This article provides an overview of SOX 404 control Manage IT Physical Space.

The typical SOX 404 IT controls for Manage IT Physical Space are as follows.

Physical Access
Description: A documented process exists for physical access to the computer facilities.

Control Objective: Physical access to computer facilities by all persons should be justified, authorised, logged and monitored.

Typical Evidence:

  1. There is a documented process in place for granting access to the computer facilities.
  2. The document lists who can grant access.
  3. The process details the request and approval process.
  4. There is a documented access removal process for the computer facilities.
  5. The process documents how and by when access should be removed.
  6. There is a documented process in place to review access appropriateness regularly.

Physical Security Features
Description: Physical security features are in place to restrict access to only approved persons.

Control Objective: Physical access to computer facilities by all persons should be justified, authorised, logged and monitored.

Typical Evidence:

  1. The physical security for the building is documented.
  2. The physical security for the computer technology within the building is documented.

For more information please contact Morland-Austin at info@morland-austin.com.