GITC Objective 1
GITC Objective 1
System
Date Raised
No.
Ref
Risk Rating
Risk
Recommendation
Management Response
Engagement
Location:
Domain
Control Objective:
Logical security tools and techniques are implemented and configured to enable r
application system.
Application owners authorize the nature and extent of user access privileges and such priv
reviewed by application owners to ensure access privileges remain appropriate.
Control Activity:
T1.1 Understand and document the policies and procedures related to the authorization of
application systems.
Test Description:
Attributes
1
2
3
4
Testing/Interview
conducted by
Tesing Documentation
Design and Implementation Testing
Description of the Testing
Done.
D&I Conclusion:
Sample #
1
2
Phase
OE
OE
Attributes to Test
A
Sample #
1
2
etc
Phase
OE
OE
OE
Tickmark Legend
P
x
n/a
No Exceptions Noted
Exceptions noted
Not Applicable
Results Legend
OE Conclusion:
Attributes to Test
A
Workpaper Reference
Workpaper Reference
Engagement
Location:
Domain
Control Objective:
Control Activity:
Test Description:
Attributes
1
2
3
4
Testing/Interview
conducted by
Tesing Documentation
Design and Implementation Testing
Description of the
Testing Done.
D&I Conclusion:
Period of Review:
Population:
Sampling Frequency:
Number of Samples:
Sample #
1
2
Phase
OE
OE
Sample #
1
2
etc
Phase
OE
OE
OE
Tickmark Legend
P
x
n/a
No Exceptions Noted
Exceptions noted
Not Applicable
Results Legend
OE Conclusion:
Testing Document
cing
ation Testing
ess Testing
end
nd
Attributes to Test
A
Workpaper Reference
Attributes to Test
A
Workpaper Reference
Engagement
Location:
Domain
Control Objective:
Control Activity:
Test Description:
Attributes
1
2
3
4
Testing/Interview
conducted by
Tesing Documentation
Design and Implementation Testing
Description of the
Testing Done.
D&I Conclusion:
Period of Review:
Population:
Sampling Frequency:
Number of Samples:
Sample #
1
2
Phase
OE
OE
Sample #
1
2
etc
Phase
OE
OE
OE
Tickmark Legend
P
x
n/a
No Exceptions Noted
Exceptions noted
Not Applicable
Results Legend
OE Conclusion:
Testing Document
cing
er access matrix.
ation Testing
ess Testing
end
nd
Attributes to Test
A
Workpaper Reference
Attributes to Test
A
Workpaper Reference
Engagement
Location:
Domain
Control Objective:
Control Activity:
Test Description:
Attributes
1
2
3
4
Testing/Interview
conducted by
Tesing Documentation
Design and Implementation Testing
Description of the
Testing Done.
D&I Conclusion:
Period of Review:
Population:
Sampling Frequency:
Number of Samples:
Sample #
1
2
Phase
OE
OE
Sample #
1
2
etc
Phase
OE
OE
OE
Tickmark Legend
P
x
n/a
No Exceptions Noted
Exceptions noted
Not Applicable
Results Legend
OE Conclusion:
Testing Document
cing
ation Testing
ess Testing
end
nd
Attributes to Test
A
Workpaper Reference
Attributes to Test
A
Workpaper Reference
Engagement
Location:
Domain
Control Objective:
Control Activity:
Test Description:
Attributes
1
2
3
4
Testing/Interview
conducted by
Tesing Documentation
Design and Implementation Testing
Description of the
Testing Done.
D&I Conclusion:
Period of Review:
Population:
Sampling Frequency:
Number of Samples:
Sample #
1
2
Phase
OE
OE
Sample #
1
2
etc
Phase
OE
OE
OE
Tickmark Legend
P
x
n/a
No Exceptions Noted
Exceptions noted
Not Applicable
Results Legend
OE Conclusion:
Testing Document
cing
ation Testing
ess Testing
end
nd
Attributes to Test
A
Workpaper Reference
Attributes to Test
A
Workpaper Reference
Engagement
Location:
Domain
Control Objective:
Control Activity:
Test Description:
Attributes
1
2
3
4
Testing/Interview
conducted by
Tesing Documentation
Design and Implementation Testing
Description of the
Testing Done.
D&I Conclusion:
Period of Review:
Population:
Sampling Frequency:
Number of Samples:
Sample #
1
2
Phase
OE
OE
Sample #
1
2
etc
Phase
OE
OE
OE
Tickmark Legend
P
x
n/a
No Exceptions Noted
Exceptions noted
Not Applicable
Results Legend
OE Conclusion:
Testing Document
cing
ation Testing
ess Testing
end
nd
Attributes to Test
A
Workpaper Reference
Attributes to Test
A
Workpaper Reference