11.15
Control Activities
Principle 11 - Design General Control Activities over Information Technology
Attribute 11.15 - Control activities for changing information technology prevent unauthorized or untested modifications to existing systems. To reasonably assure that changes to the configuration of information technology are necessary, work as intended, and do not cause loss of data or program integrity, changes go through a formal change management process in which they are authorized, documented, tested, and independently reviewed. This may involve requiring authorization of change requests; reviewing the changes, approvals, and testing results; and designing protocols to determine whether changes are made properly. Depending on the size and complexity of the entity, initial development or acquisition of information technology and subsequent changes to the information technology may be included in one methodology or two separate methodologies.
>>>Navigational Buttons<<<
- Index of Attributes
- Previous Attribute - ?
- Next Attribute - ?
