Project 3: Simulating an ITGC Audit

Timeline: Week 6-7
Objective: Conduct an ITGC audit for a simulated organization, including both internal and external auditing perspectives. Identify control weaknesses and recommend corrective actions.

Project Tasks:

  1. Prepare for the Audit:

    • Review the company’s ITGC documentation, including policies on access control, change management, and backup/recovery processes.
    • Identify the scope of the audit and the specific ITGC areas to focus on.
  2. Perform the Audit:

    • Test key ITGC components (e.g., user access reviews, change approval processes, system security controls).
    • Conduct interviews with stakeholders and review relevant logs, system documentation, and compliance records.
  3. Identify Weaknesses:

    • Highlight any gaps or non-compliance issues (e.g., inadequate documentation, lack of segregation of duties, or outdated risk management practices).
    • Identify root causes for each weakness and assess potential consequences (e.g., security breaches, regulatory fines, system downtime).
  4. Deliverable:

    • Audit report including audit findings, a risk assessment, and prioritized recommendations for corrective actions.
    • Present findings in a formal audit presentation.
Alert: You are not allowed to copy content or view source !!