Term · 13. Additional Terms
Internal Control IC
Definition
Process or mechanism implemented by management to provide reasonable assurance regarding effectiveness of operations, reliability of financial reporting, and compliance with laws/regulations. Identity-related internal controls: access provisioning workflows, periodic access certification, SoD enforcement, privileged access management, audit logging.
- Application
- SOX, SOC 2, ISO 27001, NIST 800-53 all enumerate internal control requirements. Identity controls typically classified as «IT General Controls» (ITGCs) — foundational to financial reporting reliability.
- Standards & regulations
-
- NIST SP 800-53 Rev. 5 «Internal control. A process, effected by an entity’s oversight body, management, and other personnel, designed to provide reasonable assurance regarding the achievement of objectives in the following »
- NIST SP 800-37 Rev. 2 «Internal control. The policies, procedures, techniques, and mechanisms that organizations use to achieve their objectives and to ensure that appropriate actions are taken to address risks. Internal co»
- NIST SP 800-39 «Internal control. A process, effected by an entity’s oversight body, management, and other personnel, designed to provide reasonable assurance regarding the achievement of objectives in the following »
- Sources
-
- NIST SP 800-53 Rev. 5 (csrc.nist.gov) primary source
Related terms
-
Identity Governance (IG)
Discipline of policies, processes, and oversight ensuring identities have appropriate access — no more, no less — throug …
-
Audit Trail
Chronological record of identity events — authentication, authorization decisions, provisioning actions, configuration c …
-
Access Certification (AC)
Periodic review process where designated reviewers (managers, role owners, application owners) attest that users still n …
-
Access Control (AC)
Mechanism that determines whether a principal is permitted to perform a specific action on a specific resource. Includes …
-
Audit
Independent examination of identity controls, processes, and records to verify compliance with policy and regulatory req …
-
Automated Data Classification
Machine learning-driven discovery and classification of sensitive data across structured and unstructured stores — ident …