SOX Engine

Risk Mapping

5 assertions mapped
13 financial accounts
15 controls
F/S Assertions
Controls
ITGC-AM-001fail
access management
Timely Termination of Access
ExistenceRights & ObligationsAll Financial Accounts (system-wide access)
ITGC-AM-002pass_with_exceptions
access management
Periodic User Access Reviews
ExistenceRights & ObligationsAll Financial Accounts (system-wide access)
ITGC-AM-003fail
sod
Segregation of Duties — Conflict Detection
ExistenceValuationRights & ObligationsCompletenessAccounts PayableCash & Equivalents+2
ITGC-AM-004pass
access management
Privileged Access Monitoring
ExistenceRights & ObligationsAll Financial Accounts (system-wide access)
ITGC-CM-001pass_with_exceptions
change management
Change Approval Documentation
ExistenceCompletenessValuationAll Financial Accounts (system-wide)
ITGC-CM-002pass
change management
Developer Access to Production
ExistenceCompletenessAll Financial Accounts (system-wide)
ITGC-CM-003pass_with_exceptions
change management
Emergency Change Procedures
ExistenceCompletenessAll Financial Accounts (system-wide)
ITGC-OPS-001pass_with_exceptions
it operations
Backup Completion Verification
ExistenceCompletenessAll Financial Data (recoverability)
ITGC-OPS-002pass
it operations
Batch Job Monitoring
CompletenessAccuracyAll Financial Accounts (batch processing)
ITGC-OPS-003pass
it operations
Incident Response Documentation
ExistenceRights & ObligationsAll Financial Accounts (incident impact)
ITGC-AM-005pass
access management
Password Policy Enforcement
ExistenceRights & ObligationsAll Financial Accounts (authentication)
ITGC-AM-006pass_with_exceptions
access management
New User Provisioning Authorization
ExistenceRights & ObligationsAll Financial Accounts (system-wide access)
ITGC-CM-004pass
change management
SDLC Testing Documentation
ExistenceCompletenessAccuracyAll Financial Accounts (system integrity)
ITGC-OPS-004pass
it operations
Database Direct Access Restriction
ExistenceCompletenessValuationAll Financial Accounts (data integrity)
ITGC-OPS-005pass
it operations
Security Log Monitoring & Alerting
ExistenceCompletenessAll Financial Accounts (detection capability)
Financial Accounts