1.1.3 Scope of This Guideline
IT General Control
IT General Control is the control for employing continuously and effectively the system, on which application is
mounted, and its platform. Generally, "RCM," "Process Flow," "Process Description" are drawn up as a control
document.
277
IT General Control applies COBIT for SOX framework basically. Refer to [Appendix1. Process Structure of IT
General Controls]
1.2 Steps for Documentation of IT General Controls
1.2.1 Documentation Steps
Documentation process for IT General Control consists of two steps:
"1. Preparation for Documentation" and "2. Documentation."
(1) Preparation for Documentation
Select the systems subject to assessment, and identify IT assessment unit.
(2) Documentation
IT General Control documents, such as RCM, are prepared for each process and IT assessment unit.
1.Preparation for Documentation 2.Documentation
STEP STEP1
Prepare System List
STEP2
Select systems for
assessment
STEP3
Identify IT
Assessment Unit
STEP4
Prepare RCM
STEP5