy 9. Conduct quarterly onsite inspection and/or post audit of the registered devices for furnish SMD. BYOD to offices under their area of jurisdiction. a. approved/disapproved registration for BYOD from the list of requests b. list of disconnected devices from the network (if any) generated thru Sharepoint.
C. Nmtsd
1. Endorse BYOD request from National Office (N.O) to SMD thru email for conduct of
VA. 2. Receive notification from SMD of the vulnerabilities found, (if any) for laptop/desktop PC BYOD request.
5. Work closely with concerned offices on security breaches relative to the use of 4. Monitor approved devices connected to the BIR network. 3. Inform SMD if vulnerabilities have been resolved for re-conduct of VA. 6. Coordinate with SMD on security matters relative to BYOD Policy BYOD.
7. Analyze and implement required mitigation on identified security breaches.
D. SMD
10. Work closely with concerned offices on security breaches relative to the use of 1 1. Analyze and implement required mitigation on identified security breaches. 5. Inform NMTSD thru email if laptop/desktop has been cleared from VA. 7. Receive from RDC-CONED/NODC-CONED/NMTSD the monthly inventory list of 8. Receive from RDC-CONED/NODC-CONED/NMTSD the onsite inspection/post 2. Conduct VA on Iaptop/desktop PC. 3. If with vulnerabilities, inform NMTSD of the vulnerabilities for resolution. 4. Re-conduct VA if vulnerabilities have been resolved. 6. Install EDR agent/solution to the approved device 9. Monitor approved BYOD connected to the BIR network. 1. Receive thru email-the endorsed N.O request/s from NMTSD for conduct of VA. the approved/disapproved registration for BYOD. BYOD. audit report.
@ BUreAU OF INtErNaL revenue RECORDS MANAGFMENT DIVISION
MAY 0 7 2025
F1 HIvA s Page 4 of 5
F. OACIR-ISDOS
1. Receive from RDC-CONED/ NODC-CONED/NMTSD the monthly inventory list of 2 Receive from RDC-CONED/NODC-CONED/NMTSD the onsite inspection/post devices from the network (if any). the approved/disapproved registration for BYOD and the list of disconnected
3. Review submitted inventory list/post audit report and provide recommendation or audit report.
necessary corrective action to concerned office, if applicable.
V. EFFECTIVITY
This Order shall take effect immediately.
ROME LuMAguI, JR Commissioner of Internal Revenue
S ABUREAU OF INTERNAL REVENUE RECORDS MANAGEMENT DIVISION
MAY 0 7 2025
BY ADMIN UNII - A7S Ts
F1 Page 5 of 5
Want an analysis of this document?
Ask ASG Legal AI to summarize it, compare it with other rulings, or explain how it applies to your situation — it researches from this same library.