Achievable logoAchievable logo
CMA Part 1
Sign in
Sign up
Purchase
Textbook
Practice exams
Support
How it works
Exam catalog
Mountain with a flag at the peak
Textbook
1. External financial reporting decisions
2. Planning, budgeting, and forecasting
3. Performance management
4. Cost management
5. Internal control
5.1 Governance, risk and compliance
5.2 System controls and security measures
5.2.1 General accounting system controls
5.2.2 System development controls
5.2.3 Application and transaction controls
5.2.4 Technology controls
5.2.5 Backup controls and business continuity planning
6. Technology and analytics
Achievable logoAchievable logo
5.2.2 System development controls
Achievable CMA Part 1
5. Internal control
5.2. System controls and security measures
Our CMA Part 1 course is currently in development and is a work-in-progress.

System development controls

4 min read
Font
Discuss
Share
Feedback

System development controls

Definitions
System development controls
Policies and procedures designed to ensure that information systems are planned, designed, tested, and implemented in a way that promotes reliability, security, accuracy, and alignment with business requirements. These controls reduce the risk of errors, fraud, or system failures during the System Development Life Cycle (SDLC).

These controls ensure that systems are designed and implemented with reliability and security in mind. This is directly linked to the System Development Life Cycle (SDLC), a structured framework used to guide the development and maintenance of information systems.

The SDLC is discussed in more detail in CMA Part 1, Section F. The SDLC typically includes the following phases:

  • Planning: Define objectives, scope, and resource requirements.
  • Analysis: Gather and analyze user and system requirements.
  • Design: Develop detailed system and process specifications.
  • Development: Build or program the system according to design specifications.
  • Testing: Verify system functionality, security, and accuracy.
  • Deployment: Deploy the system into the production environment.
  • Maintenance: Monitor, update, and improve the system as needed.

To ensure the integrity, security, and effectiveness of systems throughout these phases, the following key controls should be implemented:

  • System authorization activities: Ensure that any system development or change is explicitly authorized by appropriate levels of management to prevent unauthorized access to system data.
  • User specification activities: Involve end users during the requirements-gathering phase to ensure that systems are designed to meet actual business needs.
  • Technical design activities: Translate user requirements into detailed technical specifications to guide development.
  • Internal audit participation: Include internal auditors in the design and review process to ensure that control requirements are adequately addressed.
  • Program testing: Conduct rigorous testing to compare actual program performance against predetermined standards and identify issues prior to implementation.
  • User test and acceptance procedure: Ensure users formally test the system and document the outcomes to support the final decision on deployment.

These specific controls support compliance, transparency, and operational effectiveness throughout the system development process.

Physical access controls

Definitions
Physical access controls
Security measures designed to restrict unauthorized individuals from entering sensitive areas where critical IT infrastructure and data are stored, such as server rooms, data centers, communication hubs, and storage facilities.

These controls form the foundation of any comprehensive information security strategy because even the most secure digital system can be compromised if physical access is not properly managed.

Effective physical access control measures include:

  • Badge-based entry systems: Employees and authorized personnel are issued access cards or badges that grant entry to specific locations based on their role. These systems can log entries and exits for audit purposes.

  • Biometric authentication: High-security areas may require fingerprint scans, facial recognition, or iris scans to verify the identity of individuals entering the premises.

  • Surveillance systems (CCTV): Continuous monitoring through cameras deters unauthorized access and provides video evidence in case of a breach or incident.

  • Security personnel: Trained guards can control access points, perform identity verification, and respond to incidents or alarms.

  • Visitor logs and escorts: All non-employees must sign in and out, present valid identification, and be accompanied by authorized staff while inside secure areas.

  • Environmental controls: These include systems for fire suppression, temperature and humidity control, and backup power—designed to protect hardware from environmental threats.

  • Secure hardware enclosures: Physical locking cabinets and racks within server rooms provide an additional layer of protection for critical equipment.

Implementing layered physical access controls reduces the risk of theft, vandalism, espionage, or tampering, and supports regulatory compliance in areas like data privacy and cybersecurity (e.g., SOX, GDPR). These controls are especially crucial in industries such as finance, healthcare, and government where the sensitivity of data and systems is high.

System development controls

  • Policies and procedures for reliable, secure, accurate systems
  • Aligned with System Development Life Cycle (SDLC) phases:
    • Planning, Analysis, Design, Development, Testing, Deployment, Maintenance
  • Key controls:
    • System authorization by management
    • User involvement in requirements gathering
    • Technical design specifications
    • Internal audit participation
    • Rigorous program testing
    • User test and acceptance procedures

Physical access controls

  • Restrict unauthorized entry to sensitive IT areas
  • Key measures:
    • Badge-based entry systems with audit logs
    • Biometric authentication (fingerprint, facial, iris)
    • Surveillance systems (CCTV)
    • Security personnel at access points
    • Visitor logs and escort requirements
    • Environmental controls (fire suppression, climate, backup power)
    • Secure hardware enclosures (locking cabinets/racks)
  • Supports regulatory compliance (SOX, GDPR) and protects against theft, tampering, and environmental threats

Sign up for free to take 5 quiz questions on this topic

Previous
Next  | 5.2.3 Application and transaction controls
All rights reserved ©2016 - 2026 Achievable, Inc.

System development controls

System development controls

Definitions
System development controls
Policies and procedures designed to ensure that information systems are planned, designed, tested, and implemented in a way that promotes reliability, security, accuracy, and alignment with business requirements. These controls reduce the risk of errors, fraud, or system failures during the System Development Life Cycle (SDLC).

These controls ensure that systems are designed and implemented with reliability and security in mind. This is directly linked to the System Development Life Cycle (SDLC), a structured framework used to guide the development and maintenance of information systems.

The SDLC is discussed in more detail in CMA Part 1, Section F. The SDLC typically includes the following phases:

  • Planning: Define objectives, scope, and resource requirements.
  • Analysis: Gather and analyze user and system requirements.
  • Design: Develop detailed system and process specifications.
  • Development: Build or program the system according to design specifications.
  • Testing: Verify system functionality, security, and accuracy.
  • Deployment: Deploy the system into the production environment.
  • Maintenance: Monitor, update, and improve the system as needed.

To ensure the integrity, security, and effectiveness of systems throughout these phases, the following key controls should be implemented:

  • System authorization activities: Ensure that any system development or change is explicitly authorized by appropriate levels of management to prevent unauthorized access to system data.
  • User specification activities: Involve end users during the requirements-gathering phase to ensure that systems are designed to meet actual business needs.
  • Technical design activities: Translate user requirements into detailed technical specifications to guide development.
  • Internal audit participation: Include internal auditors in the design and review process to ensure that control requirements are adequately addressed.
  • Program testing: Conduct rigorous testing to compare actual program performance against predetermined standards and identify issues prior to implementation.
  • User test and acceptance procedure: Ensure users formally test the system and document the outcomes to support the final decision on deployment.

These specific controls support compliance, transparency, and operational effectiveness throughout the system development process.

Physical access controls

Definitions
Physical access controls
Security measures designed to restrict unauthorized individuals from entering sensitive areas where critical IT infrastructure and data are stored, such as server rooms, data centers, communication hubs, and storage facilities.

These controls form the foundation of any comprehensive information security strategy because even the most secure digital system can be compromised if physical access is not properly managed.

Effective physical access control measures include:

  • Badge-based entry systems: Employees and authorized personnel are issued access cards or badges that grant entry to specific locations based on their role. These systems can log entries and exits for audit purposes.

  • Biometric authentication: High-security areas may require fingerprint scans, facial recognition, or iris scans to verify the identity of individuals entering the premises.

  • Surveillance systems (CCTV): Continuous monitoring through cameras deters unauthorized access and provides video evidence in case of a breach or incident.

  • Security personnel: Trained guards can control access points, perform identity verification, and respond to incidents or alarms.

  • Visitor logs and escorts: All non-employees must sign in and out, present valid identification, and be accompanied by authorized staff while inside secure areas.

  • Environmental controls: These include systems for fire suppression, temperature and humidity control, and backup power—designed to protect hardware from environmental threats.

  • Secure hardware enclosures: Physical locking cabinets and racks within server rooms provide an additional layer of protection for critical equipment.

Implementing layered physical access controls reduces the risk of theft, vandalism, espionage, or tampering, and supports regulatory compliance in areas like data privacy and cybersecurity (e.g., SOX, GDPR). These controls are especially crucial in industries such as finance, healthcare, and government where the sensitivity of data and systems is high.

Key points

System development controls

  • Policies and procedures for reliable, secure, accurate systems
  • Aligned with System Development Life Cycle (SDLC) phases:
    • Planning, Analysis, Design, Development, Testing, Deployment, Maintenance
  • Key controls:
    • System authorization by management
    • User involvement in requirements gathering
    • Technical design specifications
    • Internal audit participation
    • Rigorous program testing
    • User test and acceptance procedures

Physical access controls

  • Restrict unauthorized entry to sensitive IT areas
  • Key measures:
    • Badge-based entry systems with audit logs
    • Biometric authentication (fingerprint, facial, iris)
    • Surveillance systems (CCTV)
    • Security personnel at access points
    • Visitor logs and escort requirements
    • Environmental controls (fire suppression, climate, backup power)
    • Secure hardware enclosures (locking cabinets/racks)
  • Supports regulatory compliance (SOX, GDPR) and protects against theft, tampering, and environmental threats

More from System controls and security measures

  • General accounting system controls
  • Application and transaction controls
  • Technology controls
  • Backup controls and business continuity planning