You are on page 1of 1

Control 

Framework in IT Environment Application Controls Character Level


• Format check

Field Level
Input Controls • Reasonableness check
• Existence check
Computer • Check digit
Applications application Ensure valid, accurate and 
controls systems and complete input data
programs Record Level
• Cross‐field check sums
• Cross‐field reasonableness check
Processing Controls
Application 
Application Controls
Internal Ensure all transactions are  Batch Controls 
systems
controls processed, no transactions are  • Control Totals
development
Associated  processed more than once, 
with specific  every transaction can be traced  Run‐to‐run Controls
applications,  through each stage of 
processing.   Audit Trail Controls
Computer such as 
General payroll, order 
service
controls Report Distribution Controls
center processing, 
Output Controls
purchases, etc. End User Controls
Ensure that system output is not 
lost, misdirected, or corrupted,  Controlling Digital Output
and that privacy is not violated.

System Development  Controls Computer Center Controls Special air conditioning 


Documentation governing  required to meet special 
Systems Development  the design, development,  Environmental Controls temperature and humidity 
Standards and implementation of  requirements.
application systems.
Ensure that system 
documentation is sufficiently  Protection from fire, flood, 
accurate and complete to  Physical Security earthquake, sabotage, power 
System  facilitate audit and maintenance  Computer  outage.
Development   activities Project planning and project  Center 
supervision. Physical access control 
Controls Controls
Project Management
Disaster recovery plan
Controls governing  Ensure 
the systems Ensure that system development  uninterrupted 
activities are properly managed  Backup and off‐site storage 
development  availability of  procedures
process directly in accordance with  Identification and correction  computer service 
affect the  management’s policies of unauthorized program  center operation
Controls over release of 
reliability of the changes data, reports, and 
application  computer programs
programs Program Change Control Identification and correction 
of application errors Capacity planning and 
that are developed
Detect unauthorized  performance monitoring
Management Controls
program maintenance. Control of access to system 
libraries Job scheduling

You might also like