0% found this document useful (0 votes)
22 views9 pages

IT General Controls Overview: Key Aspects

Uploaded by

sskmwork
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
22 views9 pages

IT General Controls Overview: Key Aspects

Uploaded by

sskmwork
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd

IT General Controls (ITGC) – Detailed Overview

1. Change Management (Program & Configuration Changes)

Objective
Ensure all changes to applications, databases, infrastructure, and configurations are
authorised, tested, properly documented, implemented in a controlled manner, and are
traceable, so that changes don’t break controls, corrupt data, or introduce fraud
opportunities.

Main Types of Changes


- Application code changes (new features, bug fixes)

- Configuration changes (roles, tolerances, workflows, parameters)

- Database changes (schema, tables, stored procedures)

- Infrastructure changes (OS, network, middleware, firewalls)

- Emergency changes (urgent fixes to production issues)

- Patch management (security patches, OS/app patches)

Key Risks
- Unauthorised changes leading to hidden logic, fraud, or data manipulation

- Inadequate testing causing incorrect calculations, broken interfaces, failed reports

- Developers with direct production access bypassing controls or altering data

- Lack of version control making rollback impossible and environments inconsistent

- Poor documentation resulting in confusion and errors

Key Controls
1. Formal Change Management Policy

- Defines what a change is, types of changes (normal, emergency, standard), and roles &
responsibilities.

2. Change Request & Approval Process

- All changes logged in a change ticketing system with proper approvals and
documentation.

3. Impact Analysis
- Assessment of business, system, control, and compliance impacts.

4. Segregation of Duties (SoD)

- Developers cannot approve or migrate their own changes, and do not have unrestricted
production access.

5. Separate DEV/TEST/UAT/PROD Environments

- Changes are developed and tested before promotion to production.

6. Testing & UAT

- Documented test plans, test cases, results, and user sign-offs.

7. Controlled Migration to Production

- Only authorised release managers/IT ops migrate changes with full audit trails.

8. Emergency Change Process

- Special procedure with retrospective approvals and additional monitoring.

9. Version Control & Change History

- Use of source code/version control tools enabling rollback and traceability.

10. Documentation & Communication

- Updated SOPs, manuals, and user communication for each release.

Audit Procedures (How to Test)


- Review change management policies and procedures.

- Select sample changes (including emergency) and verify tickets, approvals, testing, and
migration evidence.

- Review access rights of developers to ensure no direct production deployments.

- Verify that key configuration changes are also controlled and documented.

2. Logical Access Management

Objective
Ensure that only authorised and appropriate users have access to systems and data, at the
right level, and that access is removed when no longer needed.

Key Risks
- Unauthorised access leading to data theft, fraud, or manipulation
- Excessive access rights enabling override of controls

- Dormant accounts used as backdoor for misuse

- Shared IDs/generic accounts resulting in lack of accountability

- Weak passwords increasing risk of compromise

Key Controls
1. Access Management Policy

- Defines processes for user creation, modification, deletion, password standards, MFA,
and privileged access.

2. User Provisioning

- New access only on approved requests; role-based access and least-privilege principle
applied.

3. User De-Provisioning

- Timely disabling/removal of access for resigned or transferred employees.

4. Periodic User Access Reviews

- Business owners review and certify access lists periodically, focusing on


critical/privileged access.

5. Privileged Access Management (PAM)

- Strict control, justification, logging, and review of admin/root access.

6. Authentication Controls

- Strong password configurations, MFA where relevant, and account lockout after failed
attempts.

7. Authorization Controls & SoD

- Roles and profiles designed to avoid conflicts; maker-checker enforced for critical
transactions.

8. Logging & Monitoring

- System logs for logins, failed attempts, privileged activities; regular review of exceptions.

9. Generic/Shared Accounts

- Minimized and tightly monitored; primarily limited to service/system accounts.


Audit Procedures (How to Test)
- Review access management and password policies.

- Test samples of new, modified, and terminated users for proper approvals and timely
changes.

- Review privileged user lists and their appropriateness.

- Verify configuration of password settings and authentication mechanisms.

- Review evidence of periodic user access reviews.

3. Physical Access & Security

Objective
Protect IT assets, servers, network equipment, and data centres from physical damage,
theft, or unauthorised physical access.

Key Risks
- Unauthorised physical entry leading to tampering, theft, or malicious hardware insertion

- Damage due to fire, water, heat, humidity, or power failures

- Loss/theft of devices causing data leakage

- No physical logs, making incident investigation difficult

Key Controls
1. Physical Access Restriction

- Limited access to data centres and server rooms through access cards, biometrics,
security guards.

2. Access Logging & Monitoring

- Automated logs and CCTV monitoring of entry/exit points and critical areas.

3. Physical Security Policies

- Rules on devices, media, photography, and vendor/visitor management.

4. Environmental Controls

- Fire detection/suppression, temperature and humidity control, water leak detection.

5. Power & Redundancy

- UPS, generators, surge protection, and proper grounding.

6. Asset Management
- Tagging and tracking IT assets with periodic physical verification.

7. Media Handling & Storage

- Secure storage and transport of backup media; secure disposal/destruction of obsolete


media.

Audit Procedures (How to Test)


- Physically inspect server rooms/data centres and observe access mechanisms.

- Review lists of individuals with physical access and confirm appropriateness.

- Inspect CCTV coverage and retention policies.

- Review evidence of maintenance for environmental and power controls.

- Inspect asset registers and sample physical verification records.

4. Backup & Restoration

Objective
Ensure that data and system configurations are backed up regularly and can be restored
correctly and completely when needed.

Key Risks
- Permanent data loss from hardware failure, cyber incidents, or human error

- Backups not taken, incomplete, or corrupted

- Inability to restore within required time

- Backups stored only onsite and affected by the same disaster as production

Key Controls
1. Backup Policy

- Defines scope, frequency, retention, and storage locations for backups.

2. Automated Backup Jobs

- Scheduled backups via backup tools with monitoring and alerts.

3. Offsite/Cloud Storage

- Copies of backups maintained in separate physical or cloud locations.

4. Backup Security

- Encryption of backup data and restricted access to backup media.


5. Backup Monitoring & Reporting

- Regular review of backup job success/failure and remediation.

6. Periodic Restoration Testing

- Test restores performed to verify data integrity and recovery times.

7. Documentation

- Documented backup schedules, responsibilities, and restore procedures.

Audit Procedures (How to Test)


- Review backup policies and coverage for critical systems.

- Inspect backup job logs and reports for a defined period.

- Verify existence and security of offsite/cloud backup copies.

- Review evidence of recent restore tests and their results.

- Where feasible, observe or request a test restore of non-production data.

5. Incident Management

Objective
Ensure that IT incidents, including security incidents, are identified, recorded, classified,
investigated, resolved, and reported in a structured manner.

Definition of Incident
Any unplanned interruption or reduction in the quality of an IT service, or any significant
security event.

Key Risks
- Incidents not recorded, leading to repeat issues

- Security incidents not escalated, leading to prolonged exposure

- Root causes not addressed, resulting in recurring outages

- Poor communication to stakeholders, increasing business impact

Key Controls
1. Incident Management Policy/Procedure

- Defines what constitutes an incident and the end-to-end process.

2. Centralised Incident Logging

- All incidents logged and tracked in a service desk/ticketing tool.


3. Prioritisation & SLAs

- Classification by severity and impact; defined SLAs for resolution.

4. Root Cause Analysis (RCA)

- Formal RCA for major or recurring incidents, with corrective and preventive actions.

5. Security Incident Handling

- Special process for security events including containment, investigation, and reporting.

6. Incident Reporting & Metrics

- Regular dashboards/reports showing volumes, types, and SLA adherence.

7. Integration with Change & Problem Management

- Incident trends informing problem records and system changes.

Audit Procedures (How to Test)


- Review incident management policies and procedures.

- Obtain incident logs for a sample period and review classification, response, and closure.

- Verify that major incidents have RCA and documented corrective actions.

- Review handling and escalation of security incidents.

- Analyse metrics and reports to ensure ongoing monitoring and improvement.

6. Business Continuity Planning (BCP) & Disaster Recovery (DR)

Objective
Ensure the organisation can continue or quickly resume critical business operations in case
of serious disruption, and that IT systems and data can be recovered within acceptable time
and data loss limits.

Key Concepts
- Business Impact Analysis (BIA): identifies critical processes, dependencies, and maximum
tolerable downtime.

- Recovery Time Objective (RTO): target time to restore a system/process.

- Recovery Point Objective (RPO): maximum acceptable data loss measured in time.

Key Risks
- Extended downtime causing financial and reputational damage

- Inability to process critical transactions or meet regulatory requirements


- Permanent data loss

- Poor coordination during crises leading to ineffective response

Key Controls – BCP


1. Business Continuity Policy

- Organisation-wide framework and governance for continuity planning.

2. Business Impact Analysis (BIA)

- Assessment of critical processes, dependencies, and required RTO/RPO.

3. BCP Strategy

- Use of alternate sites, work-from-home, or manual workarounds.

4. BCP Plan Documentation

- Detailed procedures, contacts, and communication plans for crisis situations.

5. BCP Awareness & Training

- Training and drills to familiarise staff with their roles in a disruption.

Key Controls – DR
1. DR Strategy

- Selection and design of DR sites and technologies to meet RTO/RPO.

2. DR Plan

- Documented technical steps to fail over to DR and fail back to primary.

3. Alignment with RTO/RPO

- Ensuring DR design (replication, backups) supports business requirements.

4. DR Infrastructure & Access

- Properly configured and secured DR environment, kept up to date.

5. DR Testing

- Regular DR drills (tabletop, partial, full) with documented results.

6. Review & Maintenance

- Periodic updates to BCP and DR plans based on system changes and lessons learned.
Audit Procedures (How to Test)
- Review BCP and DR policies and documented plans.

- Confirm that BIA has been performed and is current.

- Evaluate RTO/RPO definitions and whether DR capabilities can meet them.

- Review evidence of recent BCP/DR tests, including issues and remediation.

- Assess overall governance and management oversight of BCP/DR activities.

Common questions

Powered by AI

Environmental controls are crucial in preventing physical security breaches and protecting IT infrastructure by managing risks associated with fire, temperature, humidity, and power failures. Fire suppression systems, climate control, and power redundancies like UPS and generators ensure that physical components remain operational and safe from environmental dangers. These controls protect against data loss and hardware damage, maintaining the integrity of IT systems and supporting business operations continuity .

Key challenges in performing and maintaining BCP and DR plans include ensuring plans are comprehensive and updated, integrating new technologies, and sustaining awareness and training among staff. To address these challenges, organizations should institute regular reviews and updates of BCP/DR plans, incorporate feedback from drills and actual events, invest in technology that supports rapid adaptability, and maintain ongoing communication and training programs. Effective governance ensures alignment with business goals and enhances resilience against disruptions .

Combining VPN access with Multi-Factor Authentication (MFA) enhances security by adding layers of verification for users accessing systems remotely. VPNs ensure secure data transmission by encrypting connections, while MFA requires multiple forms of verification (e.g., password and a dynamic code), decreasing the likelihood of unauthorized access even if one security layer is compromised. This multi-layered approach significantly strengthens the security posture by requiring additional evidence of identity before granting access .

Incident management practices integrate with change and problem management by using incident trends to inform problem records, which can identify root causes and guide system change implementations. By coordinating these processes, organizations can improve IT service stability and reliability, as incidents are less likely to recur due to unaddressed underlying issues. This collaboration helps ensure that incidents are resolved effectively, system changes are controlled and documented, and overall IT service quality is maintained .

Periodic user access reviews enable business owners to regularly review and certify user access lists, focusing on critical and privileged access. These reviews help ensure that users have appropriate access, which is aligned with their roles and responsibilities, and that unnecessary or dormant accounts are removed. By systematically validating user access, organizations minimize the risk of unauthorized access, data theft, and fraud, thereby strengthening security and maintaining strict compliance with access policies .

Inadequately implemented SoD controls can lead to unauthorized changes, as developers could potentially approve and implement their own changes, leading to a higher risk of concealed manipulations or fraud. It compromises the integrity of the change management process since there is no independent verification, and critical changes could be improperly documented or tested. Ensuring that duties are properly segregated helps maintain checks and balances, reducing the risk of control bypass and ensuring changes are traceable and secure .

The impact analysis step in IT change management assesses the potential effects of changes on business, system, control, and compliance, helping to mitigate risks such as unauthorised changes, inadequate testing, and bypassed controls. By understanding the implications of a change, organizations can prepare appropriate tests and documentation, ensuring all stakeholders are informed and the extent of the change is understood before it is implemented. This process reduces the likelihood of hidden issues, fraud opportunities, and data corruption .

Poor documentation in IT change management can lead to confusion, errors, and the inability to understand or trace changes, which increases the likelihood of unauthorized or improper changes and complicates troubleshooting and recovery in case of failures. These risks can be mitigated by maintaining detailed, up-to-date change logs, formal documentation of change processes, and ensuring communication with all relevant stakeholders before and after changes are implemented. Well-documented processes facilitate smooth transitions, uphold system integrity, and enhance accountability .

Automated backup systems ensure that data is consistently backed up according to defined schedules, reducing the risk of human error and oversight. Offsite or cloud storage enhances data protection by providing geographical separation between primary data and backup copies, protecting against local physical disasters. Together, they improve recovery capabilities by ensuring that complete, accurate backups are always available for restoration, safeguarding data integrity, and ensuring business continuity .

A Business Impact Analysis (BIA) identifies critical business processes, their dependencies, and assesses the maximum tolerable downtime for each process. It aligns with Recovery Time Objectives (RTO) and Recovery Point Objectives (RPO) by determining the target timeframes within which systems must be restored and the acceptable data loss periods, respectively. This alignment ensures that business continuity strategies and disaster recovery plans are effective, meet organizational needs, and support quick recovery from disruptions, thereby minimizing financial and reputational damage .

You might also like