Domains
Change management
Segregated dev / test / prod, peer-review gates, change-advisory board evidence, emergency-change attestation.
Logical access
Joiner / mover / leaver, privileged-access reviews, MFA coverage, dormant-account discipline.
Computer operations
Job scheduling, batch monitoring, incident-to-problem linkage, backup success and restore tests.
System development
SDLC gating, secure-coding evidence, dependency / SBOM management, vulnerability remediation SLAs.
Business continuity & DR
RTO / RPO attestation, DR test cadence, dependency map, third-party continuity carve-out.
Cloud configuration
CIS / SCC baseline, drift detection, IaC review, secrets-management discipline.
Model-change ITGC
AI Assurance OS binding — model registry, change record, challenger evidence, monitoring re-baseline.
Evidence chain
Immutable evidence vault, hash-chain attestation, regulator-ready scoping (SR 15-18 / BCBS 239 aligned).