Control Intelligence

AI Analysis Results

Data Backup & Disaster RecoveryIT General Controls (ITGC)

Back to Sub-Process
75
/ 100
Adequate
Overall Sub-Process Rating
AdequateControl exists and operates; minor enhancements possible.
2 controls evaluated4 strengths identified2 gaps identified
Executive Summary

The Data Backup & Disaster Recovery process demonstrates adequate controls overall, with most key controls designed and operating as intended. Certain areas require enhanced documentation or monitoring to close identified gaps, but no material weaknesses were noted during the assessment period.

Strengths
  • Financial system data is backed up per a... is consistently executed
  • Disaster recovery plan is documented, tested annually, and... is consistently executed
  • Key controls are documented in a centralized repository
  • Exception reporting is generated and reviewed timely
Gaps
  • No automated alerting for control threshold breaches
  • Monitoring controls are not formally documented or tested
Recommendations
  1. 1Implement a workflow tool that captures reviewer identity and timestamp for all approvals
  2. 2Develop a remediation tracker with defined SLAs and escalation paths
  3. 3Establish a quarterly monitoring schedule with documented results and sign-off
Framework Mapping
COSO 2013
Principle P11
SOX 404
ICFR.ITGC.BR.01ICFR.ITGC.BR.02
IIA Standards 2024
IV.10.2

Control-Level Breakdown (2)

IT-BR-01AdequateScore: 75/100
Financial system data is backed up per a documented retention policy and tested quarterly.
Key Finding

The control is in place and generally operating as intended. Financial system data is backed up per a documented retention policy and tested quarterly. Minor documentation or timeliness gaps were noted but do not represent material risk.

Recommendation

Enhance documentation and monitoring for: financial system data is backed up per a documented retention policy and tested quarterly. Ensure review evidence includes timestamps and reviewer identity.

Framework Tags
COSO P11ICFR.ITGC.BR.01IIA IV.10.2
IT-BR-02StrongScore: 85/100
Disaster recovery plan is documented, tested annually, and covers all in-scope financial systems.
Key Finding

The control is well-designed and operating effectively. Disaster recovery plan is documented, tested annually, and covers all in-scope financial systems. Evidence of consistent execution and monitoring was observed.

Recommendation

Continue current practices. Consider automating remaining manual steps to sustain the control with less effort.

Framework Tags
COSO P11ICFR.ITGC.BR.02IIA IV.10.2