Information technology general controls


Information technology general controls are controls that apply to all systems, components, processes, and data for a given organization or information technology environment. The objectives of ITGCs are to ensure the proper development and implementation of applications, as well as the integrity of programs, data files, and computer operations.
The most common ITGCs:

General Computer Controls

ITGCs may also be referred to as General Computer Controls which are defined as:
Controls, other than application controls, which relate to the environment within which computer-based application systems are developed, maintained and operated, and which are therefore applicable to all applications. The objectives of general controls are to ensure the proper development and implementation of applications, the integrity of program and data files and of computer operations. Like application controls, general controls may be either manual or programmed. Examples of general controls include the development and implementation of an IS strategy and an IS security policy, the organization of IS staff to separate conflicting duties and planning for disaster prevention and recovery process.

Global Technology Audit Guide (GTAG)

GTAGs are written in straightforward business language to address a timely issue related to information technology management, control, and security. To date, the Institute of Internal Auditors has released GTAGs on the following topics:GTAG 1: Information Technology ControlsGTAG 2: Change and Patch Management Controls: Critical for Organizational SuccessGTAG 3: Continuous Auditing: Implications for Assurance, Monitoring, and Risk AssessmentGTAG 4: Management of IT AuditingGTAG 5: Managing and Auditing Privacy RisksGTAG 6: Managing and Auditing IT VulnerabilitiesGTAG 7: Information Technology OutsourcingGTAG 8: Auditing Application ControlsGTAG 9: Identity and Access ManagementGTAG 10: Business Continuity ManagementGTAG 11: Developing the IT Audit PlanGTAG 12: Auditing IT ProjectsGTAG 13: Fraud Prevention and Detection in the Automated WorldGTAG 14: Auditing User-developed ApplicationsGTAG 15: Formerly Information Security Governance--Removed and combined with GTAG 17GTAG 16: Data Analysis TechnologiesGTAG 17: Auditing IT Governance