IT General Controls (ITGCs) refer to foundational IT controls that support the reliability and security of information systems across all applications. Systems development controls fall under ITGCs because they ensure that:
IT systems are developed, tested, and implemented securely.
Change management, system testing, and access controls are enforced before deployment.
Ensuring Secure Development Practices:
IIA GTAG 8: Auditing Application Controls states that strong systems development controls prevent unauthorized access and errors in IT systems.
Risk Mitigation in Software Changes:
IIA Standard 2110 – Governance requires IT governance to enforce security policies for system development.
Weak controls increase risks of security vulnerabilities and financial misstatements.
Alignment with COSO & COBIT Frameworks:
COBIT (Control Objectives for Information and Related Technologies) classifies systems development controls as an ITGC domain.
COSO Internal Control – Integrated Framework supports secure system change processes.
A. Error listings (Incorrect)
Reason: Error listings are application controls that detect transaction errors within specific processes. ITGCs support all systems, not just specific applications.
B. Distribution controls (Incorrect)
Reason: Distribution controls deal with physical/logistical distribution of information or resources, not core ITGC functions.
C. Transaction logging (Incorrect)
Reason: While transaction logging is important for data integrity and security, it is an application control, not a general IT control.
IIA GTAG 8: Auditing Application Controls – Defines IT general controls and application-specific controls.
IIA Standard 2110 – Governance – Requires secure IT development and governance structures.
COBIT & COSO Internal Control Frameworks – Classify system development controls as critical ITGCs.
Why is Answer D Correct?Analysis of Incorrect Answers:IIA References:Thus, the correct answer is D. Systems development controls.
Submit