SU 5 – Information Technology, General and
Application Controls
Session 1: Overview of Computer Controls
Categories of Computer Controls:
1. General IT Controls
Framework impacting the overall control environment.
Ensures effective functioning of application controls.
Not specific to individual assertions.
Remain in place regardless of transaction processing.
2. Application Controls
Directly address risks to information integrity within specific
applications.
Ensure data is free from fraud/error.
Related to specific assertions and business cycles.
Procedures for initiating, recording, processing, and reporting
transactions.
Classification of General Controls
Definition:
Controls over IT processes that support the proper operation of the
IT environment.
, Types of General Controls:
1. Organisational and Personnel Practices:
Responsibility and corporate structure.
Segregation of duties.
Staff practices and supervision.
2. Business Continuity:
Operating environment management.
Disaster recovery and repair.
3. System Development and Implementation:
Needs assessment, project management, planning, design,
development, testing, implementation, and post-
implementation review.
4. Change Controls:
Authorisation, development, programming, implementation,
post-implementation review, scheduling, and production runs.
5. Operating Controls:
Scheduling, production runs, operating activities, asset use,
library controls, logs, and registers.
6. Access Controls:
Security management (physical and logical), logs, and
reviews.
Organisational Controls & Personnel Practices
Definition:
Structure and management of IT department activities.
Application Controls
Session 1: Overview of Computer Controls
Categories of Computer Controls:
1. General IT Controls
Framework impacting the overall control environment.
Ensures effective functioning of application controls.
Not specific to individual assertions.
Remain in place regardless of transaction processing.
2. Application Controls
Directly address risks to information integrity within specific
applications.
Ensure data is free from fraud/error.
Related to specific assertions and business cycles.
Procedures for initiating, recording, processing, and reporting
transactions.
Classification of General Controls
Definition:
Controls over IT processes that support the proper operation of the
IT environment.
, Types of General Controls:
1. Organisational and Personnel Practices:
Responsibility and corporate structure.
Segregation of duties.
Staff practices and supervision.
2. Business Continuity:
Operating environment management.
Disaster recovery and repair.
3. System Development and Implementation:
Needs assessment, project management, planning, design,
development, testing, implementation, and post-
implementation review.
4. Change Controls:
Authorisation, development, programming, implementation,
post-implementation review, scheduling, and production runs.
5. Operating Controls:
Scheduling, production runs, operating activities, asset use,
library controls, logs, and registers.
6. Access Controls:
Security management (physical and logical), logs, and
reviews.
Organisational Controls & Personnel Practices
Definition:
Structure and management of IT department activities.