CC5.2 COSO principle 11: Selects and develops general controls over technology
Also selects and develops general control activities over technology to support the achievement of objectives.
5
artefacts
1
held by a system
3
at each review
hard
to go live
Document repository
where the evidence lives
teal = a system already holds it · olive = produced at each review
system holds itEvidence a system already holds
- Evidence of controls over the technology infrastructure, such as change management, configuration and capacity · Ticketing / ITSM
periodic reviewEvidence produced at each review
- Evidence of general technology controls over infrastructure, security management and technology acquisition, development and maintenance · Cloud console / configuration management
- Evidence of access security controls over the technology, restricting who can affect it · Document repository
- Evidence of control over technology acquired from vendors, including cloud services · Vendor register / contract repository
governing documentDocuments that govern the control
- Dependency analysis showing which business process controls rely on technology, and therefore on these general controls · Document repository
First move
Mostly documents and reviews. Pull the 1 system-held artefact from your Ticketing / ITSM on a schedule; put the documents under version control with an owner and review date, and log each review as a dated record with a named reviewer.
Common gaps auditors find
- General controls documented for on premises infrastructure while the cloud platform hosting the service is out of scope
- Dependency between automated business controls and the general controls never identified, so a general control failure invalidates untested reliance
- Controls over technology acquisition absent, so services enter production with no control assessment
- Segregation between development and production undocumented at the technology layer
Do this for your whole sheet
Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.
Build my evidence sheetCC5.1 COSO principle 10: Selects and develops control activities to mitigate risks · CC5.3 COSO principle 12: Deploys control activities through policies and procedures