IT controls - General vs Application Controls

Поделиться
HTML-код
  • Опубликовано: 24 июл 2024
  • In this video I explain the difference between general IT controls and application IT controls.
    #InternalControls #ITControls #Auditing
    My ultimate audit video study guide is available here
    amandalovestoaudit.com/learni...
    Subscribe to watch more auditing videos
    / amandalovestoaudit
    Catch me on social media!
    / amandalovestoaudit
    / amandasaudit
    / amandalovestoaudit
    Camera - Sony A6500 + 28mm, illustrations captured on Explain Everything on the iPad Pro
    Mic - Rode SmartLav+
    Monitor - SmallHD Focus
    Lighting - Aputure 672S, Aputure AL-MC

Комментарии • 114

  • @Parmindersingh-rk8cd
    @Parmindersingh-rk8cd 4 года назад +20

    Normal it general controls are categorised into domains:
    1. Access: to application, to servers, to data centers
    2. Changes in Inscope Application and related infrastructure: if there any code changes performed in the application, or if there any such changes in the application which changes the functioning of the application (like changing the tax rate on any product), patches applied in the application, security patches made on the servers,
    3. Security: testing of Firewall, antivirus elements
    4. Other IT Operations: Scheduled jobs, interfaces, Backups, Incidents

  • @xosharonnoelle7
    @xosharonnoelle7 5 лет назад +8

    Recently found your channel and have my uni audit exam next week! Thank you so much for these videos, they are so helpful and well made!

  • @143fromRose
    @143fromRose 5 лет назад +11

    This video couldn’t have come at a better time! Currently studying this topic this week! Thank you so much!!

  • @Tony-bc1rr
    @Tony-bc1rr 4 года назад

    This is such an fantastic video with clear explanation and examples. Absolutely loving it! Keep it up Amanda will follow the channel!

  • @abdulwahabalhaji8662
    @abdulwahabalhaji8662 4 года назад +11

    Thank you so much for this video! I'm interviewing for IT Risk Consultant this week and this clarifies things for me a lot.

    • @thres34
      @thres34 3 года назад +2

      One year on, did you get the job?

    • @abdulwahabalhaji8662
      @abdulwahabalhaji8662 3 года назад +10

      I DIIIIIID and I’m a senior now!!!!

    • @funnyclips4045
      @funnyclips4045 3 года назад

      @@abdulwahabalhaji8662 hmdl 🤲🏽

    • @mrmindstorms
      @mrmindstorms 3 года назад

      Hos do you like it? :) I have my last interview tomorrow, but Reddit says it’s really boring and few exit opportunities

  • @snb1143
    @snb1143 3 года назад +3

    Thanks I really loved that video, I was really struggling with general v application controls, now all is clear.

  • @abdullahaljalil5218
    @abdullahaljalil5218 2 года назад

    This is my second presentation today
    Lots of appreciations for the these valuable videos 👍

  • @mustafa7amin7
    @mustafa7amin7 5 лет назад +16

    👍Thank You very much for great video and answering my question.
    Your way of explaining is great to understand easily within shortest time 👍

  • @sunubishwokarma1002
    @sunubishwokarma1002 2 года назад

    Great explanation, thank you so much.

  • @staceturner3442
    @staceturner3442 4 года назад +3

    Thank you, this was very informative!!!

  • @thabangmahlangu1484
    @thabangmahlangu1484 4 года назад +4

    Thank you so much, you just contributed to my exam success.

  • @shaistahsayedally9364
    @shaistahsayedally9364 4 года назад +9

    Hi Amanda. This video is really good. Can you break this down further into the 6 general controls (control environ, system development,access control, continuity, system software and doc)? Enjoy your style of lecturing. Everything fits into perspective with the videos you do.

  • @nosisagagai262
    @nosisagagai262 Год назад

    Great video Amanda☺

  • @MrKwabenajames
    @MrKwabenajames 2 года назад +1

    Amanda, it was amazing. Great job

  • @ttjordan81
    @ttjordan81 3 года назад +3

    Ha, when you got to the LMS part, literally a relational DB scheme I created years ago... 😍

  • @yositasunintaboon4455
    @yositasunintaboon4455 4 года назад +1

    thank you so much for sharing this helpful video

  • @neginitin8255
    @neginitin8255 2 года назад

    Beautifully explained in simple language

  • @JoMmEKiSs
    @JoMmEKiSs 4 года назад +1

    So wonderful thank you so much. You are great teacher

  • @JAFFER3657
    @JAFFER3657 4 года назад +3

    Thank You for this video and also to the person who requested this video, It helped a lot.

  • @tejumadeajoke9674
    @tejumadeajoke9674 4 года назад +2

    very insightful and easily illustrated

  • @DollFacePeter
    @DollFacePeter 4 года назад +8

    “Dr Amanda”
    That flexxxxxxx

  • @poonampatil7800
    @poonampatil7800 2 года назад

    Thanks for clarification 🙏🏻

  • @damibabz4100
    @damibabz4100 8 месяцев назад

    Thanks, this is great

  • @sahilkhan2470
    @sahilkhan2470 Год назад

    Thank you, this is very clear. Even my 100 euro's of textbooks can't explain like you do. gr from Amsterdam

  • @paulramalepe
    @paulramalepe 5 лет назад +2

    Thank you so much... but I want to understand the ICT controls in Revenue and receipts cycle!!! It confuses me big time.

  • @fadihijazi1658
    @fadihijazi1658 3 года назад +1

    you're awesome, thanks!

  • @madhavkikahani
    @madhavkikahani 2 года назад

    Hey Amanda..your way of teaching is just wow...can you please upload video on HIPPA with complete understanding from zero to hero

    • @amandalovestoaudit
      @amandalovestoaudit  2 года назад

      Hey - I don't know much about HIPPA (if you mean the healthcare privacy law) - sorry!

  • @RS-ws5lh
    @RS-ws5lh 2 года назад

    Hiii ur videos are superb, will u do a video on socq type2 audit

  • @yuqianzhao6567
    @yuqianzhao6567 4 года назад +1

    really helpful...thanks a lot!!!!

    • @amandalovestoaudit
      @amandalovestoaudit  4 года назад

      Thanks Yuqian!
      Don’t forget that I have a full study guide of videos on my website - amandalovestoaudit.com/learning-resources/audit-study-guide/

  • @davidesintini6708
    @davidesintini6708 5 лет назад +1

    Niceeeee!!! What about making a video where you explain the differences between an audit of private and public company?
    Keep up the work!!

  • @ceaseuno1
    @ceaseuno1 3 года назад +1

    Thank you for the video. Do you have a video on sampling IT general controls?

    • @amandalovestoaudit
      @amandalovestoaudit  3 года назад

      Hi - not yet - when sampling, the key is going to be sampling over the entire year

  • @marwanmilan811
    @marwanmilan811 2 года назад

    Would you clarify the role of a group financial controller

  • @jusappia1580
    @jusappia1580 4 года назад +1

    Thank you

  • @mikewang8479
    @mikewang8479 3 года назад +1

    您的英语讲得真好!

    • @amandalovestoaudit
      @amandalovestoaudit  3 года назад

      Hi Mike - unfortunately I can’t read Chinese characters!

  • @vuyitumelomabunda8293
    @vuyitumelomabunda8293 2 года назад

    I salute🤙

  • @berosar
    @berosar 2 года назад +1

    Nice

  • @mrbeansprout562
    @mrbeansprout562 2 года назад

    Can I ask some question?
    for access into organization network (Internal Network) >> ITGC
    but access into each application (e.g. internal application) and some time we use different credential form internal network can we call IT application control?
    So,if focus in application >> call Application Control right?

    • @amandalovestoaudit
      @amandalovestoaudit  2 года назад +1

      Yes - focus within an application is an Application Control

  • @viviannevi7164
    @viviannevi7164 5 лет назад

    Kindly do a video on cloud accounting and/or share a link where one can get more insight on what it is and how it works, pros and cons etc. Thank you in advance.

    • @amandalovestoaudit
      @amandalovestoaudit  5 лет назад

      Hey Vivianne
      Definitely check out Heather Smith for everything cloud accounting. She has a great website and be sure to sign up for her newsletter
      ruclips.net/user/ANISEConsulting

    • @jessblack9110
      @jessblack9110 4 года назад

      I need to get some more info from you are you free to go for 30 minutes

  • @ibnal-yemen2063
    @ibnal-yemen2063 3 года назад +1

    Very nice. 🌹

  • @nagendrabijur
    @nagendrabijur 3 года назад

    Batch Jobs scheduled in an application, do they come under ITGC's or ITAC? (add/modify/delete critical scheduled jobs or interfaces between in-scope SOX system)

    • @amandalovestoaudit
      @amandalovestoaudit  3 года назад +2

      Batch jobs within an application would be an Application Control ☺️

    • @nagendrabijur
      @nagendrabijur 3 года назад

      @@amandalovestoaudit thanks for the clarification and Quick reply!😁

  • @EvaSlash
    @EvaSlash 4 года назад +3

    Do you have any tips for an IT Audit SOX interview? How to impress and stand out?

    • @amandalovestoaudit
      @amandalovestoaudit  4 года назад +1

      Hi Gib Gob - do you mean going for a job in IT Audit/SOX? Or do you mean interviewing clients?
      I presume it is the latter - know your potential employer:
      * what sort of companies do they audit?
      * check out the SOX 404 reports on some of those companies - what are common issues that fall under the IT category? (rather than the manual category)
      * how would you go about detecting those sorts of major deficiencies
      And the final one - make sure you have at least 1 question for your employer that shows you want to know whether you fit in at their organisation - that may be about clients, location, travel, advancement, culture, diversity & inclusion.
      Good luck!

    • @busolaoshideko8680
      @busolaoshideko8680 4 года назад

      @@amandalovestoaudit Insightful. Thank you

  • @amitsalekar1433
    @amitsalekar1433 2 года назад

    How can you relate the IT controls with IT Audits

  • @arvindiyer4578
    @arvindiyer4578 4 года назад

    Can you explain , what is configurable and Non Configurable Controls and explain with an example

    • @amandalovestoaudit
      @amandalovestoaudit  4 года назад

      Hi Arvind - the teacher in me always asks a question first. What do you think the difference is? Give it a go and then I’ll happily provide some guidance based on your response ☺️

  • @nhlovukophilosophy6975
    @nhlovukophilosophy6975 4 года назад

    Greetings,can you please highlight which aspects to dwell much on when coming to computer auditing?

    • @amandalovestoaudit
      @amandalovestoaudit  4 года назад

      Hi Edward - I’m unsure of your question. Do you mean when you are studying computer audit? Or when you are auditing a client’s systems?

    • @nhlovukophilosophy6975
      @nhlovukophilosophy6975 4 года назад

      @@amandalovestoaudit on both aspects, and how to go about the subsequent events as an Auditor?

    • @amandalovestoaudit
      @amandalovestoaudit  4 года назад

      Hi Edward - auditing computers are like auditing any other process - understand the internal controls, identify the control activities, test the controls for effectiveness.
      As for subsequent events - I have 3 videos on this topic
      A strategy for answering subsequent event questions
      ruclips.net/video/i1nZ3k0E4JQ/видео.html
      Subsequent events - some worked examples
      ruclips.net/video/pv-zenAjTGQ/видео.html
      Interpreting the Auditing Standard on SUBSEQUENT EVENTS ISA/ASA560
      ruclips.net/video/H-R3LwHwdVg/видео.html

  • @ntcuong01ct1
    @ntcuong01ct1 3 дня назад

    Dear Friends, I have a question about internal control:
    1/ I think internal control (IC) are activities that identify risks and frauds occurring in business processes and financial reports. After the IC (internal control) department detects risks, it will propose to management levels or the Board of Directors to identify risks and handle them. Question: Am I understanding this correctly?, I hope you can answer and add more. Thank you.

  • @thekingoftheboxleton
    @thekingoftheboxleton 3 года назад +6

    How do you manage not to say "um" when you are speaking?! Great job.

    • @amandalovestoaudit
      @amandalovestoaudit  3 года назад +5

      Lots of practice - but I still do it occassionally! Trying to speak too fast also can cause ums. I think in this video I wrote a script and used my teleprompter!

    • @thekingoftheboxleton
      @thekingoftheboxleton 3 года назад +1

      @@amandalovestoaudit thanks for your content. I am just at the bottom rung of aca doing assurance and your vids proper help!

    • @TheVivacious01
      @TheVivacious01 Год назад +1

      pause instead of saying um

  • @Phsoco
    @Phsoco 4 месяца назад

    I understand this video is old, however, is it correct to assume applications like email filters/blockers that are add-ons for other applications are considered General IT controls as opposed to IT Application Controls? I'm assuming it's General because it's not programmed into the application, but rather an add-on.

  • @peterc.7841
    @peterc.7841 5 лет назад +1

    is this about Sarbanes Oxley?

    • @amandalovestoaudit
      @amandalovestoaudit  5 лет назад

      Hi Peter - not specifically. SOX does require you to report on any material deficiencies in internal controls - but this video is just about the difference between 2 types of IT controls - application and general. SOX requires you to look at all controls - manual (done by people) and IT

  • @AwesomeIcer9000
    @AwesomeIcer9000 2 года назад

    My textbook also mentions ‘user controls’, what is that exactly?

    • @amandalovestoaudit
      @amandalovestoaudit  2 года назад

      User controls are those related to guiding user behaviour. Does it refer to computer end user controls?
      www.prweb.com/releases/2004/12/prweb185286.htm

  • @cuss1874
    @cuss1874 2 года назад

    i need help for my task:(

  • @pearlczworld
    @pearlczworld 5 лет назад

    Amanda, what is a BSO test?

    • @amandalovestoaudit
      @amandalovestoaudit  5 лет назад

      Hi - I don’t remember mentioning that in the video ... or do you mean generally?

    • @pearlczworld
      @pearlczworld 5 лет назад

      Amanda, thanks for responding. I had someone at work ask me this and dont know what they were referring to. what kind of test is it?

    • @amandalovestoaudit
      @amandalovestoaudit  5 лет назад

      Ok - it is something I’ve actually never heard of before! I will ask around and see if I can help - it might be something specific to your audit firms

  • @rousyamigo4278
    @rousyamigo4278 4 года назад +1

    Dear Amanda how to check for back up ?

    • @amandalovestoaudit
      @amandalovestoaudit  4 года назад +1

      Asking about the process, see if they’ve done any restorations from backups (usually this process needs to be documented and signed off by mgmt). You can’t usually physically/actually test the backup

    • @rousyamigo4278
      @rousyamigo4278 4 года назад

      @@amandalovestoaudit Thank u so much

  • @karabondlovu6528
    @karabondlovu6528 4 года назад

    Hello
    I'm asking for an assistance relating to General control vs Application control

    • @amandalovestoaudit
      @amandalovestoaudit  4 года назад

      What sort of assistance?

    • @karabondlovu6528
      @karabondlovu6528 4 года назад

      I was trying to send the document but I couldn't
      I was asking for you email so that I can share the document

    • @funnyclips4045
      @funnyclips4045 3 года назад +1

      @@karabondlovu6528 I am sorry, but that seems a bit shady. Just ask her the question instead of sending documents?

  • @Tokollo_
    @Tokollo_ Год назад

    🤣im in my final year and I still have to remind myself now and then about the difference between these 2.The line that differentiates them is too thin its easy to mix them up

  • @jmn1238
    @jmn1238 3 года назад

    I would think the app controls are more interface controls rather than SOD

  • @buyiemsane3446
    @buyiemsane3446 Год назад

    1 2 3

  • @gauthapandith
    @gauthapandith 2 года назад

    Sometimes it may be correct to say that Auditing is an art not having any logical approach and only limited by your imaginations as no answer is right or wrong !

  • @80dakka
    @80dakka 4 года назад

    Hello , please if u can help as I am new IS Auditor need some Authorised SW's of the below:
    Transaction logging
     Query tools
     Statistics and data analysis (CAAT)
     Database management system (DBMS)
     Data warehouses, data marts, data mining
     AI
     Embedded audit modules (EAM)
     Neural network technology
     Standards such as Extensible Business Reporting Language (XBRL)

    • @amandalovestoaudit
      @amandalovestoaudit  4 года назад +1

      Hi Bo - I’d check out Auditnet.org - this is a great resource for practitioners.

  • @dennisafariogun1658
    @dennisafariogun1658 2 года назад

    1

  • @nitishdash4850
    @nitishdash4850 3 года назад

    Best at 1.25x

  • @user-zj8dp8ue1z
    @user-zj8dp8ue1z 2 года назад

    「上記のギフトのいずれかを選択できます」、

  • @Kris-bb4oy
    @Kris-bb4oy 3 года назад +1

    crykey mate