You are on page 1of 3

IT audit

--------------------------------------------------------
( )
-----------------------------------------------1. IT policies
- IT (IT Policies)
- policies ( )
policies policies
2. Access to programs and data
data user , permission, acess control policies

logical and physical access control
2.1 (Segregation of duties)
- (Job description)
2.2, 2.3 2.4
-
2.2 user profile management user
- user (
IT )
- issue disable account user account
- issue user account
- issue user account 90
- issue ....
2.3 system security configurations
- configurations
share folder ( share files HR )
permissions share folder( )
- log admin/root account
- password policy
- configuration enable audit log

- issue access data


- issue admin/root account
admin/root account IT admin/root
- issue password policy set
user password 90 , password 8 ,
password 6 , ( windows, linux UNIX)
- issue enable audit log
2.4 Physical access control ( )
- server data center
maintenance server
- issue 24
- issue
- issue ( )
- issue visotor logbook ( issue )
- issue ...

3. Changes Management
3.1 Change management policy
- change ( procedure )
- issue
3.2 Program changes
( 7% 10% support 10%
)
- 3.1
- change request form
...
- issue
- issue programmer ( programmer admin )
- issue UAT (User acceptant test)
- issue approve
- issue ...
3.3 Configuration changes system configuration
( config Network router static route dynamic route
)
- 3.1
- change request form ( CC (Change control) )

CC 3.2
- issue approve
- issue UAT (User acceptant test)
( CC admin config UAT)
Changes Management

---------------- BACKUP
--- end of ans ---

You might also like