11.15: Difference between revisions
Created page with "'''Control Activities''' '''Principle 11 - Design General Control Activities over Information Technology''' '''Attribute 11.15''' - Control activities for changing information technology prevent unauthorized or untested modifications to existing systems. To reasonably assure that changes to the configuration of information technology are necessary, work as intended, and do not cause loss of data or program integrity, changes go through a formal change management proces..." |
No edit summary |
||
| (One intermediate revision by the same user not shown) | |||
| Line 4: | Line 4: | ||
'''Attribute 11.15''' - Control activities for changing information technology prevent unauthorized or untested modifications to existing systems. To reasonably assure that changes to the configuration of information technology are necessary, work as intended, and do not cause loss of data or program integrity, changes go through a formal change management process in which they are authorized, documented, tested, and independently reviewed. This may involve requiring authorization of change requests; reviewing the changes, approvals, and testing results; and designing protocols to determine whether changes are made properly. Depending on the size and complexity of the entity, initial development or acquisition of information technology and subsequent changes to the information technology may be included in one methodology or two separate methodologies. | '''Attribute 11.15''' - Control activities for changing information technology prevent unauthorized or untested modifications to existing systems. To reasonably assure that changes to the configuration of information technology are necessary, work as intended, and do not cause loss of data or program integrity, changes go through a formal change management process in which they are authorized, documented, tested, and independently reviewed. This may involve requiring authorization of change requests; reviewing the changes, approvals, and testing results; and designing protocols to determine whether changes are made properly. Depending on the size and complexity of the entity, initial development or acquisition of information technology and subsequent changes to the information technology may be included in one methodology or two separate methodologies. | ||
'''>>>Navigational Buttons<<<''' | |||
* '''[[Index of Attributes]]''' | |||
* '''Previous Attribute - [[11.14]]''' | |||
* '''Next Attribute - [[11.16]]''' | |||
__FORCETOC__ | |||
=== Jamie's Story === | |||
No examples are available to illustrate governance gaps for this attribute. | |||
=== Election Anomalies === | |||
No examples are available to illustrate governance gaps for this attribute. | |||
Latest revision as of 10:07, 22 August 2026
Control Activities
Principle 11 - Design General Control Activities over Information Technology
Attribute 11.15 - Control activities for changing information technology prevent unauthorized or untested modifications to existing systems. To reasonably assure that changes to the configuration of information technology are necessary, work as intended, and do not cause loss of data or program integrity, changes go through a formal change management process in which they are authorized, documented, tested, and independently reviewed. This may involve requiring authorization of change requests; reviewing the changes, approvals, and testing results; and designing protocols to determine whether changes are made properly. Depending on the size and complexity of the entity, initial development or acquisition of information technology and subsequent changes to the information technology may be included in one methodology or two separate methodologies.
>>>Navigational Buttons<<<
- Index of Attributes
- Previous Attribute - 11.14
- Next Attribute - 11.16
Jamie's Story
No examples are available to illustrate governance gaps for this attribute.
Election Anomalies
No examples are available to illustrate governance gaps for this attribute.
