ITGC Auditing: A Practical Guide for CISA Candidates
Information Technology General Controls (ITGCs) form the bedrock of IT audit. Master the concepts of Access, Change Management, and Operations to excel in the CISA exam and in your career.
Whether you are preparing for the CISA exam or executing a SOX compliance audit, understanding Information Technology General Controls (ITGCs) is absolutely essential. ITGCs are the foundational controls applied to IT infrastructure, applications, and databases to ensure their continuous, secure, and reliable operation.
If ITGCs fail, all the automated business controls (application controls) that rely on that system are inherently compromised. Here is a practical breakdown of the core ITGC domains you must master for your CISA certification.
1. Logical Access Controls This is arguably the highest-risk ITGC domain. It ensures that only authorized users have access to systems and data. What CISA tests: - Provisioning/Deprovisioning: How are user accounts created, and more importantly, how quickly are they disabled upon termination? (The CISA exam loves testing the risk of terminated employees retaining access). - Authentication vs. Authorization: Authentication proves who you are (passwords, MFA). Authorization dictates what you can do (RBAC). - Periodic Access Reviews (PAR): Management must review access rights regularly to ensure they remain appropriate based on the principle of least privilege.
2. Change Management Uncontrolled changes to production systems cause outages and introduce severe security vulnerabilities. What CISA tests: - Segregation of Duties (SoD): The golden rule of change management: Developers who write the code must never have the access to deploy that code into the production environment. - The Change Process: Every change must follow a strict lifecycle: Request, Assess impact, Approve (by CAB - Change Advisory Board), Test (in a separate environment), Deploy, and Post-Implementation Review. - Emergency Changes: How are break-fix scenarios handled? Emergency changes can bypass normal approvals to restore service, but they must be documented and reviewed retroactively.
3. Computer Operations (and Backup/Recovery) This domain covers the day-to-day running of the IT environment to ensure business resilience. What CISA tests: - Job Scheduling and Monitoring: Are automated batch jobs (like overnight financial reconciliations) monitored for failure? - Backups: Are backups performed regularly, encrypted, and stored offsite? Crucially, the CISA exam will test whether backups are actually tested for restoration. A backup is useless if you cannot restore from it. - Incident and Problem Management: Incident management restores service quickly; problem management finds the root cause to prevent recurrence.
Mastering these three pillars of ITGCs is critical for your CISA exam prep (specifically Domains 4 and 5) and will serve as the technical foundation for your entire IT audit career.