Principle 11 - Design General Control Activities over Information

From Corrective Action Plan AZ
Revision as of 22:04, 13 August 2026 by Kelly (talk | contribs)
(diff) ← Older revision | Latest revision (diff) | Newer revision → (diff)

11.0 Design General Control Activities over Information

External Link to US GAO Green Book Principle 11

Overview

11.01

Management should design general control activities over information technology to mitigate risks to achieving the entity’s objectives to acceptable levels.

11.1 Response to Risks

11.02

Management designs general control activities over the entity’s information technology to mitigate risks to information security. Information security is the protection of information or information technology from unauthorized access, use, disclosure, disruption, modification, or destruction to provide confidentiality, integrity, and availability. The reliability of information technology used within business processes, including automated controls, depends on the selection, development, and implementation of general control activities over information technology.

11.2 Design of the Entity’s Information Technology

11.03

Management designs information technology to support the entity’s information system and business processes. The entity’s information system includes both manual and automated processes. Automated processes are wholly or partially performed using information technology.

11.04

Management designs the entity’s use of information technology in the information system by considering the defined information requirements for each of the entity’s business processes. Information technology incorporated into business processes enables information related to those processes to become available to the entity on a timelier basis. Additionally, information technology may be incorporated into control activities to enhance internal control over the processing and security of information. Although information technology implies specific types of control activities, information technology is not a “stand-alone” control consideration. It is an integral part of most control activities.

11.05

Information technology consists of the infrastructure, platforms, and software used to automate processes. Infrastructure comprises the physical information technology resources necessary to run software, including the hardware and devices used for information processing, data storage, and network communication. Infrastructure also includes the logical information technology resources necessary to run multiple virtual machines on shared physical information technology resources. Platforms comprise the logical information technology resources necessary to run application software, including operating systems and related computer programs, tools, and utilities. Software comprises application software, access control software, and other software used to perform specific functions of the entity’s business processes.

11.06

Management designs the information technology infrastructure to support the entity’s business processes. Information technology requires a physical infrastructure in which to operate, including communication networks for linking information technologies, computing resources for software and platforms to operate, and electricity to power the information technology. An entity’s information technology infrastructure can be complex. It may be owned and operated by the entity, shared by different units within the entity, or outsourced either to service organizations or to location-independent technology (e.g., cloud computing and storage) services. In designing the information technology infrastructure, management considers factors such as the expertise required to develop and maintain the information technology, costs to develop information technology internally or outsource, desired level of control over resources, and impact on continuity of operations.

11.3 Design of Appropriate Types of General Control Activities

11.07

Management designs appropriate types of general control activities to mitigate information security risks. General control activities are the actions established through policies and procedures that apply to all or a large segment of an entity’s information technology. They support the proper operation of the entity’s information technology by creating a suitable environment for effective operation of application and user control activities. When designing general control activities, management evaluates information security objectives to meet the defined information requirements. General control activities are designed to achieve one or more of the following information security objectives:

  • Confidentiality - Preserving authorized restrictions on information access and disclosure, including means for protecting privacy and sensitive information.
  • Integrity - Guarding against improper information modification or destruction, which includes ensuring information’s non-repudiation and authenticity.
  • Availability - Ensuring timely and reliable access to and use of information, thus preventing the disruption of access to or use of information or information technology.

11.08

The nature, timing, and precision of general control activities will depend on various factors, such as the complexity of the technology, sensitivity of information, use of service organizations, use of shared service or data centers, and risk of the underlying business process being supported.

11.09

General control activities may be applied at the entity, system, and business process levels.

General control activities include the following:

  • Security management - A separate process, addressing all components of internal control, for responding to risks related to information security.
  • Logical and physical access - Control activities that restrict access to information technology to authorized users.
  • Configuration management - Control activities to develop and maintain the operating and security features of information technology and control changes to their configuration.
  • Segregation of duties - Separating control activity responsibilities related to information technology to prevent individuals from controlling all critical stages of a process or overriding automated processes.
  • Contingency planning - Control activities that maintain the continuity of operations and rely on information technology, including contingency plans for recovery after a disruption of service.

11.10

Security management is the ongoing process for mitigating information security risks as part of the entity’s overall internal control system (sometimes referred to as a security management program). This ongoing process covers all components of internal control related to information security risks.

11.11

Logical and physical access control activities include restricting access or detecting inappropriate access to information and information technology. They protect information technology resources against unauthorized access, use, disclosure, disruption, modification, or destruction, whether from malicious intent or error. Logical access control activities require users to authenticate themselves and restrict them to the applications or functions commensurate with their assigned responsibilities, supporting an appropriate segregation of duties. Management may grant different permissions to employees and end users, including the rights to create, read, edit, or delete a file; execute a program; and retrieve or update information in a database. Management designs other control activities to promptly update access rights when employees change job functions or leave the entity. Physical access control activities involve restricting physical access to information and information technology, including the physical infrastructure, and protecting it from intentional or unintentional loss or impairment.

11.12

Configuration management control activities involve the identification and management of operating and security features for information technology (i.e., infrastructure, platforms, and software) throughout the technology development process. Management may use a technology development methodology to provide a structure for a new information technology design by outlining specific phases and documenting requirements, approvals, and checkpoints within control activities over the development, maintenance, and change of technology. Management evaluates the objectives and risks of the new technology in designing control activities over its technology development methodology.

11.13

Control activities for developing information technology, commonly referred to as systems development controls, prevent the use of unauthorized or untested systems. Management may internally develop information technology, acquire it from suppliers, or outsource its development to service organizations. Management incorporates methodologies for acquisition into its development process and designs control activities over the selection, ongoing development, and maintenance of information technology. For a system developed internally, management designs control activities to mitigate risks in outsourced technology before it is incorporated into the entity’s business processes. Management evaluates the unique risks that using a service organization, search engine, or artificial intelligence software present to the completeness, accuracy, and validity of information submitted to and received from the organization or software system.

11.14

Control activities for maintaining information technology include identifying vulnerabilities to patch and other functional updates to be made. Management continuously monitors the entity’s information technology to establish a baseline for evaluating performance, detecting underlying deficiencies before they negatively impact users, collecting data when risks occur, and enabling continuous improvement. Vulnerability management is the process of identifying system vulnerabilities where change may be necessary for remediation. Management may identify vulnerabilities through continuous monitoring of characteristics such as the type of technology used, physical entry points, and trends in user activity. Management may use monitoring software that automatically notifies appropriate personnel when a breach or irregularity is identified. Management may also perform penetration testing of the system to identify vulnerabilities that a hacker might exploit. Patch management is the process of applying platform and software updates to close security vulnerabilities and improve functionality. Management implements control activities to periodically or automatically update antivirus software, apply patches to correct security issues, and scan for and remove unauthorized access points.

11.15

Control activities for changing information technology prevent unauthorized or untested modifications to existing systems. To reasonably assure that changes to the configuration of information technology are necessary, work as intended, and do not cause loss of data or program integrity, changes go through a formal change management process in which they are authorized, documented, tested, and independently reviewed. This may involve requiring authorization of change requests; reviewing the changes, approvals, and testing results; and designing protocols to determine whether changes are made properly. Depending on the size and complexity of the entity, initial development or acquisition of information technology and subsequent changes to the information technology may be included in one methodology or two separate methodologies.

11.16

Segregation of duties control activities help prevent fraud, waste, and abuse from being executed using information technology in the internal control system and mitigate the risk of management override of automated processes. Management considers the need to separate responsibilities for control activities related to the entity’s information technology so that one individual does not control all critical stages of a process. This may include separating responsibilities for designing, testing, and implementing new systems or for processing transactions and managing databases.

11.17

Contingency planning protects critical and sensitive data against loss and allows for critical operations to continue without disruption or be promptly resumed when unexpected events occur. Maintaining technology through contingency planning often includes backup and recovery procedures, as well as continuity of operations plans, depending on the risks and consequences of a full or partial power systems outage or other disruption of service. Recovery plans are tested periodically in disaster simulation exercises to determine whether they will work as intended.

Assessment Observations Compared to Green Book Components, Principles, & Attributes

Control Environment

Component: Control Environment - The foundation for an internal control system. It provides the discipline and structure to help an entity achieve its objectives.

  • Principle 3 - Establish Structure, Responsibility, and Authority
    • Attributes (3.01, 3.02, 3.03, 3.04, 3.05, 3.06, 3.07, 3.08, 3.09, 3.10, 3.11, 3.12)
  • Principle 4 - Demonstrate Commitment to Competence
    • Attributes (4.01, 4.02, 4.03, 4.04, 4.05, 4.06, 4.07, 4.08)
  • Principle 5 - Enforce Accountability
    • Attributes (5.01, 5.02, 5.03, 5.04, 5.05, 5.06, 5.07, 5.08)
Risk Assessment

Component: Risk Assessment - The identification and analysis of risks facing the entity as it seeks to achieve its objectives. This assessment provides the basis for developing appropriate risk responses.

  • Principle 6 - Define Objectives and Risk Tolerances
    • Attributes (6.01, 6.02, 6.03, 6.04, 6.05, 6.06, 6.07, 6.08, 6.09, 6.10)
  • Principle 7 - Identify, Analyze, and Respond to Risks
    • Attributes (7.01, 7.02, 7.03, 7.04, 7.05, 7.06, 7.07, 7.08, 7.09, 7.10, 7.11, 7.12, 7.13, 7.14, 7.15)
  • Principle 8 - Assess Fraud, Improper Payment, and Information
    • Attributes (8.01, 8.02, 8.03, 8.04, 8.05, 8.06, 8.07, 8.08, 8.09, 8.10, 8.11, 8.12, 8.13, 8.14, 8.15, 8.16, 8.17, 8.18, 8.19, 8.20)
  • Principle 9 - Identify, Analyze, and Respond to Change
    • Attributes (9.01, 9.02, 9.03, 9.04, 9.05, 9.06, 9.07, 9.08, 9.09, 9.10, 9.11, 9.12, 9.13)
Control Activities

Component: Control Activities - The actions management establishes through policies and procedures to mitigate risks to achieving the entity's objectives to acceptable levels.

  • Principle 10 - Design Control Activities
    • Attributes (10.01, 10.02, 10.03, 10.04, 10.05, 10.06, 10.07, 10.08, 10.09, 10.10, 10.11, 10.12, 10.13, 10.14, 10.15, 10.16, 10.17, 10.18, 10.19, 10.20, 10.21, 10.22, 10.23)
  • Principle 11 - Design General Control Activities over Information
    • Attributes (11.01, 11.02, 11.03, 11.04, 11.05, 11.06, 11.07, 11.08, 11.09, 11.10, 11.11, 11.12, 11.13, 11.14, 11.15, 11.16, 11.17)
  • Principle 12 - Implement Control Activities
    • Attributes (12.01, 12.02, 12.03, 12.04, 12.05)
Information and Communication

Component: Information and Communication - The quality information management and other personnel communicate and use to support the internal control system.

  • Principle 13 - Use Quality Information
    • Attributes (13.01, 13.02, 13.03, 13.04, 13.05, 13.06, 13.07)
  • Principle 14 - Communicate Internally
    • Attributes (14.01, 14.02, 14.03, 14.04, 14.05, 14.06, 14.07, 14.08)
  • Principle 15 - Communicate Externally
    • Attributes (15.01, 15.02, 15.03, 15.04, 15.05, 15.06, 15.07, 15.08, 15.09)
Monitoring

Component: Monitoring - Activities management establishes and operates to assess the quality of performance over time and promptly resolve the findings of audits and other reviews.

  • Principle 16 - Perform Monitoring Activities
    • Attributes (16.01, 16.02, 16.03, 16.04, 16.05, 16.06, 16.07, 16.08, 16.09, 16.10)
  • Principle 17 - Evaluate Issues and Remediate Deficiencies
    • Attributes (17.01, 17.02, 17.03, 17.04, 17.05, 17.06, 17.07, 17.08)