IT, data & continuous
IT General Controls (ITGC)
Organization-wide policies, procedures, and activities that ensure IT systems operate reliably and data is protected. ITGC provides the environment in which application-specific controls operate and is essential for the integrity of information systems supporting financial reporting. The three core areas are logical access control, change management, and backup and recovery.
Source: COSO Internal Control Framework 2013, IIA GIAS 2024