|
Thursday, September 23, 2004 Do you have any idea what Sarbanes-Oxley legislation means to your IT department? The above comment came from a reader whose organization's IT security policy is being set by a team of auditors who, quite frankly, aren't trained to implement proper security measures. I spoke off the record with a colleague who has a fair amount of experience helping companies design Sarbanes-Oxley compliance plans. He said that some internal and external auditor groups are being overly aggressive in their interpretation of certain sections of Sarbanes-Oxley. These different interpretations can lead to inconsistencies where one group of auditors tells a company, "Yes, Bob can have the sa password," and another set of auditors tells the company, "Heck no, Bob can't have the sa password." Sarbanes-Oxley: Accountants Setting IT Policy? Previous articles From 'Can't' to Compliant
|
Sponsored by:
Kumquat: Get the feedback you deserve
Learn more
FREE to Inside Sarbanes Oxley readers

|
About inside Sarbanes-Oxley inside Sarbanes Oxley is dedicated to finding the best sources of news and information on the changing landscape of Sarbanes Oxley and compliance. Whether you call it SOX, Sarbox, or the Sarbanes-Oxley Act of 2002, look no further than inside Sarbanes Oxley. More Copyright © 2004-2006, Inside Sarbanes-Oxley
|
Additional resources Try these recently updated resources: RSS Feed Interested in staying up-to-date on all the latest Sarbanes-Oxley news? Subscribe to the inside Sarbanes-Oxley RSS feed and get all of the latest news on SOX delivered directly to your feed reader. inside
Sarbanes-Oxley RSS Feed
|