
Subscribe to
Computerworld
|
April 10, 2006 (Computerworld) -- Fear can be a powerful generator of upstanding conduct, say Stephen Wagner and Lee Dittmar. But business runs on discovering and creating value. In this month's Harvard Business Review, the co-authors discuss how smart companies are finding unexpected benefits in Sarbanes-Oxley compliance. Wagner, who is the managing partner of the U.S. Center for Corporate Governance at Deloitte & Touche, and Dittmar, who leads the enterprise governance consulting practice at Deloitte Consulting and co-leads its Sarbanes-Oxley practice, talked with Kathleen Melymuka about how your company can use compliance requirements to its advantage.
What were some of the big control gaps that early Sarbanes-Oxley compliance efforts uncovered?
WAGNER: One of requirements of internal controls is maintenance of records in reasonable detail that reflect transactions. We found [that] in many instances, control documentation was way behind or didn't exist. A second issue was "tone at the top" -- the communication that comes out of the boardroom and the CEO suite that sets the stage for the organization, including how it deals with ethical standards. We found that there was often very little communication across organizations around the importance of maintaining good controls. In some cases we found duplication of control activities that created inefficiency and less-than-effective controls. Lastly, we ran into the notion of unnecessary complexity in the extreme. Many companies are far more complicated than they need to be. In the IT area in particular, there was duplication of systems, multiple instances of ERP -- one division of a company had 200 financial accounting systems.
DITTMAR: And organizations didn't know what their control programs consisted of. They knew they had them, but as one told me, it was "kind of tribal." There was no consistency in how they did it. We found uncontrolled access to systems that are important to maintaining the integrity of financial reporting. I got a call from a CIO who said, "I've got hundreds of systems and 700 to 800 people who have access all the way to the database level. How can I control that?" This is an extreme example, but it was pervasive. Systems were designed for speed, not for controls. There were also a lot of challenges around security and change management. When we asked about change management processes, many companies said, "Which ones? For this system or this system?"
|
|
Print this Story |
|
Send Us Feedback |
|
E-mail this Story |
|
Digg this Story |
|
Slashdot this Story |
|
|
|
|
|
|
All Zones Application Performance Zone Enterprise-Class Security Zone Enterprise Solutions Zone The File Data Management Zone Grid Computing on Windows Zone Security Management Zone ITIL Best Practices Zone The SAS Zone Storage Virtualization Zone The Data Center Management Zone |
|
|
| ||||||||
| ||||||||
| ||||||||
|


Monitoring Costs and Benefits - an excerpt from the book "IT Success" Monitor IT costs and business benefits. Learn how to conduct an accurate cost-benefit analysis across the entire application life cycle--and gain an understanding on how to better communicate the value of IT. Read this excerpt from "IT Success!"
Download this white paper
|

|
Is Your Company a Great Place to Work?
Our annual survey recognizes top employers that offer satisfying and challenging work environments for their IT staffs. Nominate a company here.
See the 2007 Best Places to Work in IT report
|

Enhancing Business Mobility with Convertible PCsFor years Pen enabled computing devices have enjoyed great success and acceptance in highly vertical industries like delivery services, auditing and POS. The primary limitations of early pen computing devices, which were the hurdles to early mainstream adoption, were the power limitations of the devices, no stable OS environment for application development, and the lack of a keyboard for traditional input. Now, with the availability of Windows XP Tablet PC edition and Vista, which are both Pen Enabled operating systems, the flexibility afforded by dual function convertible notebooks and a host of 3rd party applications, Pen Computing has expanded into areas like healthcare, insurance, education, retail, and sales force automation. What used to be strictly vertical has now caught on as a preferred alternative to standard notebooks. Is now the right time for you to consider pen computing? Tune in to find out what these amazing mobile devices can do to simplify tasks, expand the utility of a traditional notebook, and increase the ROI of traditional notebook computing. Listen to this podcast now
|
![]() |
HP Compaq t5735 Thin Client
Linux-based thin client delivers desktop-like performance supporting a variety of open-source applications, creating a new paradigm in thin client computing. The NEW HP Compaq t5735 Thin Client provides convenient access to server-based solutions, Virtual Desktop Infrastructure (VDI) or to a variety of remote client solutions. Download this datasheet
|
Global Operations Uses HP Thin Clients to Improve Security and TCO
Do you need a secure standardized platform while maintaining a lower cost of ownership company wide and to help make the company more competitive? Read how the CIO of the world's largest manufacturer of polyethylene folding tables, chairs, picnic tables, and residential basketball equipment obtained his IT Goal with HP Thin Clients. Download this case study
|
HP's Virtualization: HP's Remote Client Solutions Webinar
- Hear from IDC analysts on PC Client Virtualization and Alternatives to Client Computing - Hear how customers solved IT challenges with HP's solution to Virtualization - Learn about different types of virtualization market analysis from HP's CTO - Hear from the VP of Netpads, Inc. how HP Thin Client solutions helped solve IT challenges, security concerns and lowered TCO for the emerging hospitality. View this webcast
|
| About Us Advertise Contacts Editorial Calendar Help Desk Jobs at IDG Privacy Policy Reprints Site Map |
|
CIO The Industry Standard |

