MHM Home Page
What is a SAS 70 Audit?
Who can perform a SAS 70 Audit?
The Benefits
Our Expertise
The Readiness Process
Example Control Objectives

Application Development and Maintenance

Controls provide reasonable assurance that program development and modification standards exist to ensure only authorized, documented, tested, and approved programs are placed into production.

  • Changes made to system software are subject to change control policies and procedures.
  • Program modifications are logged and recorded, and a history of program changes is maintained.
  • A project management database schedules and tracks the status of program changes.
  • Programming changes are tested by systems and business users to determine if systems and business specifications have been satisfied.
  • Software modifications are tested prior to implementation.
  • Software processing problems are documented, and the resolution is reviewed and approved by the IT department.
  • Program modifications are reviewed and approved by management and authorized users prior to implementation.

<< Back to Example Control Objectives