Double Dipping on SOX
Some companies are leveraging Sarbanes-Oxley investments for business; others are leveraging business investments to comply.
November 7, 2005 12:00 PM ETComputerworld -
Mention the Sarbanes-Oxley Act to a CIO or a corporate executive, and he's likely to roll his eyes or grimace.
That's because most executives view the compliance requirements as a grim burden, like cleaning out a pack rat's basement.
Large public companies have had to devote thousands of staff hours and invest millions of dollars to identify, document and audit internal controls within their organizations just to comply with Section 404 of the federal law. Often the result has been that other strategic initiatives and revenue-enhancing IT projects had to be put on the back burner.
Those pressures have continued unabated in 2005. U.S. companies are expected to spend nearly $15.5 billion on compliance-related activities this year, with technology spending on Sarbanes-Oxley alone expected to top $1.7 billion, according to Boston-based AMR Research Inc.
Mindful of these investments, some savvy companies have leveraged their Sarbanes-Oxley spending to benefit the business in ways that go beyond mere regulatory compliance, yielding more bang for the buck.

![]()
Kim Van Nostern, chief information security officer at Allstate Insurance ![]()
Two years ago, Allstate developed its own compliance and control management system to help document controls in its various IT divisions. One of those tools is a scanning system created last year to identify worms and viruses and prevent them from attacking any of Allstate's systems.
Beyond helping Allstate ensure that it has effective security controls in order to comply with Sarbanes-Oxley, the scanning tool has delivered a nice side benefit. It enables the company's asset management specialists to constantly survey Allstate's corporate network and identify and track PCs, servers and other pieces of equipment that they previously didn't have a record of, says Van Nostern.
Catching Exceptions
At the end of 2004, American Electric Power Co. (AEP) began using software from Oversight Systems Inc. in Atlanta to help it monitor transactions in its accounts payable group. If a manager authorizes a purchase above his spending limit, the system recognizes it and spits out an exception report, says Mike Sullivan, assistant controller at the Columbus, Ohio-based power company.
Those capabilities have helped AEP comply with Section 404 requirements. But
Additional Resources


White Papers & Webcasts
A Truly Global HCM System
Learn about a system built with advanced object-oriented technology that support multi-national requirements and costs less to implement, maintain and upgrade....
Usability Is Everything
Learn what sets Workday's HR and Payroll solutions apart from the competition....
Moving Beyond Monolithic - What's Next for Enterprise Application Architectures?
This white paper reviews the current state of enterprise application architecture and presents a prediction on what might come next....
SaaS at Flextronics, Inc.
Dave Smoley, CIO of Flextronics, discusses the real value of software-as-a-service and why he chose Workday for his HR solution....
The Shortcut Guide to Managing Certificate Lifecycles
(Source: Thawte) If you have ever shopped for a certificate, you know that there is a wide selection of products and vendors from...
Agile Enterprise Content Management (ECM) for Rapid ROI
Find out how combining ECM and BPM will help adress issues about content rich business processes....
MarketVibe: Communications and Collaboration Needs at Business Organizations
In April 2009, IT and business leaders were invited to participate in a survey on business communications and collaboration solutions. The goal of...
Modernizing the IT Infrastructure
(Source: Oracle) There is a lot of legacy in many government IT systems today - legacy hardware, legacy software platforms, and legacy skills...
The Value of Network and Application Visibility by Aberdeen
This survey-based paper analyzes best practices for improving application visibility and analysis. This paper can help serve as a guideline for organizations looking...
Taking the Service Desk to the Next Level
Listen to this conversation with Doug Mueller to learn how standards and processes have evolved to bring us the service desk of today...
Subscribe to Computerworld
