Revenue Memorandum Order · RMO
RMO 5-2024 Digest v3
To prescribe the policies and procedures for the implementation of Multi-Factor Authentication (MFA) for Virtual Private Network (VPN) access in the Bureau of Internal Revenue.
- Document type
- RMO
- Number
- 5
- Year
- 2024
- Text quality
- Not specified
Document text
Reference copy · verify against the official sourceRMO No. 5-2024 (issued February 13, 2024) is an internal BIR issuance prescribing policies and procedures for implementing Multi-Factor Authentication (MFA) for Virtual Private Network (VPN) access. MFA is required for all Bureau VPN users, who are responsible for activities under their accounts; one-time passwords/PINs are generated via a mobile application or sent to the registered BIR email address. BIR employees and third-party service providers with existing or new VPN access must accomplish two copies of the Server Network Access Request Form (SNARF, Annex A) with a network diagram and submit them to the Security Management Division (SMD), which evaluates requests only upon complete documentary requirements (other documents such as an NDA or justification letter may be required). Accounts lock after a maximum of three consecutive invalid login attempts, with unlocks/password resets logged through the BIR Service Desk System, and MFA issues or difficulties are reported to SMD.