IT General Controls (ITGC) – Detailed Overview
1. Change Management (Program & Configuration Changes)
Objective
Ensure all changes to applications, databases, infrastructure, and configurations are
authorised, tested, properly documented, implemented in a controlled manner, and are
traceable, so that changes don’t break controls, corrupt data, or introduce fraud
opportunities.
Main Types of Changes
- Application code changes (new features, bug fixes)
- Configuration changes (roles, tolerances, workflows, parameters)
- Database changes (schema, tables, stored procedures)
- Infrastructure changes (OS, network, middleware, firewalls)
- Emergency changes (urgent fixes to production issues)
- Patch management (security patches, OS/app patches)
Key Risks
- Unauthorised changes leading to hidden logic, fraud, or data manipulation
- Inadequate testing causing incorrect calculations, broken interfaces, failed reports
- Developers with direct production access bypassing controls or altering data
- Lack of version control making rollback impossible and environments inconsistent
- Poor documentation resulting in confusion and errors
Key Controls
1. Formal Change Management Policy
- Defines what a change is, types of changes (normal, emergency, standard), and roles &
responsibilities.
2. Change Request & Approval Process
- All changes logged in a change ticketing system with proper approvals and
documentation.
3. Impact Analysis
- Assessment of business, system, control, and compliance impacts.
4. Segregation of Duties (SoD)
- Developers cannot approve or migrate their own changes, and do not have unrestricted
production access.
5. Separate DEV/TEST/UAT/PROD Environments
- Changes are developed and tested before promotion to production.
6. Testing & UAT
- Documented test plans, test cases, results, and user sign-offs.
7. Controlled Migration to Production
- Only authorised release managers/IT ops migrate changes with full audit trails.
8. Emergency Change Process
- Special procedure with retrospective approvals and additional monitoring.
9. Version Control & Change History
- Use of source code/version control tools enabling rollback and traceability.
10. Documentation & Communication
- Updated SOPs, manuals, and user communication for each release.
Audit Procedures (How to Test)
- Review change management policies and procedures.
- Select sample changes (including emergency) and verify tickets, approvals, testing, and
migration evidence.
- Review access rights of developers to ensure no direct production deployments.
- Verify that key configuration changes are also controlled and documented.
2. Logical Access Management
Objective
Ensure that only authorised and appropriate users have access to systems and data, at the
right level, and that access is removed when no longer needed.
Key Risks
- Unauthorised access leading to data theft, fraud, or manipulation
- Excessive access rights enabling override of controls
- Dormant accounts used as backdoor for misuse
- Shared IDs/generic accounts resulting in lack of accountability
- Weak passwords increasing risk of compromise
Key Controls
1. Access Management Policy
- Defines processes for user creation, modification, deletion, password standards, MFA,
and privileged access.
2. User Provisioning
- New access only on approved requests; role-based access and least-privilege principle
applied.
3. User De-Provisioning
- Timely disabling/removal of access for resigned or transferred employees.
4. Periodic User Access Reviews
- Business owners review and certify access lists periodically, focusing on
critical/privileged access.
5. Privileged Access Management (PAM)
- Strict control, justification, logging, and review of admin/root access.
6. Authentication Controls
- Strong password configurations, MFA where relevant, and account lockout after failed
attempts.
7. Authorization Controls & SoD
- Roles and profiles designed to avoid conflicts; maker-checker enforced for critical
transactions.
8. Logging & Monitoring
- System logs for logins, failed attempts, privileged activities; regular review of exceptions.
9. Generic/Shared Accounts
- Minimized and tightly monitored; primarily limited to service/system accounts.
Audit Procedures (How to Test)
- Review access management and password policies.
- Test samples of new, modified, and terminated users for proper approvals and timely
changes.
- Review privileged user lists and their appropriateness.
- Verify configuration of password settings and authentication mechanisms.
- Review evidence of periodic user access reviews.
3. Physical Access & Security
Objective
Protect IT assets, servers, network equipment, and data centres from physical damage,
theft, or unauthorised physical access.
Key Risks
- Unauthorised physical entry leading to tampering, theft, or malicious hardware insertion
- Damage due to fire, water, heat, humidity, or power failures
- Loss/theft of devices causing data leakage
- No physical logs, making incident investigation difficult
Key Controls
1. Physical Access Restriction
- Limited access to data centres and server rooms through access cards, biometrics,
security guards.
2. Access Logging & Monitoring
- Automated logs and CCTV monitoring of entry/exit points and critical areas.
3. Physical Security Policies
- Rules on devices, media, photography, and vendor/visitor management.
4. Environmental Controls
- Fire detection/suppression, temperature and humidity control, water leak detection.
5. Power & Redundancy
- UPS, generators, surge protection, and proper grounding.
6. Asset Management
- Tagging and tracking IT assets with periodic physical verification.
7. Media Handling & Storage
- Secure storage and transport of backup media; secure disposal/destruction of obsolete
media.
Audit Procedures (How to Test)
- Physically inspect server rooms/data centres and observe access mechanisms.
- Review lists of individuals with physical access and confirm appropriateness.
- Inspect CCTV coverage and retention policies.
- Review evidence of maintenance for environmental and power controls.
- Inspect asset registers and sample physical verification records.
4. Backup & Restoration
Objective
Ensure that data and system configurations are backed up regularly and can be restored
correctly and completely when needed.
Key Risks
- Permanent data loss from hardware failure, cyber incidents, or human error
- Backups not taken, incomplete, or corrupted
- Inability to restore within required time
- Backups stored only onsite and affected by the same disaster as production
Key Controls
1. Backup Policy
- Defines scope, frequency, retention, and storage locations for backups.
2. Automated Backup Jobs
- Scheduled backups via backup tools with monitoring and alerts.
3. Offsite/Cloud Storage
- Copies of backups maintained in separate physical or cloud locations.
4. Backup Security
- Encryption of backup data and restricted access to backup media.
5. Backup Monitoring & Reporting
- Regular review of backup job success/failure and remediation.
6. Periodic Restoration Testing
- Test restores performed to verify data integrity and recovery times.
7. Documentation
- Documented backup schedules, responsibilities, and restore procedures.
Audit Procedures (How to Test)
- Review backup policies and coverage for critical systems.
- Inspect backup job logs and reports for a defined period.
- Verify existence and security of offsite/cloud backup copies.
- Review evidence of recent restore tests and their results.
- Where feasible, observe or request a test restore of non-production data.
5. Incident Management
Objective
Ensure that IT incidents, including security incidents, are identified, recorded, classified,
investigated, resolved, and reported in a structured manner.
Definition of Incident
Any unplanned interruption or reduction in the quality of an IT service, or any significant
security event.
Key Risks
- Incidents not recorded, leading to repeat issues
- Security incidents not escalated, leading to prolonged exposure
- Root causes not addressed, resulting in recurring outages
- Poor communication to stakeholders, increasing business impact
Key Controls
1. Incident Management Policy/Procedure
- Defines what constitutes an incident and the end-to-end process.
2. Centralised Incident Logging
- All incidents logged and tracked in a service desk/ticketing tool.
3. Prioritisation & SLAs
- Classification by severity and impact; defined SLAs for resolution.
4. Root Cause Analysis (RCA)
- Formal RCA for major or recurring incidents, with corrective and preventive actions.
5. Security Incident Handling
- Special process for security events including containment, investigation, and reporting.
6. Incident Reporting & Metrics
- Regular dashboards/reports showing volumes, types, and SLA adherence.
7. Integration with Change & Problem Management
- Incident trends informing problem records and system changes.
Audit Procedures (How to Test)
- Review incident management policies and procedures.
- Obtain incident logs for a sample period and review classification, response, and closure.
- Verify that major incidents have RCA and documented corrective actions.
- Review handling and escalation of security incidents.
- Analyse metrics and reports to ensure ongoing monitoring and improvement.
6. Business Continuity Planning (BCP) & Disaster Recovery (DR)
Objective
Ensure the organisation can continue or quickly resume critical business operations in case
of serious disruption, and that IT systems and data can be recovered within acceptable time
and data loss limits.
Key Concepts
- Business Impact Analysis (BIA): identifies critical processes, dependencies, and maximum
tolerable downtime.
- Recovery Time Objective (RTO): target time to restore a system/process.
- Recovery Point Objective (RPO): maximum acceptable data loss measured in time.
Key Risks
- Extended downtime causing financial and reputational damage
- Inability to process critical transactions or meet regulatory requirements
- Permanent data loss
- Poor coordination during crises leading to ineffective response
Key Controls – BCP
1. Business Continuity Policy
- Organisation-wide framework and governance for continuity planning.
2. Business Impact Analysis (BIA)
- Assessment of critical processes, dependencies, and required RTO/RPO.
3. BCP Strategy
- Use of alternate sites, work-from-home, or manual workarounds.
4. BCP Plan Documentation
- Detailed procedures, contacts, and communication plans for crisis situations.
5. BCP Awareness & Training
- Training and drills to familiarise staff with their roles in a disruption.
Key Controls – DR
1. DR Strategy
- Selection and design of DR sites and technologies to meet RTO/RPO.
2. DR Plan
- Documented technical steps to fail over to DR and fail back to primary.
3. Alignment with RTO/RPO
- Ensuring DR design (replication, backups) supports business requirements.
4. DR Infrastructure & Access
- Properly configured and secured DR environment, kept up to date.
5. DR Testing
- Regular DR drills (tabletop, partial, full) with documented results.
6. Review & Maintenance
- Periodic updates to BCP and DR plans based on system changes and lessons learned.
Audit Procedures (How to Test)
- Review BCP and DR policies and documented plans.
- Confirm that BIA has been performed and is current.
- Evaluate RTO/RPO definitions and whether DR capabilities can meet them.
- Review evidence of recent BCP/DR tests, including issues and remediation.
- Assess overall governance and management oversight of BCP/DR activities.