All projects
Case study 05 / 08Academic

Technology Risk, ITGC & Application Controls Assessment

Connecting control tests and evidence to risk-based remediation.

Technology risk & assurance
Context
Academic controls assessment
My role
Control evaluation, evidence documentation and recommendations
Status
Assessment and remediation documentation completed
Deliverable
Control-testing records linking observations to risk and action

Decision & evidence

Test the control, then assess the evidence

I organized findings around control objectives and test procedures. A policy describes the intended design; operating evidence is needed to establish whether that design was followed.

A missing approval record creates an evidence gap. It warrants investigation and remediation without automatically proving that the underlying change was unauthorized.

Illustrative academic example · fictional change records

From a control objective to a defensible recommendation

Control objective
Production changes have recorded approval before implementation.
Test
Compare approval and implementation timestamps for five fictional change records; inspect the supporting approval evidence.
Observation
One record lacks approval evidence. Four have an approval timestamp before implementation.
Risk
The sample cannot demonstrate consistent operation of the approval control. An unapproved change could introduce service or security risk.
Recommendation
Ask the control owner to resolve the evidence gap; make approval a required gate and retain its audit trail.
Retest
Inspect the corrected record and a fresh sample after remediation. Keep the original observation in the assessment record.

This five-record example explains the assessment method. It is not a client finding, a population failure rate or an assurance conclusion.

01

Overview

Evaluated the design and operating effectiveness of IT general controls and application controls across access management, change management, system operations, security and data integrity.

02

Objective

Identify control deficiencies and document their risk implications through structured testing and evidence, with practical remediation recommendations.

03

My contribution

  • Evaluated control design and operating effectiveness across the defined assessment areas.
  • Identified deficiencies and prepared risk-based remediation recommendations.
  • Prepared structured control-testing and audit-evidence documentation aligned with NIST 800-53 and ISO 27001 principles.
04

Technical approach

  • Organized the assessment around control objectives, test procedures, observations, risk implications and remediation actions.
  • Connected the evidence and observations to the relevant control objective, separating control design from evidence of operating effectiveness.
05

Scope & considerations

NIST 800-53 and ISO 27001 principles guide the academic assessment. Recommendations connect the observed evidence gap to a specific control owner and a retestable action.

06

Outcome

Demonstrates technology-risk analysis, IT audit, control testing, audit-evidence documentation and risk-based remediation planning.

07

Technologies

  • ITGC
  • IT Audit
  • NIST 800-53
  • ISO 27001
  • Access Management
  • Change Management
  • Control Testing
Next case studyHybrid Quantum-Classical Neural Network for DDoS DetectionView all eight projects