Big4Guy

Welcome to Big4Guy.com. Big4Guy is an online resource where I will share with you the latest news, insights, knowledge and some experiences as a Big 4 consultant. We will discuss some of the important issues which organisations are facing today in the areas of information security, security and controls in SAP R/3, Oracle Applications, J.D.Edwards, Peoplesoft and various other ERP's. You will also find information on latest complaince regulations like Sarbanes Oxley, Basel II and so on. Big4guy will also attempt to provide valuable resources for individuals interested in examinations the CISA, CISM, CISSP, PMP and various other security certifications considered essential for entry in any Big 4 accounting, auditing and consulting firms. You are invited to post your comments and viewpoints to posts here. I sincerely hope this online journal will be useful to everyone from a budding student to a professional in the accounting, auditing, management and consultancy professions.

Post details: Scoping ITGC Information Technology General Controls for Section 404

05/04/06

Permalink 07:27:43 am, Categories: Sarbanes Oxley, 271 words   English (US)

Scoping ITGC Information Technology General Controls for Section 404

As part of the overall control environment, ITGC information technology general controls have a major role to play. I had explained in one of my earlier posts here about evaluating IT controls. Scoping IT controls correctly can be key to successful 404 compliance. If ITGC's are not defined appropriately, same can not only result in a lot of work but also security and control issues. These security and control issues can then result in errors in financial statements. In extreme cases, deficiencies in ITGC's can even result in material errors if same are not mitigated.

Scoping for ITGC should begin with identifying the control objectives which address each of the areas of information technology general controls. Suzie, an expert on general computer controls at our firm gave me a list of areas in ITGC which can be starting point for companies scoping for ITGC. The lists looks something like this -

ITGC-General-Computers-Scoping

1. Management and organization of IT within the enterprise.
2. Management of Changes to operating systems, databases, and the overall IT infrastructure.
3. Development, maintenance and further customization of existing as well as new applications.
4. Approach towards network security.
5. Management of overall computer operations which would include taking backups, server room security, handling application bugs and errors, database security etc.
6. Segregation of duties, role of IT security, threat management can also be considered.
7. Application user management which includes user management i.e. user ID approval, removal in case of terminated or transferred employees, setting up users, providing access to new employees etc.

Related Posts

Risk Treatment Plans for SOX Compliance
IT Governance for Sarbanes Oxley
Sarbanes Oxley 404 Project Maturity Framework
Technology Tools for Sarbanes Oxley

Comments:

No Comments for this post yet...

Official Websites

Search

Google

Web Big4Guy.com

September 2008
Mon Tue Wed Thu Fri Sat Sun
<<  <   >  >>
1 2 3 4 5 6 7
8 9 10 11 12 13 14
15 16 17 18 19 20 21
22 23 24 25 26 27 28
29 30          

Misc

Syndicate this blog XML

What is RSS?