0% found this document useful (0 votes)
8 views5 pages

ITGC Risk Control Matrix

Uploaded by

kaizen335
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
8 views5 pages

ITGC Risk Control Matrix

Uploaded by

kaizen335
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd

IT GENERAL CONTROLS (ITGCs)

Risk Control Matrix & Audit Testing Procedures

Audit Department
[Audit Period & Date]

1. Executive Summary
This document presents a comprehensive Risk Control Matrix (RCM) for the IT General
Controls (ITGCs) audit conducted in accordance with the IT Audit Framework (ITAF) 5th Edition.
The RCM identifies key risk areas within ITGCs, maps existing controls, and outlines audit
testing procedures to assess control design and operating effectiveness.

The ITGCs audit focuses on the following critical areas:


• Access Control Management
• Change Management & Configuration Control
• Segregation of Duties (SoD)
• User Account Management
• System Administration & Privileged Access
• Backup & Recovery Controls
• Monitoring & Logging

2. Scope & Objectives


2.1 Scope
This audit covers IT General Controls across the organization's critical systems and
applications, including data center infrastructure, system administration, and application access
management. The audit addresses controls over:
• On-premises systems and cloud-based infrastructure
• User access provisioning and de-provisioning
• Change management and release processes
• System and security monitoring
• Incident response and audit logging

2.2 Audit Objectives


• Assess the design effectiveness of controls over ITGCs
• Evaluate the operating effectiveness of key controls
• Identify control gaps and areas of improvement
• Provide recommendations for remediation
• Document audit evidence in accordance with ITAF standards
3. Risk Control Matrix
The following table presents the Risk Control Matrix mapping identified risks to existing controls
and testing procedures.

Risk / Existing Controls Inherent Control Testing


Control Risk Risk Procedures
1. ACCESS CONTROL MANAGEMENT
Risk: Unauthorized access to systems and data
Inadequate • User access request High Medium • Inspect access
access review process • request forms •
provisioning Segregation of Trace 15-20
and de- request/approval roles • access requests •
provisioning Access termination Review
procedures checklist • Manager termination
access reviews procedures
Lack of • PAM tool High Medium • Verify PAM tool
privileged implementation • configuration •
access Privileged account Test 10 privileged
management logging • Session user actions •
controls recording • Restricted Review audit logs
privilege granting for anomalies
Missing or • Quarterly user access High Low • Obtain last 3
ineffective reviews • Manager access reviews •
access reviews attestation process • Verify manager
System-generated sign-off • Test
access reports • remediation of
Remediation tracking removed access

2. CHANGE MANAGEMENT & CONFIGURATION CONTROL


Risk: Unauthorized changes to systems; loss of system integrity
Informal or • Change advisory High Medium • Obtain change
missing board (CAB) • Change policy
change control request documentation documentation •
procedures • Approval workflow • Trace 15 changes
Implementation & back- through process •
out plans Verify CAB
approval
Insufficient • Environment isolation High Medium • Review network
separation controls • Separate configuration •
between credentials per Test access from
dev/test/prod environment • Firewall dev to prod •
rules enforcing Verify code
segmentation • Code deployment logs
promotion process

3. SEGREGATION OF DUTIES (SoD)


Risk: Fraud, unauthorized transactions, data manipulation
Critical SoD • Role-based access High High • Extract user role
conflicts in control (RBAC) • matrix • Identify
financial Conflicting roles SoD conflicts •
systems monitoring • Test critical
Request/Approval transactions
workflow
Lack of SoD • Periodic SoD conflict High Medium • Request last
monitoring & analysis • Executive SoD analysis •
remediation management review • Review
Conflict remediation remediation
plan evidence

4. USER ACCOUNT MANAGEMENT


Risk: Obsolete accounts; unauthorized account elevation
Orphaned or • Periodic user account High Medium • Request user
inactive user review • Inactive account inventory
accounts account disable policy • • Identify inactive
Deprovisioning accounts (>90
procedures • Account days) • Verify
lifecycle management disable/removal
Default or • Password policy High Medium • Review
weak enforcement • MFA password policy
password implementation • settings • Test
controls Periodic password reset MFA configuration
• Account lockout after • Verify lockout
failed attempts settings

5. SYSTEM ADMINISTRATION & PRIVILEGED ACCESS


Risk: Unauthorized administrative actions; system compromise
Insufficient • Restricted admin High Medium • Review admin
admin account group membership • group members •
monitoring Privileged activity Sample 20
logging • Monthly admin privileged actions
access reviews • • Verify audit log
Session recording for retention
remote access
Shared or • Individual admin High High • Verify individual
generic admin account requirement • account usage •
credentials Multi-factor Test PAM tool
authentication • logging • Review
Privileged session shared account
logging • PAM tool policy
enforcement
4. Detailed Audit Testing Procedures
4.1 Test of Controls - Access Control Management Procedure AT-01: User Access Request
& Approval • Objective: Verify that user access is properly requested, reviewed, and approved
• Sample size: 15-20 user access requests • Testing steps: 1. Obtain list of access
requests from last 6 months 2. Select sample using stratified random sampling 3. Trace
each request to supporting documentation 4. Verify appropriate manager/approver sign-off
5. Confirm access granted matches request 6. Document any exceptions or deviations
Procedure AT-02: User Access Termination • Objective: Verify that terminated employees
have all access promptly removed • Sample size: 10-15 terminated user accounts • Testing
steps: 1. Obtain HR termination list for period under review 2. Select sample of
terminated employees 3. Verify IT deprovisioning checklist completed 4. Confirm access
removed from all systems 5. Test for any lingering system access post-termination 6.
Review severance checklist sign-off 4.2 Test of Controls - Change Management Procedure
CM-01: Change Request & Approval • Objective: Verify changes follow formal approval
process • Sample size: 15 production changes • Testing steps: 1. Obtain change log for
period under review 2. Select sample of changes across applications/systems 3. Verify
CAB approval documentation exists 4. Confirm change includes business justification 5.
Verify implementation and back-out procedures documented 6. Confirm change notification
sent to stakeholders 4.3 Test of Controls - Segregation of Duties Procedure SoD-01: Critical
Role Conflict Analysis • Objective: Identify and remediate SoD conflicts • Testing steps:
1. Extract user role matrix from system 2. Define critical SoD conflict pairs (request/approve,
approve/implement, etc.) 3. Execute SoD conflict queries 4. Document identified
conflicts 5. Verify management review and sign-off 6. Confirm remediation of identified
conflicts

5. Assessment Results & Findings


Summary of audit testing results will be documented here upon completion of fieldwork,
including identified control gaps and recommendations.

5.1 Control Assessment Scale


The following scale is used to assess control design and operating effectiveness:
Rating Design Operating Overall
Effectiveness Effectiveness Assessment
Effective Control properly Control operates as Control meets
designed to address designed; objectives objectives
risk achieved
Partially Effective Control design has Control operates but Control partially
gaps but mitigates with occasional addresses risk
some risk deviations
Ineffective Control design is Control rarely Control does not
inadequate; minimal operates as adequately address
risk mitigation designed risk
Not Present No control exists to N/A Risk unmitigated
address risk
6. Recommendations
Based on the audit findings, the following recommendations are proposed for management
consideration:
1. Implement/strengthen access control reviews on a quarterly basis
2. Formalize change management procedures and enforce approval workflows
3. Conduct periodic SoD assessments and remediate identified conflicts
4. Enhance monitoring and alerting mechanisms for critical system activities
5. Document and communicate ITGCs policies to all relevant stakeholders

7. Conclusion
This Risk Control Matrix provides a structured approach to evaluating IT General Controls.
Continuous monitoring and periodic reassessment of these controls are essential to maintain an
effective control environment and support the organization's risk management objectives.

Appendix: ITAF Framework Alignment


This audit is conducted in accordance with the IT Audit Framework (ITAF) 5th Edition, issued by
ISACA. Key standards referenced include:
• Performance Standard 1201: Risk Assessment in Planning
• Performance Standard 1203: Engagement Planning
• Performance Standard 1204: Performance and Supervision
• Performance Standard 1205: Evidence

You might also like