Subscribe to our e-mail newsletters
For more info on a specific newsletter, click the title. Details will be displayed in a new window.
IT Management
Computerworld Daily News (First Look and Wrap-Up)
Computerworld Blogs Newsletter
The Weekly Top 10
More E-Mail Newsletters 
Computerworld 2007Subscribe to Computerworld
40 years of the most authoritative source of news and information for IT leaders.

The Real Value in Sarbanes-Oxley

Kathleen Melymuka   Today’s Top Stories    or  Other Management Stories  
 

Sign up to receive Security Resource Alerts

April 10, 2006 (Computerworld) -- Fear can be a powerful generator of upstanding conduct, say Stephen Wagner and Lee Dittmar. But business runs on discovering and creating value. In this month's Harvard Business Review, the co-authors discuss how smart companies are finding unexpected benefits in Sarbanes-Oxley compliance. Wagner, who is the managing partner of the U.S. Center for Corporate Governance at Deloitte & Touche, and Dittmar, who leads the enterprise governance consulting practice at Deloitte Consulting and co-leads its Sarbanes-Oxley practice, talked with Kathleen Melymuka about how your company can use compliance requirements to its advantage.

What were some of the big control gaps that early Sarbanes-Oxley compliance efforts uncovered?

WAGNER: One of requirements of internal controls is maintenance of records in reasonable detail that reflect transactions. We found [that] in many instances, control documentation was way behind or didn't exist. A second issue was "tone at the top" -- the communication that comes out of the boardroom and the CEO suite that sets the stage for the organization, including how it deals with ethical standards. We found that there was often very little communication across organizations around the importance of maintaining good controls. In some cases we found duplication of control activities that created inefficiency and less-than-effective controls. Lastly, we ran into the notion of unnecessary complexity in the extreme. Many companies are far more complicated than they need to be. In the IT area in particular, there was duplication of systems, multiple instances of ERP -- one division of a company had 200 financial accounting systems.

DITTMAR: And organizations didn't know what their control programs consisted of. They knew they had them, but as one told me, it was "kind of tribal." There was no consistency in how they did it. We found uncontrolled access to systems that are important to maintaining the integrity of financial reporting. I got a call from a CIO who said, "I've got hundreds of systems and 700 to 800 people who have access all the way to the database level. How can I control that?" This is an extreme example, but it was pervasive. Systems were designed for speed, not for controls. There were also a lot of challenges around security and change management. When we asked about change management processes, many companies said, "Which ones? For this system or this system?"

Continued...
1 | 2 | 3 | 4 | 5 | NEXT  



Print this Story Send Us Feedback E-mail this Story Digg! Digg this Story Slashdot this Story
"A marketing war over energy isn't a bad thing...." Read more...
"One of the most worthwhile things we do around here is strive to recognize the contributions made by dedicated IT..." Read more...
Read more Management posts or See all Blogs
Tools circulate that crack Debian, Ubuntu keys
Former Microsoft manager offers free fix for XP SP3 'endless reboot'
Can Icahn take on the Yahoo board and win?
More top stories...
DNS trouble knocks NSA off Internet
Developers confirm, explain why they're avoiding Windows Vista
NASA moves to save computers from swarming ants
Specialists have retrieved about 99% of the data on a disk drive on board the crashed space shuttle Columbia. Don't miss the photographs of the recovered drive.
These big ideas were supposed to revolutionize technology, but they never actually appeared. In a few cases, you'll be glad they didn't.
Nearly 20 years after the first Internet worm, Steven J. Vaughan-Nichols takes stock of the malware/anti-malware landscape and spotlights how the two sides are approaching the battle.
Though some thought it was released too soon, Mac OS X 10.5 has matured into a solid operating system, says reviewer Michael DeAgonia.
Reviews, analyses, how-tos, visual tours, hot issues and predictions about Microsoft's new OS.
Four years from now, the IT field will be a vastly different place. Will you be ready?
All Zones
Application Performance Zone
Enterprise-Class Security Zone
Enterprise Solutions Zone
The File Data Management Zone
Grid Computing on Windows Zone
Security Management Zone
ITIL Best Practices Zone
The SAS Zone
Storage Virtualization Zone
The Data Center Management Zone

Ads by TechWords

See your link here
HP's Virtualization: HP's Remote Client Solutions Webinar
HP's Virtualization: HP's Remote Client Solutions Webinar
View this webcast!
Go to the webcast 
Computerworld Report: Storage Gets Strategic
Download this Computerworld Report, free, compliments of HP.
(Source: Computerworld) Data Storage has emerged from the back room to become a key part of regulatory compliance, disaster recovery and strategic tecnhology plans. Learn more in this new this Computerworld report, a $49.95 value, available free for a limited time, compliments of HP.
Download this executive briefing download
Does collaboration drive business success?
Get this white paper now!
(Source: Microsoft Office Live Meeting) Collaboration occurs at the intersection of an enterprise's technology and culture. Discover how these two critical factors affect the quality of collaboration in Meetings Around the World: The Impact of Collaboration on Business Performance. You'll learn why enterprises need to work collaboratively - and examine how collaboration impacts business success.
Download this white paper go
White Papers
Read up on the latest ideas and technologies from companies that sell hardware, software and services.
Six Support Issues That Keep Execs Awake at Night
Spam Spikes: A Real Risk to Your Business
The New Foundation of Storage: Xiotech's Intelligent Storage Element
View more whitepapers 
HP Compaq t5735 Thin Client

Linux-based thin client delivers desktop-like performance supporting a variety of open-source applications, creating a new paradigm in thin client computing. The NEW HP Compaq t5735 Thin Client provides convenient access to server-based solutions, Virtual Desktop Infrastructure (VDI) or to a variety of remote client solutions.

Download this datasheet 
Global Operations Uses HP Thin Clients to Improve Security and TCO

Do you need a secure standardized platform while maintaining a lower cost of ownership company wide and to help make the company more competitive? Read how the CIO of the world's largest manufacturer of polyethylene folding tables, chairs, picnic tables, and residential basketball equipment obtained his IT Goal with HP Thin Clients.

Download this case study 
HP's Virtualization: HP's Remote Client Solutions Webinar

- Hear from IDC analysts on PC Client Virtualization and Alternatives to Client Computing
- Hear how customers solved IT challenges with HP's solution to Virtualization
- Learn about different types of virtualization market analysis from HP's CTO
- Hear from the VP of Netpads, Inc. how HP Thin Client solutions helped solve IT challenges, security concerns and lowered TCO for the emerging hospitality.

View this webcast