{"description":"Operate and evidence the IT general controls on a system: authentication and password configuration, access provisioning and deprovisioning, the periodic user access review, change management (testing, sign-off, logs), and subservice SOC report reliance.","edges":[{"id":"e-access-review-change-management","source":"access-review","target":"change-management"},{"id":"e-change-management-conclude","source":"change-management","target":"conclude"}],"isPublic":true,"metadata":{"capabilities":[],"controlVerbs":{},"controls":["UC-ACCESS-01","UC-ACCESS-02","UC-ACCESS-08","UC-ACCESS-09","UC-CONFIG-02","UC-ACCESS-21"],"department":"it","domains":["controls"],"library":{"aliases":[],"canonicalUrl":"https://workflow-library.com/all/?w=controls-system-itgc-operation","contentDigest":"sha256:ee939e9afca588e18417cd888bbf38732d528c8799f482833f36f760385ed30b","prerequisites":{"status":"undeclared"},"provenance":[],"releaseId":"sha256:ee939e9afca588e18417cd888bbf38732d528c8799f482833f36f760385ed30b","schemaVersion":1,"sourceTemplateId":"workflow-library:controls-system-itgc-operation"},"lineOfDefense":"operate","mappingStatus":"mapped","risks":[],"slug":"controls-system-itgc-operation","source":"coworkcanvas-gallery","standards":["iso-27001","nist-800-53","soc1","soc2"],"teams":["it"]},"name":"System ITGC Operation","nodes":[{"data":{"description":"Judge current authentication deviations and every account’s role-based disposition using reconciled joiner/mover/leaver and entitlement evidence; authorize and verify needed access removal.","instructions":"**Objective** — Judge current authentication deviations and every account’s role-based disposition using reconciled joiner/mover/leaver and entitlement evidence; authorize and verify needed access removal.\n\n**Inputs**\nThe system record, its linked controls, the identity provider and admin consoles for this system, prior-cycle evidence, and the current subservice assurance reports.\n\n**Procedure**\n*The agent prepares the combined evidence and performs the recordkeeping below. System/access owner and technical specialists owns the stated judgments and authorizations.*\n\n*Authentication & Password Configuration Review.* Confirm the authentication plane on this system still enforces the approved posture: SSO federation, MFA/2-Step Verification, and password/session policy.\n\nPull the current SSO, MFA and password/session policy configuration for this system, compare each setting to the Password & Authentication Policy, and document every deviation with an owner and a remediation date.\n\n*User Access Provisioning & Deprovisioning.* Verify the joiner-mover-leaver lifecycle operated on this system for the period: access granted on authorized request only, and leaver access revoked on time.\n\nList the period’s joiners, movers and leavers from the authoritative HR record, trace each to a provisioning or revocation event on this system, and confirm no orphaned or unauthorized account remains.\n\n*Periodic User Access Review.* Recertify that every account and privilege on this system remains appropriate to current job function.\n\nExport the full account and role list, have each entitlement reviewed against the role matrix, capture the reviewer’s disposition per account, and revoke or narrow anything not recertified.\n\n**Record in AssureSwarm**\nComplete the evidence record on this step - owner, date, population, source, conclusion, exceptions - and link the supporting evidence.\n\n**Exit criteria**\nThe configuration matches policy or every deviation is documented with an owner and date.\n\nEvery access change traces to an authorized event and no orphaned account remains.\n\nEvery account carries a documented recertification disposition and every revocation is executed.","kind":"task","label":"Periodic User Access Review"},"id":"access-review"},{"data":{"instructions":"**Objective**\nVerify changes to this system were tested, independently signed off, and are traceable in the deployment logs.\n\n**Inputs**\nThe system record, its linked controls, the identity provider and admin consoles for this system, prior-cycle evidence, and the current subservice assurance reports.\n\n**Procedure**\nSample the period’s changes, confirm each carries test evidence and an approval that is not the author’s, and reconcile the sample against the system’s deployment/audit logs for completeness. Record the independent reviewer’s native approval of this step to evidence the change-management review.\n\n**Record in AssureSwarm**\nComplete the evidence record on this step - owner, date, population, source, conclusion, exceptions - and link the supporting evidence.\n\n**Exit criteria**\nEvery sampled change has test evidence, segregated sign-off, and a matching log entry.","kind":"task","label":"Change Management: Testing, Sign-off & Deployment Logs"},"id":"change-management"},{"data":{"description":"Evaluate the SOC opinion, period coverage, exceptions and operating CUECs, then determine the supported system ITGC conclusion and accountable failure handling.","instructions":"**Objective** — Evaluate the SOC opinion, period coverage, exceptions and operating CUECs, then determine the supported system ITGC conclusion and accountable failure handling.\n\n**Inputs**\nThe system record, its linked controls, the identity provider and admin consoles for this system, prior-cycle evidence, and the current subservice assurance reports.\n\n**Procedure**\n*The agent prepares the combined evidence and performs the recordkeeping below. System control owner with vendor-assurance competence owns the stated judgments and authorizations.*\n\n*Subservice SOC Report Review (SOC 1 / SOC 2).* Confirm the vendor’s current assurance report supports continued reliance on this system, including for SOC 1 purposes where the system underpins ICFR-relevant processing.\n\nObtain the vendor’s latest SOC report and bridge letter, evaluate the opinion, exceptions and complementary user-entity controls, confirm each CUEC is met by an operating control, and record the reliance conclusion.\n\n*Conclude ITGC Operating Posture.* Conclude on the system’s ITGC operating posture for the cycle and route any failure into exception handling.\n\nAssemble the five domain records, including the vendor-reliance procedures in this checkpoint, including the vendor-reliance procedures in this checkpoint, state whether the ITGCs operated effectively for the period, open an Issue for any failed domain, and set the next cycle date.\n\n**Record in AssureSwarm**\nComplete the evidence record on this step - owner, date, population, source, conclusion, exceptions - and link the supporting evidence.\n\n**Exit criteria**\nA current report is on file, exceptions are dispositioned, and every CUEC maps to an operating control.\n\nA supported conclusion is recorded, exceptions have owners, and the next cycle is scheduled.","kind":"task","label":"Conclude ITGC Operating Posture"},"id":"conclude"}],"sourceTemplateId":"workflow-library:controls-system-itgc-operation"}
