Technology Risk, ITGC & Application Controls Assessment
Connecting control tests and evidence to risk-based remediation.
- Context
- Academic controls assessment
- My role
- Control evaluation, evidence documentation and recommendations
- Status
- Assessment and remediation documentation completed
- Deliverable
- Control-testing records linking observations to risk and action
Decision & evidence
Test the control, then assess the evidence
I organized findings around control objectives and test procedures. A policy describes the intended design; operating evidence is needed to establish whether that design was followed.
A missing approval record creates an evidence gap. It warrants investigation and remediation without automatically proving that the underlying change was unauthorized.
Illustrative academic example · fictional change records
From a control objective to a defensible recommendation
- Control objective
- Production changes have recorded approval before implementation.
- Test
- Compare approval and implementation timestamps for five fictional change records; inspect the supporting approval evidence.
- Observation
- One record lacks approval evidence. Four have an approval timestamp before implementation.
- Risk
- The sample cannot demonstrate consistent operation of the approval control. An unapproved change could introduce service or security risk.
- Recommendation
- Ask the control owner to resolve the evidence gap; make approval a required gate and retain its audit trail.
- Retest
- Inspect the corrected record and a fresh sample after remediation. Keep the original observation in the assessment record.
This five-record example explains the assessment method. It is not a client finding, a population failure rate or an assurance conclusion.
Overview
Evaluated the design and operating effectiveness of IT general controls and application controls across access management, change management, system operations, security and data integrity.
Objective
Identify control deficiencies and document their risk implications through structured testing and evidence, with practical remediation recommendations.
My contribution
- Evaluated control design and operating effectiveness across the defined assessment areas.
- Identified deficiencies and prepared risk-based remediation recommendations.
- Prepared structured control-testing and audit-evidence documentation aligned with NIST 800-53 and ISO 27001 principles.
Technical approach
- Organized the assessment around control objectives, test procedures, observations, risk implications and remediation actions.
- Connected the evidence and observations to the relevant control objective, separating control design from evidence of operating effectiveness.
Scope & considerations
NIST 800-53 and ISO 27001 principles guide the academic assessment. Recommendations connect the observed evidence gap to a specific control owner and a retestable action.
Outcome
Demonstrates technology-risk analysis, IT audit, control testing, audit-evidence documentation and risk-based remediation planning.