
Trace the emergence of internal audit and general controls, driven by early fraud scandals and the Sarbanes-Oxley Act of 2002 regulating annual financial and operational audits.
Assess how IT general controls safeguard confidentiality, reliability, and continuity through policies, procedures, and core components like access, change, incident management, and IT operations.
Learn the end-to-end process of user creation, from ticketing and manager verification to admin provisioning via Active Directory, including ad authenticated and non ad authenticated access.
Learn the end-to-end user termination process: raise and approve termination tickets, verify HR and AD listings, revoke network and application credentials within policy timelines.
Authorize high privileged access to production system only after ticket submission, manager approval, HR active employee validation, job responsibility assessment, and independent log reviews on a monthly basis.
Review the user access process to validate proper creation and termination and log findings. Ensure monthly reviews cover all users, verify extension and revocation tickets, and enforce segregation of duties.
The lecture explains change management testing, detailing how a change ticket from the business unit (blue team) goes to CAB for approval, followed by development, testing, migration, and production deployment.
Incident management prioritizes issues using P1 to P4, enforcing SLAs with defined response and resolution times, and auditing tickets with root cause analysis and business justification.
Explore data backup concepts, including full, incremental, and differential backups, and learn how scheduled or manual backups trigger email notifications for success or failure of server backups.
Learn the internal audit process from sending a risk office audit notification to conducting walkthroughs, collecting evidence, testing controls, and closing the audit for a given application.
ITGC (Information Technology General Controls) is a comprehensive course that explores the principles, methodologies, and practices associated with controlling and securing information technology systems within an organization. This course provides students with a solid foundation in understanding the control and security mechanisms necessary to protect and manage IT resources effectively.
The course begins by introducing students to the fundamental concepts of ITGC, including control frameworks, audit processes, and risk management techniques. Students learn about the importance of establishing and maintaining robust control environments to safeguard the confidentiality, integrity, and availability of information assets.
Throughout the course, students delve into various key areas of ITGC, such as access controls, change management, system development life cycle, data backup and recovery, and network security. They gain practical knowledge on designing and implementing access controls to ensure that only authorized individuals can access sensitive information. They also learn about change management processes to effectively manage system modifications while minimizing potential risks.
Moreover, the course emphasizes the significance of a structured system development life cycle to ensure that IT systems are designed, developed, and maintained with appropriate controls in place. Students explore strategies for data backup and recovery to ensure business continuity in the event of data loss or system failures. Additionally, they study network security measures, including firewalls, intrusion detection systems, and encryption techniques, to protect network infrastructure from unauthorized access and attacks.
By the end of the course, students acquire the skills necessary to assess, implement, and monitor IT controls. They learn to identify control deficiencies, mitigate risks, and establish best practices for maintaining a secure and well-controlled IT environment. Overall, ITGC equips students with the knowledge and skills to address the complex challenges associated with information technology controls and security.