Skip to main content

T&T Security Standard

Version: 2, effective date: 01-Aug-2022

Andrei Dohataru


Contents

1 Standard description

The purpose of this document is to define the T&T security permissions model for the T&T infrastructure components.

2 Document objectives and benefits

2.1 Objectives

Objectives of the document are: - Access permissions for all IT supporting teams to Database servers, Databases, Application servers - Definition of the access levels - Specification of access type for each of the access levels defined within the model - Process to maintain the permissions - Roles and permissions for business/functional users of the T&T systems and applications

2.2 Benefits

The document helps to set up the T&T security permission model in a control manner.

3 Definitions

Abbreviation / TermExplanation
T&TTrack and Trace
GateFactory level system which stores unused codes and provides activated codes to higher-level systems.
GLAGlobal Label Application. Starts production, generates and prints MC and Pallet codes/labels. Confirms production and sends results to SAP. Mandatory system.
InexpressFactory level system, transit data processor: doing data compression and uploading to iTrack from factory.
TPMStore aggregations. Validate aggregations according to T&T rules. Transfer aggregations to CR.
SAPJTI SAP S/4 HANA system, considered a trusted source of Master data (Material Master, Customers, JTI entities, etc.) also transactional data (Production orders, Deliveries, Invoices, and Payments) for T&T relevant entities where SAP is implemented.

Please refer to IT Glossary in the IT P&P portal for further definitions.

4 Roles & Responsibilities

4.1 Process Stakeholders

#ActivityBTS T&T ServiceGDC T&TGTC-DC-TIGTC-DC-TAGTC-DC-SDFactory
1Define and maintain standardA / RCCCCI
2Apply the document in the T&T Implementation projects.R / A

A – Accountable, R – Responsible, C – Consulting, I – Informed

4.2 T&T Main Support Teams

TeamRoleWorking Hours
3rd party - Monovi1st and 2nd support level team for all T&T functional/technical issues24/7
3rd party - Inexto2nd and 3rd level support for Gate, Inexpress, iTrack systems
3rd party - Fracture Code2nd and 3rd level support for TPM T&T system
3rd party - Sierra2nd and 3rd level support for GLA system
DCOoverall support of T&T infrastructure including servers, operating systems, databases, storage24/7
SAP T&T2nd and 3rd level support for SAP T&T system
GSC CP SupportBusiness support for T&T systems

5 T&T Permissions for User Accounts

The standard has defined model of T&T security permission model for T&T Systems and related applications.

5.1 Access to T&T Servers and Databases

Access to T&T Servers and databases is granted based on Active Directory groups. Access types and roles are shown in the table below:

GroupT&T Application ServerT&T Database
AdministratorsLocal administratorSQL Roles:
- db_datareader
- db_datawriter
- db_ddladmin
- db_backupoperator
- view definition
- execute
- view server state
UsersRDP accessSQL Roles:
- db_datareader
- view definition
Support TeamRDP access
Administrative access to application services on all T&T App servers
SQL Roles:
- db_datareader, view server state & view definition for all T&T DBs
- SQL T&TSupport role for GLA & GATE DBs. It means read/write access to below GLA tables:
- [WorkOrder]
- [WorkOrderBOM]
- [ProductionRunLog]
- [ProductionRun]
- [TrackingRule]
- [User]
- [UserProfileGroup]
- [SetupParameter]
- [PalletProductionContent]
- [PalletProduction]
- [MaterialGroup]
- [MaterialCharacteristic]
- [UserWorkcenter]
- [vwFractureCodeReader]
DevOps Team- RDP access
- Local administrator
- Administrative access to application services on all T&T App servers
SQL Roles:
- db_datareader
- db_datawrite
- db_ddladmin
- db_backupoperator
- execute
- view definition
- view server state
DB Server OS
- Local administrator
DevOps deploy
Service account
- Local administrator
- Administrative access to application services on all T&T App servers
SQL Roles:
- ddl_admin
- execute
- db_backupoperator
- view definition
DB Server OS
- Local administrator
GSC CP SupportN/ASQL Roles:
- db_datareader
- view definition

5.2 Permission Description

Detailed description of permission level based on security group is shown in below table:

SystemSecurity Group (JTICORP)Permission level
TPMSWIGVA01-TAT-TPM-SYSTEM AdminsMS SQL Server
db_datareader,
db_datawriter,
db_ddladmin,
db_backupoperator,
execute,
view definition,
view server state

Windows Server: Local Administrator over TPM APP Servers
TPMSWIGVA01-TAT-TPM-SYSTEM UsersMS SQL Server
db_datareader,
view definition

Windows Server: RDP to TPM Application servers
Gate, Inexpress, iTrackSWIGVA01-TAT-Inexto-SYSTEM AdminsMS SQL Server
db_datareader,
db_datawriter,
db_ddladmin,
db_backupoperator,
execute,
view definition,
view server state

Windows Server: Local admin over Gate/Inexpress app servers
Gate, Inexpress, iTrackSWIGVA01-TAT-Inexto-SYSTEM UsersWindows Server: RDP to Gate/Inexpress application servers
Gate, Inexpress, iTrackSWIGVA01-TAT-Inexto-SYSTEM DataReaderMS SQL Server:
db_datareader,
view definition
GLASWIGVA01-TAT-GLA-SYSTEM AdminsWindows Server: Local Admin for app servers

MS SQL Server
db_datareader,
db_datawriter,
db_ddladmin,
db_backupoperator,
execute,
view definition,
view server state
GLASWIGVA01-TAT-GLA-SYSTEM UsersWindows Server:
- RDP access to APP Servers
- Admin access to Application services only

MS SQL Server:
db_datareader,
db_datawriter,
view definition
All T&T SystemsSWIGVA01-TAT-SUPPORTWindows Server:
- RDP access to application Servers
- Access to Start/Stop Application services only

MS SQL Server:
db_datareader,
view server state,
view definition

Additionaly for GLA & GATE databases:
db_datawriter,
execute
All T&T SystemsGlobal-IT-TT-DevOps-AdminsWindows Server: member of local Administrators group

MS SQL Server:
db_datareader,
db_datawriter,
db_ddladmin,
db_backupoperator,
execute,
view server state,
view definition

DB Server OS:
- Local administrator
All T&T SystemsGlobal-IT-TT-DevOps-DeploymentWindows Server: member of local Administrators group

MS SQL Server:
db_datareader,
db_datawriter,
db_ddladmin,
db_backupoperator,
db_securityadmin,
execute
DB Server OS:
- Local administrator
All T&T SystemsGlobal-GSC-CP-SupportMS SQL Server:
db_datareader,
view definition

5.3 Permissions for DataLake

Access required for collecting data to T&T DWH (Azure DataLake):

System dbService accountPermission level
TPM DL, GATE DLZ_TAT_HARDENING_PRODMS SQL Server:

db_datareader,
db_datawriter,
execute
TPM DL, GATE DLTPM non interactive execution user
Z_XXX_TPMSVC_PRD

GATE non interactive execution user
Z_TAT_GATE_PROD_XXX
MS SQL Server:
db_datareader,
db_datawriter,
execute,
view definition

5.4 Permission Model

The security permissions model is represented by the following schemas.

Administrators and Users permissions:

TTSecurityStandard-image1.JPG

Support Team permissions [SWIGVA01-TAT-SUPPORT]:

TTSecurityStandard-image2.JPG

6 T&T Service Accounts

The T&T system relies on several service accounts used by the system applications to run and to access various resources like databases, shared folders, APIs, etc. The credentials for all these service accounts must be stored in a centralized place accessible to the entire T&T team and are not reliant on any single one person.

6.1 Credentials Storage

The usernames and passwords for all service accounts used by the T&T system must be stored into the BTS_QT safe of JTI Enterprise Password Vault.

6.2 Password Change

When changing the password for any service account used by the T&T system, the new password must be maintained in BTS_QT safe of JTI Enterprise Password Vault.

7 T&T Certificates

The T&T system accesses several services which require an SSL certificate to authenticate. These certificates must be stored in a centralized place accessible to the entire T&T team and are not reliant on any single one person. Certificates expire regularly therefore a monitoring and renewal procedure must be in place to ensure that the certificates are refreshed in due time and are replaced before losing connectivity.

7.1 Certificates Storage

All the certificates used by the T&T System must be stored in ATOS_CR safe of JTI Enterprise Password Vault.

7.2 Certificates Expiration

Before any certificate expires a new one must be requested and reconfigured on the required application to ensure that connectivity is not lost due to the certificate expiration. It is noteworthy that different systems supplied by different vendors will require different lead times for the certificate refresh, this must be factored in so the refresh procedure is initiated in due time to get the new certificate before the expiration of the existing one.

7.3 Certificate Expiration Monitoring

It is the responsibility of JTI to monitor the expiration date of all the certificates and request certificate replacement. In order to do that JTI must ensure that a certificate monitoring system and the process are in place which will alert when the certificates are about to expire.

8 Access to T&T Resources

SQL databases It is recommended that all supported teams should use MS SQL Server Management tool on their own machines, through VDI or oneportal.jti.com whenever possible.

Windows System Services Standard Windows Service Console on own machines

Remote Desktop RDP usage should be treated as an exception to avoid server resource utilization and the standard license allows only for 2 simultaneously remote session

9 Access to the SAP System and Corresponding T&T Functionality

Access to the SAP system and corresponding T&T functionality is realized in line with SAP Security Standard (10.118) and SAP Account and Access Management Procedure (10.071). In the context of T&T, the following access types are used and realized via JTI SAP Security model:

9.1 Business Users

Business users are getting access to SAP T&T functionality via their standard business SAP Security roles, enhanced to include T&T transactions and authorization objects, and assigned to their SAP accounts (SAP User Groups = USER or GENERIC). Business role granting is executed via standard SAP GRC functionality.

9.2 IT BTS TT Experts

Under normal circumstances, IT BTS TT users are getting access to SAP T&T functionality via their standard business SAP Security roles, enhanced to include T&T transactions and authorization objects, and assigned to their SAP accounts (SAP User Groups = USER or GENERIC).

In case of urgent problems, Emergency Access Management (EAM) accounts are used, to execute firefighting tasks outside IT BTS TT normal job function and ensures that IT BTS TT Experts are operating within a controlled and fully auditable environment.

EAM Roles granting and control are executed via standard SAP GRC EAM functionality; EAM access ownership is granted to IT BTS TT Director and IT GDC TTDC Director.

9.3 System Users

Integration with other T&T systems within the JTI systems landscape (e.g., with Factory GLA systems) is executed via dedicated system accounts (SAP User Groups = SYS).

To restrict access according to Segregation of Duties (SoD) requirements, and to identify interfacing system, for each Production T&T system, connected to SAP S/4 Production system, a separate dedicated system SAP account should be generated with permissions, limiting SAP access by system entity only.

(As an example, Production Trier factory GLA will be allowed to acquire production orders data and post production order confirmations for the Trier factory plant only and not allowed to access data for other plants.)

SAP S/4 Production system connection parameters and system account name and password are managed as confidential by appointed IT BTS TT and IT GDC TTDC experts. Connecting T&T system is fully responsible for secure storage, maintenance and proper applying of SAP connection parameters and credentials, data are not accessible to any system user or support team except appointed IT BTS TT and IT GDC TTDC experts.

10 Permissions Monitoring

The administrative user accounts are under JSOX control and are being monitored accordingly.

11 Document control

11.1 Contact person

Questions and feedback regarding this standard should be submitted to the BTS T&T Team.

11.2 Revision History

VersionEffective DateReason for Changes
1July 2021New document
1.1August 2021Updated with Service Accounts and Certificates
1.2April 2022Upload to CMS
1.3July 2022Implement DCTA recommendations (CHG239138)
1.4August 2022Add GSC CP support team to scope of the document
1.5August 2023Update permissions for Support team
VersionEffective datePurpose of changeAuthor
201-Aug-2022The GSC CP support team has been added to the scope of the documentAndrei Dohataru
101-July-2021First version of the documentAndrei Dohataru

12 References

ANY QUESTIONS?

ASK TEAM