October 18, 2010

General IT Controls Related to Applications

Questions & Answers from Protiviti's "Guide to The Sarbanes-Oxley Act: Managing Application Risks and Controls"

This section of Protiviti's "Guide to the Sarbanes-Oxley Act: Managing Application Risks and Controls – Frequently Asked Questions" addresses common questions about general IT controls related to applications. Topics covered include: What does the Section 404 compliance team look for when evaluating application change controls? What elements of data management and disaster recovery should be evaluated by Section 404 compliance teams as they relate to applications? What elements should be considered with respect to the network, operating system and databases to support effective application control? And, what are interface risks and how are they managed?