u/Cold-Meringue4200

▲ 14 r/itaudit

ITGC Scoping

Team, can someone please clarify how you approach ITGC scoping for SOX?

What I have seen as a common trend is that ITGCs generally fall under three areas: Logical Access, Change Management, and Computer Operations (job scheduling, backups, incident management, etc.).

However, when I ask how we arrived at these specific areas, or what authoritative guidance or standard drives that scope, I rarely get a definitive answer.

For example, I have seen some SOX programs include physical security and backups within ITGC scope, while others exclude them. This makes me wonder: what actually drives these differences in scope across SOX programs?

Interested in hearing how others approach and defend their ITGC scope, especially with external auditors.

reddit.com
u/Cold-Meringue4200 — 8 days ago

Itgc scoping

Team, can someone please clarify how you approach ITGC scoping for SOX?

What I have seen as a common trend is that ITGCs generally fall under three areas: Logical Access, Change Management, and Computer Operations (job scheduling, backups, incident management, etc.).

However, when I ask how we arrived at these specific areas, or what authoritative guidance or standard drives that scope, I rarely get a definitive answer.

For example, I have seen some SOX programs include physical security and backups within ITGC scope, while others exclude them. This makes me wonder: what actually drives these differences in scope across SOX programs?

Interested in hearing how others approach and defend their ITGC scope, especially with external auditors.

reddit.com
u/Cold-Meringue4200 — 8 days ago