GeneralRequirementforGeneralComputerControlsReview概要信息文档NetworkDiagram;网络拓扑图CriticalServerHardwareListincludingModel,O/Sversionandnameofoutsourcedvendorsupport;主要服务器的硬件列表,包含其型号、操作系统、购买日期和供应商名称等关键信息MajorApplicationSystemincludingsoftwarenameandnameofoutsourcedvendorsupport.主要应用系统的软件列表,包含其名称、购买日期与外部服务商名称等关键信息Wewillbeappreciatedifyoucanpreparethefollowingdocumentations(ifany)beforethecommencementofourannualgeneralcomputercontrolsreview.此外根据我们本次审核的范围,还需要贵公司提供以下文档(如不适用则略过):1)InformationResourceStrategyandPlanning信息资源战略和计划Organisation组织结构Documentationregardingdepartmentaland/orjobfunction/responsibility.与部门或工作的职能和责任有关的文件Consistenttotheentity’sbusinessandstrategicgoals实体业务和战略目标的一致性Informationsystemsstrategiesandlong-andshort-termplans;信息系统战略以及长、短期计划Currentbusinessstrategy.当前业务战略MISPersonnelTrainingandRecruitment管理信息系统人员的培训和招聘Trainingmaterials;培训材料Pre-definedMISpersonnelqualificationsandrequirements.既定的管理信息系统人员的资格和要求2)InformationSystemOperations信息系统运作Monitoringofprocessing/Authorizationofschedules监控处理/时间表的授权Operationalmanual;运作手册Detailsoftheday-to-dayoperationjobschedule;详细的日常操作工作时间表Joblogs(samplesonly);工作日志(仅需样本)Logforexceptionstonormalprocessing;正常处理的例外情况日志Documentaryevidenceofmanagementreview.管理层审核的有关文件Backupschedulesandretention备份时间表和留存资料Backupschedule;备份时间表Backuplog;备份日志Documentaryevidenceregardingthetestingofon-goingreadabilityofbackupandretaineddata;与备份及保留数据的测试有关的文件Physicalsecurityforbackupmedia;备份媒体的物理安全Anyoff-sitebackuparrangement.异地备份安排Monitoringservicelevels服务水平监控Reportsforperformanceandcapacityutilizationofthecomputersystem;计算机系统性能和容量利用报告Servicelevelagreementswithaffectedparties;有关部门的服务水平协议Documentaryevidenceregardingmonitoringofservicelevels.与服务水平监控有关的文件UserTraining用户培训Proceduresfortrainingtousers;用户培训程序Usermanuals(samplesonly).用户手册(仅需样本)Helpdesk/Problemresolution帮助/问题解决Detailsofhelpdeskarrangement;帮助的具体安排Problemlogs(samplesonly);问题日志(仅需样本)Problemstatisticsprovidedtomanagement;给管理层的问题统计Agreementswithoutsidecontractorsorsoftwarevendorsforsupportservices.与外部承包人或软件供应商鉴定的有关支持服务的协议3)InformationSecurity信息安全General概况Informationsystemsecuritypolicies,procedures,standardand/orguidance;信息系统安全政策、程序、标准或指导Securityandinternalcontrolframework;安全和内部控制框架Systemssecurityconfigurationreports信息安全设置报告Logicalsecurity逻辑安全RACFsecuritysettings(separaterequestlistingwillbeprovidedduringourreview);RACF安全设置(在审核中将提供单独的所需材料清单)SecuritysettingsofdistributedenvironmentssuchasUnix,OS/400,WindowsNTandNovellNetware,ifavailable(ourDTTproprietaryautomatedtoolwillbeusedtoperformsuchreview);操作环境的安全设置,例如:Unix,OS/400,WindowsNT和NovellNetware(如果可能,我们DTT拥有的自动工具将提供相关的审核)Policyandproceduresregardingthecreation,alterationanddeletionofusersaccessauthorityovertheoperatingsystemlevel,applicationlevel...