ITGC Scoping
Team, can someone please clarify how you approach ITGC scoping for SOX?
What I have seen as a common trend is that ITGCs generally fall under three areas: Logical Access, Change Management, and Computer Operations (job scheduling, backups, incident management, etc.).
However, when I ask how we arrived at these specific areas, or what authoritative guidance or standard drives that scope, I rarely get a definitive answer.
For example, I have seen some SOX programs include physical security and backups within ITGC scope, while others exclude them. This makes me wonder: what actually drives these differences in scope across SOX programs?
Interested in hearing how others approach and defend their ITGC scope, especially with external auditors.