Ads by TechWords

See your link here
Subscribe to our e-mail newsletters
For more info on a specific newsletter, click the title. Details will be displayed in a new window.
Computerworld Daily News (First Look and Wrap-Up)
Computerworld Blogs Newsletter
The Weekly Top 10
More E-Mail Newsletters 
 

Changing the DNA of IT: Sarbanes-Oxley and Service Management

April 18, 2005 12:00 PM ET

Computerworld - As organizations work toward compliance with the immediate deadlines of the Sarbanes-Oxley Act of 2002 and prepare to meet other requirements within the act, they are discovering the dollar cost of compliance. Organizations need to spend wisely on tools that will meet the basic tenets of Sarbanes-Oxley -- including improved transparency and accountability in business processes and corporate accounting -- while providing the foundation for future compliance. IT service management -- a fundamental tool set for weaving transparency, control and risk mitigation into the fabric of IT -- can help organizations achieve regulatory compliance while promoting IT governance and improved business operations.
Key Components of the Sarbanes-Oxley Act
Sarbanes-Oxley requirements for IT departments are contained in two sections and referenced in a third. Section 302 requires corporate executives to certify that their companies have designed and implemented adequate controls to ensure that financial reports are reliable and compiled according to generally accepted accounting principles. Section 404 requires that the Section 302-controlled processes result in certifiable financial reports. IT managers must take direct responsibility for the integrity of the IT role in the financial reporting process.
The real-time disclosure provision of Section 409, which requires immediate public disclosure of material changes, places further burdens upon the IT organization.
Auditing Frameworks: COSO and Cobit
Corporate auditors have adopted general frameworks for assessing the quality of an organization's control environment, including IT governance. Two prominent and complementary frameworks are Coso (the Committee of Sponsoring Organizations of the Treadway Commission) and Cobit (Control Objectives for Information and Related Technology). Although these frameworks aren't part of Sarbanes-Oxley legislation, they provide auditors with the taxonomy of subject areas and operational requirements that auditors need to assess the quality of IT governance.
The Coso framework is a wide approach to IT governance that auditors follow when looking for evidence of a sound support structure for financial reports. U.S. Securities and Exchange Commission communications on Sarbanes-Oxley audits specifically mention Coso. The framework extends beyond financial reporting and applies to every IT function.
The Information Systems Audit and Control Association and the IT Governance Institute released Cobit, which follows the general Coso structure. It provides a set of high-level control objectives for IT processes grouped into four domains: planning and organization, acquisition and implementation, delivery and support, and monitoring.
These domains are designed to cover all aspects of information and its supporting technology. Auditors and business-process owners can use these control objectives to assess the control system provided for the IT environment.
An organization structured around Cobit control objectives



Additional Resources

Xerox
By using solid ink technology only from Xerox, you could save up to 65% by printing color for the cost of black and white. Enter for a chance to WIN a PhaserTM 8860 network color printer!
Microsoft
Save time and mitigate security risk. Deploy it now.
Sybase
In this white paper, IDC analyzes the role of next-generation mobile enterprise platforms as organizations seek a more strategic deployment of mobile solutions.

Learn the important issues you must consider before starting your next mobility initiative. Get your mobility white paper from IDC now, compliments of Sybase.

White Papers & Webcasts

IT Modernization in Government
As IT budgets are slashed, IT management pressures rise and legacy systems linger in government organizations, modernizing the IT infrastructure and applications has...  

Usability Is Everything
Learn what sets Workday's HR and Payroll solutions apart from the competition....

Accelerate SSL Encrypted Applications
The amount of SSL traffic is growing in the enterprise. Because it is encrypted, it cannot be properly controlled and accelerated. Blue Coat...  

The Value of Real SaaS at Workday
Cost savings, speed to value, and innovation brought to the enterprise by Workday's software-as-a-service solutions for HR and Payroll....

ESG Lab Field Audit
Many companies have successfully implemented Riverbed WAN optimization solutions within their Cisco networks. This ESG Lab Field Audit document explores the success that...  

SaaS at Flextronics, Inc.
Dave Smoley, CIO of Flextronics, discusses the real value of software-as-a-service and why he chose Workday for his HR solution....

Shape Your Apps Strategy to Reflect New SaaS Licensing and Pricing Trends
Why are smart companies choosing software-as-a-service? Find out in the complimentary Forrester Research report...  

Why Compliance Pays
This OnDemand webcast explores the relationship that firms with best compliance records have higher revenue, greater customer retention, lower financial losses from data...

Natural User Interface for Enterprise Applications
Learn how a revolutionary user interface can make a complex enterprise application so intuitive even casual users can jump right in....  

Agile Enterprise Content Management (ECM) for Rapid ROI
Find out how combining ECM and BPM will help adress issues about content rich business processes....