SlideShare a Scribd company logo
3
Most read
5
Most read
6
Most read
IT General Controls
An Overview
About the Company
With a proven track record of serving over 650 clients and achieving compliance for more than 200
organizations, Kratikal is a CERT-In Empanelled cybersecurity solutions provider. The company has
developed over 2,000 test cases for web, mobile, and IT environments, and successfully tested over 25,000 IT
infrastructure devices.
Why Choose Kratikal?
Expert Team
Certified cybersecurity professionals bring extensive hands-on experience to the table.
Wide-Ranging Experience
Collaborate with various sectors, including fintech, healthcare, payments, education, and
e-commerce.
Global Compliance Expertise
Internal auditors and compliance implementers are well-versed in international IT frameworks and
regulations.
Customized Solutions
Focus on delivering optimized, bespoke solutions that align with your organization’s specific
requirements.
What is IT General Controls?
IT General Controls or ITGC are guidelines that describe safety measures and procedures to keep an
organization’s technology functioning appropriately and securely.
Further simplifying it, the key areas include -
• Making sure only the right people can access sensitive information.
• Ensuring any changes to systems or software are properly planned and documented.
• Regularly saving copies of data and having plans to restore it if something goes wrong.
• Monitoring and maintaining IT systems to ensure they work as intended.
Who Needs to Follow ITGC Guidelines?
Any organization involved in managing, using, or protecting IT systems and data should follow IT
General Controls Guidelines. A few of them include -
• Publicly Traded Companies
• Financial Institutions
• Healthcare Organizations
• Government Agencies
• Companies with Sensitive Data
IT General Controls Methodology
Framework Selection
Select the framework that aligns best with enterprise goals and compliance, or combine elements as
needed.
Internal Controls Mapping
Make sure internal controls align with the framework before starting an audit.
GAP Analysis
Compare internal controls with framework controls to find any gaps.
Plan Creation and Execution
During the testing phase, create corrective plans for areas that don’t meet framework expectations.
Quality Checks of Controls
Test the controls after they are set up to make sure they work.
Mitigation Activity Monitoring
Continuously monitor controls to ensure they meet current requirements and adapt to changes.
IT General Controls Compliance Frameworks
IT General Controls are a set of basic security practices that help companies follow rules and
regulations related to their IT systems. There are three main security frameworks that organizations
rely on to maintain strong compliance:
• COSO (Committee of Sponsoring Organizations)
• COBIT (Control Objectives for Information Technology)
• ISO 27001
IT General Controls Implementation - Kratikal’s Approach
Planning
Identifying the necessary IT general controls. This involves looking at the industry, the type of data
handled, and the locations of the clients.
Defining the Scope
Estimating the timeline by working backward from the target end date, considering resources and
managed service providers (MSPs).
Risk Assessment
Assessing current processes to establish a baseline and prioritize necessary enhancements for audits
or compliance.
Designing and Implementation Controls
Developing a plan using selected IT general controls and baseline insights. Combining effective
controls with security improvements, prioritizing them for audits or compliance.
Testing the Controls
To ensure each IT general control (ITGC) works effectively, Kratikal tests every ITGC with a diverse team
to identify flaws and ensure reliability.
Contact Us :
sales@kratikal.com
+91 9289192210
B-70, Second Floor, Sector-67,
Noida (UP) - 201301
For India
(+1) 323 287 9435
400 W Peachtree St NW Atlanta,
GA, 30308, USA
For USA
THANK YOU!

More Related Content

PPTX
FRAMEWORKS AND STANDARDS-GRC,GDPR,SOX,PCI DSS,SOX,ISO
PPT
gray_audit_presentation.ppt
PPTX
Control Standards for Information Security
PPTX
Orientation in IT Audit
PDF
Control and audit of information System (hendri eka saputra)
PPTX
Governance and management of IT.pptx
PDF
Introduction to IT compliance program and Discuss the challenges IT .pdf
PPTX
MCGlobalTech Consulting Service Presentation
FRAMEWORKS AND STANDARDS-GRC,GDPR,SOX,PCI DSS,SOX,ISO
gray_audit_presentation.ppt
Control Standards for Information Security
Orientation in IT Audit
Control and audit of information System (hendri eka saputra)
Governance and management of IT.pptx
Introduction to IT compliance program and Discuss the challenges IT .pdf
MCGlobalTech Consulting Service Presentation

Similar to IT General Controls (ITGC) - A Brief Overview (20)

PDF
Lecture 06 - CoBit - Control Objectives for Information and Related Technolog...
PDF
Facility Environmental Audit Guidelines
PPTX
Cyber Security_Consultant_Nial Lande.pptx
PPTX
Week 4_Lecture_Internal Control_Student.pptx
PPTX
MCGlobalTech Service Presentation
PDF
Chapter 10 security standart
DOCX
WLS Services Brochure March 2013
PPT
Accountability Corbit Overview 06262007
PPTX
DOC-20250530-WA0008.pptx.................
PDF
20 IT Auditor questions.pdf
PPTX
Chapter 1 Security Framework
PPTX
the role of 27001 in cybersecurity pp.pptx
PDF
Best Practices for Seamless SOC 2 Certification in IT.pdf
PPTX
IT Governance Framework
PPTX
Cobit 41 framework
PPTX
What is the UK Cyber Essentials scheme?
PPTX
ISO27001_COBIT_Students.pptx
PPTX
future technology in ai and whats are the new technogies used by the government
PDF
Ebsl Technologies It Operations Internal Presentation
Lecture 06 - CoBit - Control Objectives for Information and Related Technolog...
Facility Environmental Audit Guidelines
Cyber Security_Consultant_Nial Lande.pptx
Week 4_Lecture_Internal Control_Student.pptx
MCGlobalTech Service Presentation
Chapter 10 security standart
WLS Services Brochure March 2013
Accountability Corbit Overview 06262007
DOC-20250530-WA0008.pptx.................
20 IT Auditor questions.pdf
Chapter 1 Security Framework
the role of 27001 in cybersecurity pp.pptx
Best Practices for Seamless SOC 2 Certification in IT.pdf
IT Governance Framework
Cobit 41 framework
What is the UK Cyber Essentials scheme?
ISO27001_COBIT_Students.pptx
future technology in ai and whats are the new technogies used by the government
Ebsl Technologies It Operations Internal Presentation
Ad

Recently uploaded (20)

PDF
The Role of Testing and QA in Successful Mobile App Development_Spinx Infotec...
PDF
Robert Hume San Diego_ How Firefighting Tools and Technology Have Transformed...
PPTX
AI-Powered-Mobile-App-Development-The-Future-of-Intelligent-Applications.pptx
PDF
Optimize Freight, Fleet, and Fulfillment with Scalable Logistics Solutions.pdf
PPTX
Erotic Boudoir Photography by okoh's boudoir.pptx
PDF
Understanding LA's Zero Waste Initiative
PDF
Legacy Application Modernisation Services.pdf
PDF
How Firewalls Stop Cyber Attacks Before They Happen?
PDF
Top In-Demand Occupations for Skilled Migration to Australia in 2025
PDF
Leveraging Earth Observation Data to Improve Wildfire Prevention and Manageme...
PPTX
The Rise of Work-from-Home Internships.pptx
PDF
NAV to Microsoft Dynamics 365 Business Central Upgrade in London UK (1).pdf
PDF
Profitable Farming Starts with AI in Agriculture | Rubixe
PDF
The Dark Web’s Front Door: Finding the Real Hidden Wiki
PDF
Digital Marketing Skills in Demand for 2025.pdf
PDF
Sustainable Fire Safety How AMCs Contribute to a Greener Future.pdf
PPTX
Struggles of Blind Individuals and How We Can Help..pptx
PPT
8.1 Protein energy malnutrition paedatric.ppt
PDF
Threat Intelligence Services in Abu Dhabi
PPTX
Next-Generation Airline Network & Schedule Planning
The Role of Testing and QA in Successful Mobile App Development_Spinx Infotec...
Robert Hume San Diego_ How Firefighting Tools and Technology Have Transformed...
AI-Powered-Mobile-App-Development-The-Future-of-Intelligent-Applications.pptx
Optimize Freight, Fleet, and Fulfillment with Scalable Logistics Solutions.pdf
Erotic Boudoir Photography by okoh's boudoir.pptx
Understanding LA's Zero Waste Initiative
Legacy Application Modernisation Services.pdf
How Firewalls Stop Cyber Attacks Before They Happen?
Top In-Demand Occupations for Skilled Migration to Australia in 2025
Leveraging Earth Observation Data to Improve Wildfire Prevention and Manageme...
The Rise of Work-from-Home Internships.pptx
NAV to Microsoft Dynamics 365 Business Central Upgrade in London UK (1).pdf
Profitable Farming Starts with AI in Agriculture | Rubixe
The Dark Web’s Front Door: Finding the Real Hidden Wiki
Digital Marketing Skills in Demand for 2025.pdf
Sustainable Fire Safety How AMCs Contribute to a Greener Future.pdf
Struggles of Blind Individuals and How We Can Help..pptx
8.1 Protein energy malnutrition paedatric.ppt
Threat Intelligence Services in Abu Dhabi
Next-Generation Airline Network & Schedule Planning
Ad

IT General Controls (ITGC) - A Brief Overview

  • 2. About the Company With a proven track record of serving over 650 clients and achieving compliance for more than 200 organizations, Kratikal is a CERT-In Empanelled cybersecurity solutions provider. The company has developed over 2,000 test cases for web, mobile, and IT environments, and successfully tested over 25,000 IT infrastructure devices. Why Choose Kratikal? Expert Team Certified cybersecurity professionals bring extensive hands-on experience to the table. Wide-Ranging Experience Collaborate with various sectors, including fintech, healthcare, payments, education, and e-commerce. Global Compliance Expertise Internal auditors and compliance implementers are well-versed in international IT frameworks and regulations. Customized Solutions Focus on delivering optimized, bespoke solutions that align with your organization’s specific requirements.
  • 3. What is IT General Controls? IT General Controls or ITGC are guidelines that describe safety measures and procedures to keep an organization’s technology functioning appropriately and securely. Further simplifying it, the key areas include - • Making sure only the right people can access sensitive information. • Ensuring any changes to systems or software are properly planned and documented. • Regularly saving copies of data and having plans to restore it if something goes wrong. • Monitoring and maintaining IT systems to ensure they work as intended.
  • 4. Who Needs to Follow ITGC Guidelines? Any organization involved in managing, using, or protecting IT systems and data should follow IT General Controls Guidelines. A few of them include - • Publicly Traded Companies • Financial Institutions • Healthcare Organizations • Government Agencies • Companies with Sensitive Data
  • 5. IT General Controls Methodology Framework Selection Select the framework that aligns best with enterprise goals and compliance, or combine elements as needed. Internal Controls Mapping Make sure internal controls align with the framework before starting an audit. GAP Analysis Compare internal controls with framework controls to find any gaps. Plan Creation and Execution During the testing phase, create corrective plans for areas that don’t meet framework expectations. Quality Checks of Controls Test the controls after they are set up to make sure they work. Mitigation Activity Monitoring Continuously monitor controls to ensure they meet current requirements and adapt to changes.
  • 6. IT General Controls Compliance Frameworks IT General Controls are a set of basic security practices that help companies follow rules and regulations related to their IT systems. There are three main security frameworks that organizations rely on to maintain strong compliance: • COSO (Committee of Sponsoring Organizations) • COBIT (Control Objectives for Information Technology) • ISO 27001
  • 7. IT General Controls Implementation - Kratikal’s Approach Planning Identifying the necessary IT general controls. This involves looking at the industry, the type of data handled, and the locations of the clients. Defining the Scope Estimating the timeline by working backward from the target end date, considering resources and managed service providers (MSPs). Risk Assessment Assessing current processes to establish a baseline and prioritize necessary enhancements for audits or compliance. Designing and Implementation Controls Developing a plan using selected IT general controls and baseline insights. Combining effective controls with security improvements, prioritizing them for audits or compliance. Testing the Controls To ensure each IT general control (ITGC) works effectively, Kratikal tests every ITGC with a diverse team to identify flaws and ensure reliability.
  • 8. Contact Us : sales@kratikal.com +91 9289192210 B-70, Second Floor, Sector-67, Noida (UP) - 201301 For India (+1) 323 287 9435 400 W Peachtree St NW Atlanta, GA, 30308, USA For USA