0% found this document useful (0 votes)
4 views12 pages

Cisa Module 4

Module 4 covers IT controls, including IT systems, company-level controls, general IT controls, application controls, and IT security controls. It emphasizes the importance of access management, program changes, and computer operations to ensure data integrity, confidentiality, and availability. The module also outlines preventive, detective, and corrective controls, along with input, processing, and output controls to safeguard organizational processes and data.

Uploaded by

rosie Ferrer
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
4 views12 pages

Cisa Module 4

Module 4 covers IT controls, including IT systems, company-level controls, general IT controls, application controls, and IT security controls. It emphasizes the importance of access management, program changes, and computer operations to ensure data integrity, confidentiality, and availability. The module also outlines preventive, detective, and corrective controls, along with input, processing, and output controls to safeguard organizational processes and data.

Uploaded by

rosie Ferrer
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

MODULE 4 - IT CONTROLS

1. IT Systems Overview
● Business processes are supported by one or more application systems.
● Covers input controls, processing controls, and output controls.
● An application is generally supported by one or more infrastructure concept.
● General IT Controls support the proper operation of infrastructure concepts.
● Covers access to programs & data, program changes & development, and computer
operations.
● Management is responsible for creating an environment under which the entity's intemal
controls operate.

2. Common Elements of an Organization


2.1 Company-Level Controls
Company-level controls → set the tone for the organization. Examples include:
● Systems planning
● Operating style
● Enterprise policies
● Governance
● Collaboration
● Information sharing
● Codes of conduct
● Fraud prevention
2.2 General IT Controls
General controls → formed by controls embedded in shared services. Examples include:
● Access to Programs and Data
● Program Changes
● Program Development
● Computer Operations

2.3 Application Controls


Application controls → Controls embedded in business process applications, designed to
achieve completeness, accuracy, validity, and recording assertions. Examples include:
● Authorizations
● Approvals
● Tolerance levels
● Reconciliations
● Input edits

2.4 IT Security Controls


IT security controls → Controls that are technical to avoid threats & minimize loss.
● Vulnerability Testing
● Penetration Testing
● Network Infra Review
● Network Devices

3. General IT Controls
● General IT controls (GITCs) are foundational controls that apply to an organization's IT
environment and systems.
● They are designed to ensure the integrity, reliability, and security of IT processes and
systems, supporting the effectiveness of automated and manual controls.
● GITCs are crucial for safeguarding the confidentiality, integrity, and availability of data
and IT infrastructure.

3.1 The CIA Triad


1. Confidentiality
2. Integrity
3. Availability

3.2 Importance of General IT Controls


Necessary to meet:
3.2.1 Operational and IT Objectives
● Confidentiality
● Integrity
● Availability
● Effectiveness and Efficiency
3.2.2 Financial Statement Objectives
● Accuracy
● Completeness
● Validity
3.3 Control Classification
3.3.1 Preventive Controls
● Objective: To stop issues or risks from occurring in the first place.
● Characteristics: Proactive, focuses on prevention.
● Examples:
○ Access Controls: Ensuring only authorized users can access systems or data (e.g.,
multi-factor authentication).
○ Firewall Rules: Blocking unauthorized access to a network.
○ Policies and Procedures: Implementing strong password policies or secure coding
standards.
○ Segregation of Duties (SOD): Separating roles to reduce fraud or errors (e.g.,
separating developers from production deployment).

Different environments:
1. Production / live environment - e.g. Canvas; whatever Sir does on his side affects the
users (students)
2. Test environment [all simulations, whatever you do here would not affect the live data so
make sure all are working], staging environment -
3. Development environment

Awareness within the people is the best preventive controls - not all are aware

3.3.2 Detective Controls


● Objective: To identify and alert when risks or issues have occurred.
● Characteristics: Reactive, focuses on identifying and reporting.
● Examples:
○ Log Monitoring and Analysis: Reviewing system logs to detect unusual activities.
○ Intrusion Detection Systems (IDS): Identifying unauthorized network activity.
○ Reconciliation Procedures: Comparing records to identify discrepancies.
○ Audit Trails: Tracking changes or transactions to detect unauthorized
modifications.

3.3.3 Corrective Controls


● Objective: To fix or mitigate the impact of identified issues or risks.
● Characteristics: Reactive, focuses on remediation.
● Examples:
○ Patch Management: Applying updates to fix vulnerabilities in systems or
applications.
○ Incident Response Plans: Steps taken to address a data breach or security
incident.
○ Backup Restoration: Recovering data or systems from backups after a failure or
ransomware attack.
○ Error Correction Processes: Correcting discrepancies identified in financial or
operational records.

3.4 Review Process


1. Understand and identify the IT Environment and applications for review
2. Conduct interviews, walkthroughs, and documentation reviews to obtain an
understanding of processes
3. Assess appropriateness of existing control environment (control design)
4. Validate existing controls to assess control operating effectiveness

3.5 General IT Controls Elements


● Access to Programs and Data: Access controls restrict access (prevent and detect) to
relevant information systems and prevent individuals from perpetrating and concealing
an error or irregularity
● Program Change: Controls for program changes ensure that changes to existing
systems/applications are authorized, tested, approved, properly implemented, and
documented.
● Program Development: Program development controls ensure that new systems'
applications, which are developed or acquired, are authorized, tested, approved, properly
implemented, and documented.
● Computer Operations: Controls for computer operations ensure that system/application
processing is appropriately authorized and scheduled, and deviations from scheduled
processing are identified and resolved.

3.6 Major Classifications


1. Access to Programs and Data
2. Program Changes
3. Program Development
4. Computer Operations

3.6.1 Access to Programs and Data


● Risk: Unauthorized access to program and data may result in improper changes or
modification, destruction, or leak of data.
● Objectives: Access shall be limited to authorized individuals only.
● Examples:
○ Policies and procedures (Baseline standards)
○ User access provisioning/de-provisioning
○ Regular access reviews
○ Password requirements
○ Privileged accounts
○ Segregation of duties
○ Encryption mechanisms
○ System authentication
○ Physical access controls
■ Door locks
■ Turnstiles
■ CCTVs

[Link] Information Security Policy/User Awareness


● Controls are in place to help determine access to programs and data controls are
implemented in a consistent manner by issuing and maintaining an information security
policy
● Employees are aware of their roles and responsibilities
● Control Example:
○ Approval and regular review of security policies
○ New hires complete an online exam or acknowledgment form regarding security
policies
○ Annual information training/update to all empbyees

[Link] Configuration of Access Rules


● Authorizations or access rights are assigned various roles to help reduce risk of
unauthorized access.
● Ability to change access rights and roles is restricted and is carried out in a controlled
manner.
● Control Example:
○ Roles in the system are defined based on job responsibilities and are authorized
by the system owner.
○ Changes to roles and responsibilities are authorized by management.
● Excessive full system admin access
● “Super User" access
● Overall ability to override process-level controls
● Control Example:
○ Developers are appropriately restricted from accessing the production
environment
○ Access to modify, delete user profiles is restricted.
[Link] Identification and Authentication
● Logical access controls are in place for applications and systems to protect against
unauthorized access
● Control Example:
○ Assignment of unique user IDs to individuals.
○ Appropriate password configurations are in place
● Key Elements:
○ No shared ID's
○ Password rules (or other mechanisms) that are appropriate to the relevant risks,
including:
■ Minimum password lengths
■ Forced password changes

[Link] Physical Access


● Physical access to information systems relevant to financial reporting is appropriately
restricted to reduce the risk of unauthorized or inappropriate access
● Control Example:
○ Physical access to computer facilities is restricted.
○ Servers hosting financial applications are located in a physically secure area
where access is limited to IT Operations personnel.
● Physical Access Controls:
○ Door locks - bolting/electronic/Biometric
○ Logging - Manual/Electronic
○ Identification badges (photo IDs)
○ Video cameras/ Security guards
○ Controlled visitor access
● In smaller less complex companies, we would do very limited testing as this risk is
minimal

3.6.2 Program Changes & Development


● Risk: Inappropriate changes to systems or programs may result in inaccurate data.
● Objectives: All changes to existing systems, as well as new systems to be implemented,
are properly authorized, tested, approved, implemented, and documented.
● Examples:
○ Change management procedures
○ System development methodologies
○ Authorization, development, implementation, testing,
○ approval, and documentation
○ Migration to the production environment
○ Configuration change management
○ Emergency change management
○ Version controls
○ Data migration procedures
○ Cut-over procedures
○ Post-implementation reviews

[Link] Program Changes Overview


Program Change Control Categories:
● Authorization, development, testing, and approval
● Migration to the production environment
● Configuration changes
● Emergency changes

[Link] Program Changes (Workflow)


1. Change is requested
2. Analyzed, recorded and authorized
3. Prioritized and scheduled
4. Developed in test environment
5. Tested, validated and approved in test environment
6. Migrated
7. Change ticket is closed

[Link] Different "Environments"


1. Development Environment
2. Test Environment
3. Live/Production Environment
● These are ideally separated, or isolated from each other
● E.g. located on different servers, different areas within a server (usually protected or
"partitioned"), some times a different physical location

3.6.3 Computer Operations


● Risk: Systems or programs may not be available for users or may not be processing
accurately.
● Objectives: Systems and programs are available and processing accurately.
● Examples:
○ Batch job processing
○ Job Monitoring (completed or failed)
○ Backup and recovery procedures
○ Incident and problem management
○ Changes to the batch job schedules
○ Environmental controls addressing
○ Disasters such as Fire, Flood, Earthquake, etc.
○ Temperature and Humidity
○ Light and ventilation
○ Other Hazards
○ Disaster Recovery Plan (DRP) and Business Continuity
○ Plan (DRP)
○ Patch management

[Link] Job Processing


● Determine whether adequate controls for computer operations have been established by
management to verify that system/application processing is appropriately authorized
and scheduled and deviations from scheduled processing are identified and resolved.
● Control Example:
○ Scheduled production jobs or batches are monitored daily for successful
completion. Failed jobs are identified and re-executed for completion.

[Link] Backup And Recovery Procedures


● Appropriate backup and recovery procedures and controls to help verify that data
transactions and programs that are necessary for financial reporting can be recovered.
○ Effective procedures exist and are followed
○ Appropriate controls over the backup media
● Control Example:
○ Backups of the operating system, applications and data are performed on a
periodic basis to meet business requirements.
○ Backup media is maintained and secured within the Data Center and access is
restricted to authorized individuals.
○ Backup media is rotated and secured at an offsite location accessible to
authorized individuals.

[Link] Incident And Problem Management


● Controls in place to help ensure that processing problems are identified and resolved in a
timely manner
● Control Example:
○ Issues are recorded and tracked to resolution

[Link]. Other Security Controls


Preventive Detective Corrective Compensatory

Security Awareness Training System Monitoring OS Upgrade Backup Generator


Backup Data
Firewall IDS Restoration Hot Site
Anti-Virus Anti-Virus Anti-Virus
Server Isolation
Vulnerability
Security Guard Motion Detector Mitigation
IPS IPS

4. IT Application Controls
Major Classification:
1. Input Controls
2. Processing Controls
3. Output Controls

4.1 Input Controls


● Purpose: To ensure the accuracy, completeness, and validity of data entered into a
system.
● Key Functions:
○ Prevent incorrect or unauthorized data from entering the system.
○ Validate data at the point of entry to minimize errors early.

4.1.1 Control Objectives


● Accuracy: Ensure the data entered matches the expected format and values (e.g.,
numeric, alphanumeric).
● Completeness: Ensure all required fields are filled and no critical information is missing.
● Authorization: Ensure only authorized users can input data or make changes to existing
records.
● Validation: Prevent entry of invalid data through validation checks.
● Error Prevention: Minimize human errors at the point of data entry

4.1.2 Examples include


● Control Totals: hash total sum of non-financial number with no meaning
● Range Test: Allow entry between range of characters or numbers
● Numerical Test: Prevent alphabetic entry in number fields
● Limit Check: Entries above particular number are prevented or requests approval
● Input Masks: Restrict data entry format (e.g., mm/dd/yy for dates).
● Error Alerts: Notify users of invalid entries.
● Authorization Checks: Ensure only authorized users can input data.
● Batch Totals: Verify totals of data batches before processing (e.g., invoice sums).
4.2 Processing Controls
● Purpose: To ensure that data is processed accurately, completely, consistently,
and as intended by the system.
● Key Functions
○ Detect and prevent errors during the processing stage.
○ Ensure that data transformations and computations are correct.

4.2.1 Control Objectives


● Accuracy: Ensure that calculations, transformations, and data processing follow
defined rules and system logic.
● Completeness: Ensure that all input data is fully processed without omissions.
● Consistency: Ensure that data is processed uniformly across all transactions or
batches.
● Error Detection: Identify and flag processing errors (e.g., incorrect computations or
data mismatches).
● Timeliness: Ensure that data is processed within required timelines to meet
operational needs.

4.2.2 Examples of Processing Controls


● Run-to-Run Totals: Verify that totals match between different stages of processing.
● Reconciliation Procedures: Compare data inputs with outputs to ensure consistency
and correctness.
● Error Handling Controls: Identify and address processing errors (e.g., dividing by
zero, missing data).
● Program Logic Controls: Ensure that calculations and business rules are applied
correctly by the system.
● Sequence Checks: Ensure transactions are processed in the correct order.
● Completeness Checks: Reject saving a record until all required fields are completed.
● Data and File Total Checks: Maintain logs of item counts and monetary totals with
date and time stamps; exact duplicate entries are flagged as errors.
● Reasonableness Checks: Verify that amounts fall within predetermined or expected
limits.
● End-of-File Procedures: Prevent additional operations from taking place once the
end of a file is reached.

4.3 Output Controls


● Purpose: To ensure the accuracy, completeness, security, and proper
distribution of system-generated outputs.
● Key Functions:
○ Validate that outputs are accurate and delivered to the correct recipients.
○ Protect sensitive outputs from unauthorized access or distribution.

4.3.1 Control Objectives


● Accuracy: Verify that outputs (e.g., reports, invoices) match processed data and
business requirements.
● Completeness: Ensure that all expected outputs are generated without missing
information.
● Distribution: Ensure outputs are delivered only to authorized recipients and in the
correct format.
● Security: Protect sensitive outputs from unauthorized access or disclosure.
● Auditability: Provide logs and evidence showing who received outputs and when.

4.3.2 Examples of Output Controls


● Reconciliation of Output Reports: Compare system outputs with expected or
control totals.
● Access Controls on Reports: Restrict access to sensitive reports and information.
● Error Listings: Generate reports showing errors identified during processing.
● Distribution Logs: Track who receives system outputs (e.g., financial reports) and
when.
● Formatting Checks: Ensure outputs are properly formatted, readable, and usable.
● Reference Documents: Logs that show what data was in memory when system
interruptions occur.
● Working Documents: Legal records such as checks, invoices, or stock certificates that
are safeguarded; these serve as audit evidence to verify that inputs match outputs.
● Exception Reporting: Highlight only unusual or abnormal data to help determine the
source of errors (e.g., human error or processing error).

You might also like