Englishالعربية Soon
Under attack?
Internal audit & readiness · IT audit

Controls that are documented, and controls that operate, are two different findings.

An independent, risk-based IT audit covering governance, seventeen IT general control domains and business continuity, testing design and operating effectiveness with sampled evidence, and reporting findings by risk rating with root cause and management response.

17
ITGC domains reviewed
5
Phases, mobilization to report
COBIT · ITIL
ISO 27001 · ISO 22301
Sampled
Evidence across the audit period
Method

Understand the process, then test whether it happens

Each domain is covered in three passes. Process understanding comes first, through information-gathering meetings with the relevant personnel across departments. Walk-throughs then confirm that the described process is the one actually followed.

Controls testing follows: samples selected across the entire audit period in line with a defined sampling methodology, and evidence obtained to demonstrate operating effectiveness rather than intent.

Findings are benchmarked against COBIT, ITIL, ISO 27001 and ISO 22301, and against the requirements of your regulator, so a recommendation carries a reference rather than an opinion.

Phases

Five phases, each with a defined output

Status updates run to the project sponsor throughout, so nothing in the final report is the first time anyone has heard of it.

01
Mobilization & planning
Kick-off, scope confirmation, project plan, stakeholder identification, request for information
Project charter and plan, meeting schedule, RFI sheet
02
IT governance & organization review
IT organisational structure, roles and responsibilities, policies and procedures, segregation of duties, KPIs, licensing, SLA management, third-party and outsourcing risk, cloud governance
Governance findings, risks and recommendations
03
IT general controls review
Detailed audit of the seventeen ITGC domains across the in-scope platform and its underlying operating systems, databases and networks
ITGC deficiencies, risks and recommendations
04
Business continuity management review
BCM framework, business impact assessment and risk assessment, BCP and DRP plans and test records, disaster recovery and alternate site readiness
BCM deficiencies, risks and recommendations
05
Reporting & concluding
Draft observations validated with process owners, management responses obtained, closing meeting held, final report issued
Draft and final IT audit report / management letter
Phase 3 in detail

Seventeen IT general control domains

Applied to the core platform and the operating systems, databases and networks underneath it. Domains outside your environment are scoped out at kick-off rather than reported as not applicable at the end.

3.1
Logical access & user account management
Access provisioning and de-provisioning, generic and privileged accounts, segregation of duties, periodic access reviews, password and session controls at application, OS and database level, default password changes, network access and remote access security.
3.2
Change management & environment segregation
Whether changes are categorised, prioritised, authorised, tested and implemented per procedure; segregation between who develops, who approves and who moves code to production; separated development, test and production environments; emergency change handling and roll-back.
3.3
System acquisition, development & implementation
SDLC methodology and its alignment with business requirements; controls over acquisition, development, configuration and implementation; requirements definition, design approval and secure coding; user acceptance testing, data migration and formal go-live authorisation.
3.4
IT environment protection
Malware detection coverage, settings and updating; patch installation across systems, operating systems and databases, tested by sample; firewall and intrusion prevention effectiveness; bandwidth management and capacity alignment.
3.5
Threat & vulnerability management
Periodic vulnerability assessment of systems, databases and network devices; tracking and remediation within defined timelines; consumption of threat intelligence and advisories; security event logging, correlation and monitoring coverage; alert review and escalation.
3.6
Security incident management & response
Documented policy, procedures and playbooks; detection, classification, escalation, containment and resolution; regulatory and stakeholder breach notification within required timelines; forensic readiness and evidence preservation; post-incident review and prior incident records.
3.7
Data processing & application controls
Input, processing and output controls; interface and reconciliation controls with external parties; error identification and handling; logging that establishes who, when, where and what for critical transactions; automated controls over the business lifecycle; master and standing data changes.
3.8
Fraud & AML/CFT system controls
Fraud prevention and detection across the customer lifecycle including identity verification; transaction monitoring rules, alerting and alert disposition; sanctions, watch-list and PEP screening configuration and list currency; case management and record-keeping.
3.9
Database management
Policies and procedures; performance monitoring, tested by sample; logical access for administrative and non-named users; encryption over data and backup media and key management arrangements; data classification enforcement; data and media disposal.
3.10
Data privacy & personal data protection
Framework alignment with data protection law; lawful collection, use, retention and disposal; consent management and data minimisation; data subject rights handling; cross-border transfer, third-party sharing and contractual safeguards with processors.
3.11
Records management & audit logging
Backup of systems, applications and records; retention and restoration; controls preventing unauthorised administrator access to logs or unauthorised log changes; logging of user access and errors; periodic supervisory review of logs and user activity.
3.12
Backup and recovery
Backup and restoration procedures and their business alignment; verification that data is actually recoverable, with restoration test records; offsite storage adequacy; media management against the classification policy; configuration, source code and database backup; replication to the recovery site.
3.13
High availability
Redundancy policies for main processing units and networks; communication channel redundancy; and an environment layout review to identify single points of failure.
3.14
IT service management
Service desk operations and incident logging, categorisation, prioritisation and resolution within agreed service levels; problem management including root cause analysis of recurring incidents; IT operations and job scheduling, batch monitoring and processing failure handling.
3.15
IT asset & configuration management
Completeness and accuracy of hardware and software inventories; the asset lifecycle from acquisition to disposal; secure baseline and hardening standards for operating systems, databases and network devices, and compliance monitoring against them; end-of-life and unsupported technology.
3.16
Digital channel, API & endpoint security
Authentication, session management and secure communication on customer-facing web and mobile channels; API and integration security including authentication, authorisation and input validation; endpoint and mobile device controls including anti-malware, hardening, encryption and device management.
3.17
Data center & physical security
Physical and environmental security policies; datacenter and alternate site location and disaster exposure; measures against theft, fire, water, power loss and other hazards; environmental controls including monitoring, detection, cooling and power; physical access authorisation, visitor logging and periodic reviews.
Phase 2

Governance and organisation

Reviewed before the controls: organisational structure and reporting lines, documented roles and responsibilities, the formal IT policy set, segregation of duties within the department, KPIs and performance monitoring, software licensing compliance, SLA management and escalation, third-party and outsourcing risk including right-to-audit clauses, cloud governance arrangements, and the coverage and currency of systems documentation.

Governance and compliance →

Phase 4

Business continuity and disaster recovery

The BCM framework, policy and management system documentation; the business impact assessment and risk assessment supporting the plans; identification of critical IT resources and dependencies; alternative processing arrangements; continuity and crisis management plans, teams and roles; test plans and records from the last exercises; plan maintenance; and the actual readiness of the alternate and disaster recovery site.

Tabletop exercises →

Deliverables

What is produced, and when

Planning & initiation
Project plan and meeting schedule; communication stream; stakeholder map
Fieldwork & execution
Initial request for information sheet; audit work plan; draft list of observations
Reporting & concluding
Closing meeting agenda; final IT audit report and management letter, covering governance, ITGC and BCM deficiencies, potential risks, recommendations and management responses
Throughout
Periodic audit status updates to the project sponsor

Observations are classified by risk rating: high, medium or low, with root cause, potential risk, recommendation and the management response recorded against each. Draft observations are validated with process owners for factual accuracy before anything is finalised.

Related

Where audit findings usually go next

Risk assessment

Findings become rated risks with owners, or they are forgotten by the next budget cycle.

ISO 27001

A management system turns the same control set into something maintained rather than audited annually.

Vulnerability management

Several domains reduce to one question: is exposure being found and closed on a cycle.

Audit it before your regulator does.

A scoping call establishes the audit period, the systems in scope and which of the seventeen domains apply to your environment.