您好,欢迎访问三七文档
当前位置:首页 > 商业/管理/HR > 其它文档 > IT_General_Requiremen
GeneralRequirementforGeneralComputerControlsReview概要信息文档NetworkDiagram;网络拓扑图CriticalServerHardwareListincludingModel,O/Sversionandnameofoutsourcedvendorsupport;主要服务器的硬件列表,包含其型号、操作系统、购买日期和供应商名称等关键信息MajorApplicationSystemincludingsoftwarenameandnameofoutsourcedvendorsupport.主要应用系统的软件列表,包含其名称、购买日期与外部服务商名称等关键信息Wewillbeappreciatedifyoucanpreparethefollowingdocumentations(ifany)beforethecommencementofourannualgeneralcomputercontrolsreview.此外根据我们本次审核的范围,还需要贵公司提供以下文档(如不适用则略过):1)InformationResourceStrategyandPlanning信息资源战略和计划Organisation组织结构Documentationregardingdepartmentaland/orjobfunction/responsibility.与部门或工作的职能和责任有关的文件Consistenttotheentity’sbusinessandstrategicgoals实体业务和战略目标的一致性Informationsystemsstrategiesandlong-andshort-termplans;信息系统战略以及长、短期计划Currentbusinessstrategy.当前业务战略MISPersonnelTrainingandRecruitment管理信息系统人员的培训和招聘Trainingmaterials;培训材料Pre-definedMISpersonnelqualificationsandrequirements.既定的管理信息系统人员的资格和要求2)InformationSystemOperations信息系统运作Monitoringofprocessing/Authorizationofschedules监控处理/时间表的授权Operationalmanual;运作手册Detailsoftheday-to-dayoperationjobschedule;详细的日常操作工作时间表Joblogs(samplesonly);工作日志(仅需样本)Logforexceptionstonormalprocessing;正常处理的例外情况日志Documentaryevidenceofmanagementreview.管理层审核的有关文件Backupschedulesandretention备份时间表和留存资料Backupschedule;备份时间表Backuplog;备份日志Documentaryevidenceregardingthetestingofon-goingreadabilityofbackupandretaineddata;与备份及保留数据的测试有关的文件Physicalsecurityforbackupmedia;备份媒体的物理安全Anyoff-sitebackuparrangement.异地备份安排Monitoringservicelevels服务水平监控Reportsforperformanceandcapacityutilizationofthecomputersystem;计算机系统性能和容量利用报告Servicelevelagreementswithaffectedparties;有关部门的服务水平协议Documentaryevidenceregardingmonitoringofservicelevels.与服务水平监控有关的文件UserTraining用户培训Proceduresfortrainingtousers;用户培训程序Usermanuals(samplesonly).用户手册(仅需样本)Helpdesk/Problemresolution帮助/问题解决Detailsofhelpdeskarrangement;帮助的具体安排Problemlogs(samplesonly);问题日志(仅需样本)Problemstatisticsprovidedtomanagement;给管理层的问题统计Agreementswithoutsidecontractorsorsoftwarevendorsforsupportservices.与外部承包人或软件供应商鉴定的有关支持服务的协议3)InformationSecurity信息安全General概况Informationsystemsecuritypolicies,procedures,standardand/orguidance;信息系统安全政策、程序、标准或指导Securityandinternalcontrolframework;安全和内部控制框架Systemssecurityconfigurationreports信息安全设置报告Logicalsecurity逻辑安全RACFsecuritysettings(separaterequestlistingwillbeprovidedduringourreview);RACF安全设置(在审核中将提供单独的所需材料清单)SecuritysettingsofdistributedenvironmentssuchasUnix,OS/400,WindowsNTandNovellNetware,ifavailable(ourDTTproprietaryautomatedtoolwillbeusedtoperformsuchreview);操作环境的安全设置,例如:Unix,OS/400,WindowsNT和NovellNetware(如果可能,我们DTT拥有的自动工具将提供相关的审核)Policyandproceduresregardingthecreation,alterationanddeletionofusersaccessauthorityovertheoperatingsystemlevel,applicationlevelanddatabaselevel;与创建、变更和删除用户对操作系统及数据库的访问、应用权限有关的政策和程序Userprofilelistingsofoperatingsystems,applicationsystemsanddatabasesystems;操作系统、应用系统和数据库系统的用户文档清单Documentaryevidenceregardingmonitoringofvalidityofusersprofilelistings.与用户文档清单有效性的监控有关的文件Physicalsecurityandenvironmentalcontrols物理安全和环境控制Restrictedareaaccesspolicies,procedures,standardsandguidance;限制区的进入政策、程序、标准和指导Policyandproceduresregardingtheadministrationofphysicalsecurity;与物理安全管理有关的政策和程序Accesscontrolmechanismmonitoringlogs;进入控制机制的监控日志Listofpersonnelwhohaveaccesstotherestrictedareas;有限制区进入权的人员名单Inventorylogsofaccesskeys,cardsandetc.fortherestrictedareas.进入限制区的钥匙、门卡等清单Virusprotection病毒保护Policy,procedures,standardsandguidancerelatingtovirusscanningofthenetworkandupdatingofvirussignaturelists;与网络病毒扫描和病毒库更新有关的政策、程序、标准和指导Listofanti-virussoftwareinuse;在用的反病毒软件清单Communicationtousersregardingthepolicy;针对既定的病毒防护政策,与用户进行相应沟通的文档记载Scheduleofvirusscans;病毒扫描时间表Resultingreportsfromvirusscans.病毒扫描的结果报告Softwareassetmanagement软件资产管理Policy,procedures,standards,andguidanceregardingpurchasing,approving,loading,andusingsoftware;与软件的购买、安装审批和使用有关的政策、程序、标准和指导Listingofsoftwareinventory;软件清单Approvedsoftwarelistand/orcriteria;正式的软件采购列表的及审批标准Documentationofsoftwareuseversusinventorycomparisonprocess;现用软件与公司已购买软件的对比列表Proofofownershipofsoftware(sampleonly).软件使用权的证据(仅需样本)4)ApplicationSystemsImplementationandMaintenance应用系统实施和维护General概况Systemdevelopmentmethodology;信息发展方法Listingofapplicationdevelopmentprojectsorlistingofapplicationsystemschangedduringtheyear.应用系统发展项目或年内应用系统变化的清单Approvalofapplicationsystemsacquisitionanddevelopment应用系统取得和发展的审批Policies,procedures,standards,andguidanceregardingmanagementapprovalofdevelopmentprojectsandsoftwareacquisitions;发展项目和软件需求审批的政策、程序、标准和指导Projectapproval,purchaserequestandauthorizationdocumentation;(sampleonly);项目审批、采购需求和文件授权(仅需样本)Projectplan;(sampleonly);项目计划(仅需样本)Projectimplementationschedules(sampleonly).项目实施时间表(仅需样本)Testingofapplicationsystemsimplementation应用系统实施的测试Formaltestplanwhichcoverssystemandunittesting,paralleltesting,interfacetestinganduseracceptancetest;正规的测试计划,包括单元测试、并行测试、接口测试和用户接受测试PolicyandprocedureforDataConversionTesting;数据转换测试的政策和程序DataConversionexceptionreports(sampleonly).数据转换例外报告(仅需样本)SystemChangeManagem
本文标题:IT_General_Requiremen
链接地址:https://www.777doc.com/doc-839370 .html