29.4.9 Query to Production
a) Only 2 (two) user ids are allowed to access application with SQL query. These two user ids must be granted READ access rights only.
b) All level 1 support user id must tag to their name.
29.5 Data Patching
A data patch is an activity to modify or update the database of the system.
a) Patching of data in systems is not permitted unless it is deemed necessary i.e. there is no other means to rectify the systems problem.
b) All data patching must be formally approved by respective data owner prior to the joint approval.
c) As such, in an exceptional case, there must be joint approval from Head of GT and Director, Governance & Risk Analytics or their respective designate for any data patching request.
d) For other countries within the Group, the joint approval shall be obtained by the respective country Head of IT and the designated from Director, Governance & Risk Analytics (if any).
e) Implementation of data patch must comply with the IT change management process.
f) Data patching is only allowed for any detected data error, which is unable to be fixed through the application level.
g) Root cause analysis must be performed to prevent reoccurrence of data patching.