workflow
SOX ITGC Testing
SOX ITGC Testing as a modular, decision-aware workflow. It runs on the existing Audit engagement item for this ITGC cycle (audit_type: sox_testing, period_start/period_end = the test period) — enrich that item, never create a duplicate — while per-control operating-effectiveness results live on Control-hosted SOX testing workflows, one created per in-scope ITGC control per Workflow.customFields.sox.fiscalYear, each hosted directly on the Control under test. It consumes the ICFR scoping handoff package from Annual ICFR Scoping & Risk Assessment, produces the reperformable final ITGC testing package as its named deliverable, and hands the deficiencies off to SOX Deficiency Remediation. In scope: the operating-effectiveness conclusion on the ITGCs protecting in-scope financial systems, reached by referencing the controls-owned NIST 800-53 catalog and its test scripts — not by rebuilding procedures. Out of scope, owned by related workflows: scoping of significant accounts and applications (Annual ICFR Scoping & Risk Assessment), deep completeness-and-accuracy validation of system-generated populations (SOX IPE Validation), and remediation of what fails (SOX Deficiency Remediation, the downstream handoff). It can stand alone, but is designed to exchange handoff packages with these related workflows instead of duplicating repeated work.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- sox
- department
- internal-audit
- lineOfDefense
- assure
Details
- teams
- internal-audit
- it
- finance
- domains
- sox
- standards
- sox
- nist-800-53
- sourceTemplateId
- workflow-library:sox-itgc-testing
- releaseId
- sha256:eaebf4d5b6fbbc31ce2e6cc4908a6af39aeb6d2a3e5494135f364962e96fd19a
- canonicalUrl
- https://workflow-library.com/all/?w=sox-itgc-testing
- capabilities
- mappingStatus
- mapped
- lineOfDefense
- assure
- controls
- UC-AUDIT-21
- UC-ACCESS-01
- UC-ACCESS-02
- UC-ACCESS-04
- UC-CONFIG-02
- UC-ACCESS-17
- UC-ACCESS-05
- UC-ACCESS-16
- UC-ASSET-12
- UC-BCDR-12
- UC-CONFIG-03
- UC-BCDR-03
- UC-GOV-08
- UC-SDLC-06
- UC-SDLC-07
- roleIntegrity
- activityCount
- 0
- ermPhases
- lineRoles
- serviceModes
- warnings
Source
No record-specific source URL is provided.
Download workflow template · Release: sha256:eaebf4d5b6fbbc31ce2e6cc4908a6af39aeb6d2a3e5494135f364962e96fd19a
Connections
- SOX ITGC Testing tests UC-BCDR-12 — Operate IT services according to defined procedures
- SOX ITGC Testing tests UC-CONFIG-03 — Separate environments and protect production data in testing
- SOX ITGC Testing tests UC-ACCESS-17 — Execute, monitor, and recover production processing
- SOX ITGC Testing tests UC-CONFIG-02 — Authorize, test, and approve changes before production
- SOX ITGC Testing tests UC-SDLC-06 — Maintain configuration control over systems and code
- SOX ITGC Testing tests UC-BCDR-03 — Back up data and verify restorability
- SOX ITGC Testing tests UC-ACCESS-16 — Authorize, test, and approve changes and development
- SOX ITGC Testing tests UC-ACCESS-01 — Provision and deprovision accounts through a managed lifecycle
- SOX ITGC Testing tests UC-GOV-08 — Segregate conflicting duties and areas of responsibility
- SOX ITGC Testing operates UC-AUDIT-21 — Assess control effectiveness through testing and monitoring
- SOX ITGC Testing tests UC-ASSET-12 — Operate scheduled processing, backup, and availability monitoring
- SOX ITGC Testing tests UC-ACCESS-05 — Enforce approved authorizations for information and functions
- SOX ITGC Testing tests UC-ACCESS-04 — Restrict privileged rights, utilities, and unauthorized software
- SOX ITGC Testing tests UC-ACCESS-02 — Review user access rights periodically
- SOX ITGC Testing tests UC-SDLC-07 — Approve, test, and accept changes before production release