How to Audit User Access & ITGC Basics free PDF cover
Guide

How to Audit User Access & ITGC Basics

Audit access to critical systems — joiner, mover and leaver workflows, timely removal, privileged and dormant accounts, access recertification, and the change and logging controls behind them.

What you'll find inside

  • Why user access and ITGC matters and the outcome to aim for
  • A six-step approach from identifying critical systems and privileged functions to assessing change-management and logging
  • How to analyze privileged, shared, generic and dormant accounts and test periodic access recertification
  • An auditor prompt and a quality check to test whether your evidence supports the conclusion
  • Worked example: a former employee’s ERP account still active with purchasing rights
  • Quick reference with practical reminders and a five-question mini self-check

Best for

  • IT Auditors
  • Internal Auditors
  • Senior Internal Auditors
  • Compliance Professionals

Resource information

Format:
PDF
Pages:
6
Price:
Free
Registration:
Not required

© Salih Ahmed Islam

Related Internal Audit Resources

User Access & ITGC Checklist free PDF cover
ChecklistIT & Technology

User Access & ITGC Checklist

Verify access and core IT general controls: approved least-privilege access, prompt leaver removal, controlled privileged and service accounts, evidence-based access reviews, approved changes and tested backups.

PDF • 6 Pages • Free

Segregation of Duties Review Checklist free PDF cover
ChecklistInternal Controls

Segregation of Duties Review Checklist

Review segregation of duties end to end — risk-based conflict definitions, privileged and emergency access, users matched to current roles, tested compensating controls and remediation prioritized by business impact.

PDF • 6 Pages • Free