  • Do we really need to classify the ‘CAVR’ (completeness, accuracy, validity, and restricted access) for GCC? It seems to me that they are more relating to the business transactions side. Just don’t know how to relate them to general computer controls…

  • No you don’t.
    CAVR, or other variants are financial statements assertions that are used to derive your control objectives in a business process.
    For General Controls your control objectives are already defined in COBIT.

