Catalog / ITGC
ITGC IT General Controls · SOX
The IT general controls that underpin a SOX audit: access management, change management, IT operations & resilience, incident & security monitoring, data protection, and third-party management.
- 6
- domains
- 81
- controls
- 258
- tests the agent runs
Control catalog
Access Management
-
AM-01IT Organisation & Segregation
IT responsibilities are appropriately divided.
-
AM-02Password / Authentication Policy
Credentials meet a minimum strength/lifecycle baseline.
-
AM-03Multi-Factor Authentication (MFA)
Sensitive/exposed surfaces require more than a password.
-
AM-04Centralised Identity / SSO
Identity lifecycle changes propagate consistently.
-
AM-05Session Management / Timeout
Unattended sessions are automatically secured.
-
AM-06User Access Provisioning
Access is granted only on a documented, authorised, least-privilege basis.
-
AM-07User Access Modification (Movers)
Access stays appropriate when users change roles.
-
AM-08User Access De-provisioning (Leavers)
Access is revoked promptly on departure.
-
AM-09Periodic User Access Review
Access remains appropriate via periodic owner attestation.
-
AM-10Privileged / Administrator Access
Privileged access is restricted, justified and attributable.
-
AM-11Privileged Access Management (PAM)
Privileged sessions are brokered, recorded and just-in-time.
-
AM-12Segregation of Duties (SoD)
Conflicting duties are separated.
-
AM-13Generic / Shared / Service Accounts
Non-personal accounts are inventoried, owned and controlled.
-
AM-14Remote Access / VPN
Remote connectivity is authenticated, encrypted, restricted.
-
AM-15Database Access Controls
Direct DB access is minimised, named and logged.
-
AM-16Operating System / Server Access
OS-level access is restricted and approved.
-
AM-17Application Access (RBAC)
Application functionality is granted by least-privilege role.
-
AM-18Cloud IAM / Console (GCP)
Cloud identities follow least privilege with guardrails.
-
AM-19Physical Access (or Cloud SOC)
Physical access to processing facilities is controlled.
Change Management
-
CM-01Change Management Policy
Changes are governed by a documented, current standard.
-
CM-02Change Request & Documentation
Every change is recorded for traceability.
-
CM-03Change Authorisation
Changes reach production only after approval.
-
CM-04Testing / UAT Before Production
Changes are validated before release.
-
CM-05Environment Segregation
Dev, test and production are isolated.
-
CM-06SoD in Changes (Dev ≠ Deployer)
The author of a change cannot unilaterally release it.
-
CM-07Developer Access to Production
Standing developer prod access is minimised and controlled.
-
CM-08Code Review / Peer Approval
Code changes are independently reviewed before merge.
-
CM-09Version Control / SCM
Source code integrity and history are maintained.
-
CM-10Deployment Pipeline (CI/CD)
Releases run through a controlled, auditable mechanism.
-
CM-11Emergency Changes
Urgent changes remain controlled.
-
CM-12Rollback / Back-out Plans
Failed changes can be recovered from.
-
CM-13Patch Management
Security patches are applied timely and risk-prioritised.
-
CM-14Infrastructure / IaC Changes
Infrastructure/cloud config changes are controlled.
-
CM-15Database / Schema Change Control
DB structure and data changes are controlled.
-
CM-16SDLC Methodology
Development follows a defined, gated lifecycle.
-
CM-17Requirements & Design Approval
Systems are built to approved requirements.
-
CM-18Secure Development Standards
Security is built in, not bolted on.
-
CM-19Application Security Testing & Pen Test
Applications are tested for security pre/post release.
-
CM-20Data Conversion / Migration
Migrated data is complete and accurate.
-
CM-21Go-Live / Implementation Approval
Systems go live only when ready.
-
CM-22Post-Implementation Review
Outcomes and controls are validated after release.
-
CM-23Project Governance & Stage Gates
Significant initiatives are governed and accountable.
IT Operations & Resilience
-
OR-01IT Governance & Oversight
Technology is governed with clear accountability.
-
OR-02IT & Information Security Policies
Baseline expectations are documented and maintained.
-
OR-03IT Risk Assessment
Technology risks are identified and treated.
-
OR-04Asset & Configuration Management
IT assets are known, owned and managed.
-
OR-05Regulatory & Compliance Monitoring
Applicable obligations are tracked and assessed.
-
OR-06Job Scheduling Control
Automated processing is scheduled and access-controlled.
-
OR-07Batch Monitoring & Failure Handling
Processing failures are detected and resolved.
-
OR-08System & Infrastructure Monitoring
Health of critical systems is observed.
-
OR-09Capacity & Performance Management
Resources scale to demand.
-
OR-10Data-Centre Environmental Controls
Facilities are protected (or provider-attested).
-
OR-11Backup Policy & Execution
Data is backed up to meet recovery objectives.
-
OR-12Backup Failure Monitoring
Backup failures are surfaced and fixed.
-
OR-13Backup Restoration Testing
Backups are proven recoverable.
-
OR-14Backup Storage & Protection
Backup copies are secure and resilient.
-
OR-15Disaster Recovery Plan
Recovery from major disruption is planned.
-
OR-16DR Testing
The recovery plan actually works.
-
OR-17Business Continuity Plan
Business operations continue through disruption.
Incident & Security Monitoring
-
SM-01Logging Standard & Retention
What is logged and for how long is defined/enforced.
-
SM-02Access & Privileged Activity Logging
Security events are captured centrally and protected.
-
SM-03Time Synchronisation (NTP)
Log timestamps are reliable for forensics.
-
SM-04Security Alerting & Anomaly Monitoring
Suspicious access is detected and acted upon.
-
SM-05Endpoint Protection (EDR)
Endpoints are protected and monitored for malware.
-
SM-06Vulnerability Management
Weaknesses are found and fixed on a managed basis.
-
SM-07Security Awareness Training
Staff are equipped against human-factor threats.
-
SM-08Incident Management
IT incidents follow a consistent lifecycle.
-
SM-09Problem Management
Root causes of recurring issues are addressed.
Data Security & Protection
-
DS-01Data Classification & Handling
Data is protected per sensitivity.
-
DS-02Network Security / Firewall
Zones are segmented; rules follow least privilege.
-
DS-03Encryption at Rest
Stored sensitive/PII/crypto data is protected.
-
DS-04Encryption in Transit
Data on the wire is protected.
-
DS-05Cryptographic Key Management
Keys are managed across their lifecycle (critical for a DPT firm).
-
DS-06Secrets / API Key & Token Management
Secrets are vaulted, rotated and never hardcoded.
-
DS-07Data Retention & Secure Disposal
Data is retained and disposed per policy/regulation.
Third-Party / Vendor Management
-
VM-01Vendor / Third-Party Risk Assessment
Third-party risk is assessed before and during reliance.
-
VM-02SOC Report Review (SOC 1/2)
Outsourced controls are evidenced and gaps managed.
-
VM-03Cloud Provider Governance (GCP)
Shared-responsibility and cloud obligations are managed.
-
VM-04Outsourcing Register & MAS Compliance
Material outsourcing meets MAS expectations.
-
VM-05Third-Party Access Management
External party access is least-privilege and monitored.
-
VM-06Service Level & Performance Monitoring
Vendor delivery is monitored against commitments.