Understanding on IT General Control Questions 1. Management comment Please provide us the name of systems and applications used: a) Operating system a) b) Database systems b) c) Applications used for: i) Debtors and Creditors Ledger ii) Bank reconciliation iii) Inventories iv) Payroll v) Project management i) ii) iii) iv) v) 2. Any changes to the systems and applications used during the year? 3. Any significant problems occurred on the existing systems and applications during the year? 4. Any major modifications on the existing systems and applications planned for the future? 5. Please advise whether the system and applications used are maintained in-house or outsource to third party service providers? 6. Please advise whether the system and applications used are maintained in-house or outsource to service providers? Auditor comment Questions 6. 6. 7. : b) Security, back up and storage guidelines: i) Has often do they perform backup for the below : - operating system - application programs - data ii) Where do they keep their backup? iii) Do they have access to internet or other remote accesses – If so, is there any firewall protection? iv) Do they have a locked computer room? c) Password management i) Do they use profile and password, which controls the level of access granted to a user? ii) Can anyone set up or remove user/leavers iii) Do they have inactivity timeouts? iv) How often is password changed? e) Virus protection i) Do they use virus protection? Management comment Auditor comment Conclusion We have