10.04.2023 Views

TIAPS Module 1 Audit and Assurance workbook

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Class of IT Examples<br />

Controls<br />

General Controls • The organizational <strong>and</strong> IT control environments.<br />

• Technical-support policies <strong>and</strong> procedures.<br />

• Policies <strong>and</strong> processes for change management.<br />

• Procedures for source code/document version-control.<br />

• St<strong>and</strong>ards for software development lifecycle.<br />

• Hardware/software configuration, installation, testing,<br />

management, st<strong>and</strong>ards, policies, <strong>and</strong> procedures.<br />

• Security policies, st<strong>and</strong>ards, <strong>and</strong> processes.<br />

• Procedures <strong>and</strong> policies for incident-management.<br />

• Procedures for back-up <strong>and</strong> disaster recovery.<br />

Application • Authentication.<br />

Controls<br />

• Authorization.<br />

• Change management.<br />

• Completeness checks.<br />

• Identification.<br />

• Input controls.<br />

• Problem management.<br />

• Validity checks.<br />

The relationships among the classification of IT controls are shown in the following graphic,<br />

adapted from GTAG: Information Technology Risks <strong>and</strong> Controls, The IIA, 2012 65 :<br />

Figure: Types of IT Controls<br />

65<br />

GTAG, Information Technology Risks <strong>and</strong> Controls, The IIA, 2012<br />

66

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!