ITGC Access to programs and data

Program and data access corresponding to a category of ITGC. As ITGC is a general computer control, its implementation is a regulatory obligation for large companies. To this end, the external auditors will ensure its implementation and effectiveness as part of the annual audit of the accounts.

The purpose of the category is to ensure that these are properly limited to authorized persons. A common example is the case of a person who is part of the company, always has an active account and has access to sensitive data. Unauthorized access to programs and data may result in data corruption, deletion, or leakage.

To limit these risks, the category includes 5 controls on 3 layers: applications – operating systems – databases.

  • Access creations are monitored, validated by an authorized manager, and properly implemented.
  • The access rights of users who have left or are no longer legitimate (due to change of workstation for example) are deactivated in time.
  • The activity of high-privilege accounts, administrators and sensitive generic accounts is regularly monitored.
  • Access rights are subject to periodic review.
  • Passwords are correctly configured.
Previous articleAudit Steps |Common Observations |Frameworks 10282020
Next articleITGC CM 11042020
“Sean has 9 years of experience in delivering diverse IT projects and managing IT audits as both auditee and auditor. Sean is Certified Information Systems Auditor (CISA), Certified Information Security Manager (CISM), (CDPSE) Certified Data Protection Security Engineer, (PMP) Project Management Professional and has completed other related certified trainings. He has experience in implementing ISO27001 standards, executing ITGC's, PCI DSS and good knowledge of Information Systems inline with COSO & COBIT frameworks. He has managed several security tools, Access Management Review Cycle, Policies & Procedures, Audit & other integrated projects. Sean is a member of Information Systems Audit and Control Association and has completed his Bachelor’s in Management Sciences from Nigeria and currently embarking on his Master’s program at LSU. At work, his great passion is to drive process improvement, and off work he enjoys playing chess, comedy shows and spending quality time with family and friends .”