IT execs see higher spending because of Sarb-Ox rules
But compliance processes can help companies meet federal rules
Computerworld - ORLANDO -- The Sarbanes-Oxley Act has increased IT spending for most companies, but firms that have built processes to handle compliance issues may be better equipped to meet any new federal regulatory burdens, according to IT executives at Gartner Inc.'s ITxpo here.
Compliance burdens posed by Sarbanes-Oxley have proved costly for IT, according to Gartner, which estimates that the federal requirements have raised IT spending in areas such as records management, increased security, and tools and new IT processes needed to ensure accuracy of financial records.
For Eaton Corp., a manufacturer of electrical components, regulatory compliance issues have boosted IT spending by about 1%, or about $3 million. The company spends about $300 million on IT each year, according to Robert Sell, vice president and CIO at the Cleveland-based company.
Citing state and federal lawmaker interest in the privacy issues, Gartner analyst John Bace said it's possible that California's privacy law -- which requires customer notification in the event of a breach of personal information -- may yet result in a new federal privacy law with Sarbanes-Oxley-like auditing requirements.
If that happens, Sell said his strategy will be to leverage processes that were set up to ensure Sarbanes-Oxley compliance. Sell, who served on a panel with other senior IT executives, now has one office managing IT issues associated with that law in addition to intellectual property protection and privacy issues. "We are going to leverage the people and resources across those disciplines," he said.
Other IT executives agreed that the corporate response needed for Sarbanes-Oxley compliance is giving companies the organizational, governance and educational framework they may need to deal with future compliance issues.
Gint Dargis, vice president and CIO at Richardson Electronics Ltd. in LaFox, Ill., said his firm has the ability "to scope out what's the impact to the company" if any new requirements arrive,
Moreover, regulations "are coming together -- these things are not going apart," said Jim Magliano, senior IS director at West Pharmaceutical Services Inc. in Lionville, Pa. Magliano said many of the requirements that apply to Sarbanes-Oxley also involve health regulatory-related issues, such as the Health Insurance Portability and Accountability Act.
The one thing companies can't do is treat the regulatory requirements lightly, warned panel members.
From a corporate board perspective, it's important to ensure that top executives take compliance "seriously enough," said Ken Coleman, chairman and CEO of ITM Software Corp., a business management tools company based in Mountain View, Calif. He said there is a tendency in management not to devote enoughstaff to a problem.
"This is superimportant," said Coleman. "The consequences are significant."
But Sell also said that helping a company meet its regulatory requirements is something IT leaders should step up to. "What a great opportunity -- especially for people in IT -- to demonstrate some IT leadership," he said.
Read more about Management and Careers in Computerworld's Management and Careers Topic Center.



- Excel 2010 Cheat Sheet
- Register for this Computerworld Insider Cheat Sheet and gain access to hundreds of premium content articles, guides, product reviews and more.
- Overcome Top 7 Admin Challenges of Active Directory
- As Active Directory's role in the enterprise has drastically increased, so has the need to secure the data. Gain insight on creating repeatable,...
- Insiders Can Ruin Your Company. Take Action.
- Did you know that 80 percent of threats to an organization come from the inside? The threat from insiders is often overlooked in...
- Smarter Commerce is redefining value chain visibility
- Smarter Commerce is redefining the value chain in the age of the customer. It starts with putting the customer at the center of...
- Identity Governance: The Business Imperatives
- This white paper describes the business challenges and opportunities that are driving interest in Identity Governance while discussing considerations your organization should make...
- The Executive Buyer's Guide to Project Portfolio Management
- The Innotas Executive Buyer's Guide provides you with a concise overview of Project Portfolio Management (PPM) and delivers important buying criteria to help... All Management and Careers White Papers
- Live Webcast
Integrated IT Operations Management in the Cloud - Join award-winning technology editor Stan Gibson and Andrew White, CMO at Numara Software, to learn how asset management and service management are converging...
- Integrated IT Operations Management in the Cloud
- Join award-winning technology editor Stan Gibson and Andrew White, CMO at Numara Software, to learn how asset management and service management are converging...
- Optimizing Networks for the Cloud
- Join guest speaker, Rohit Mehra, IDC Director of Enterprise Communications Infrastructure, to explore current trends, discuss best practices for optimizing Data Center and...
- Apps QuickStart Series Part 2: Designing and Deploying SQL Server on VMware vSphere
- Download this webcast to learn about the design considerations for virtualizing SQL workloads, performance and scalability information and high-availability options, as well as...
- Apps QuickStart Series Part 1: Designing and Deploying Exchange 2010 on VMware vSphere
- Download this webcast to learn the virtual hardware design considerations for Exchange 2010, deployment using the building block approach, options for high-availability and...
- Customer Spotlight: How IPC The Hospitalist Company Implemented Oracle on VMware
- Have you been looking to hear about customer's experiences with the new VMware vCenter Site Recovery Manager product? View this webcast to learn... All Management and Careers Webcasts