IT execs see higher spending because of Sarb-Ox rules
But compliance processes can help companies meet federal rules
Computerworld - ORLANDO -- The Sarbanes-Oxley Act has increased IT spending for most companies, but firms that have built processes to handle compliance issues may be better equipped to meet any new federal regulatory burdens, according to IT executives at Gartner Inc.'s ITxpo here.
Compliance burdens posed by Sarbanes-Oxley have proved costly for IT, according to Gartner, which estimates that the federal requirements have raised IT spending in areas such as records management, increased security, and tools and new IT processes needed to ensure accuracy of financial records.
For Eaton Corp., a manufacturer of electrical components, regulatory compliance issues have boosted IT spending by about 1%, or about $3 million. The company spends about $300 million on IT each year, according to Robert Sell, vice president and CIO at the Cleveland-based company.
Citing state and federal lawmaker interest in the privacy issues, Gartner analyst John Bace said it's possible that California's privacy law -- which requires customer notification in the event of a breach of personal information -- may yet result in a new federal privacy law with Sarbanes-Oxley-like auditing requirements.
If that happens, Sell said his strategy will be to leverage processes that were set up to ensure Sarbanes-Oxley compliance. Sell, who served on a panel with other senior IT executives, now has one office managing IT issues associated with that law in addition to intellectual property protection and privacy issues. "We are going to leverage the people and resources across those disciplines," he said.
Other IT executives agreed that the corporate response needed for Sarbanes-Oxley compliance is giving companies the organizational, governance and educational framework they may need to deal with future compliance issues.
Gint Dargis, vice president and CIO at Richardson Electronics Ltd. in LaFox, Ill., said his firm has the ability "to scope out what's the impact to the company" if any new requirements arrive,
Moreover, regulations "are coming together -- these things are not going apart," said Jim Magliano, senior IS director at West Pharmaceutical Services Inc. in Lionville, Pa. Magliano said many of the requirements that apply to Sarbanes-Oxley also involve health regulatory-related issues, such as the Health Insurance Portability and Accountability Act.
The one thing companies can't do is treat the regulatory requirements lightly, warned panel members.
From a corporate board perspective, it's important to ensure that top executives take compliance "seriously enough," said Ken Coleman, chairman and CEO of ITM Software Corp., a business management tools company based in Mountain View, Calif. He said there is a tendency in management not to devote enoughstaff to a problem.
"This is superimportant," said Coleman. "The consequences are significant."
But Sell also said that helping a company meet its regulatory requirements is something IT leaders should step up to. "What a great opportunity -- especially for people in IT -- to demonstrate some IT leadership," he said.
Read more about Management and Careers in Computerworld's Management and Careers Topic Center.


- Excel 2010 Cheat Sheet
- Register for this Computerworld Insider Cheat Sheet and gain access to hundreds of premium content articles, guides, product reviews and more.
- Centage/IOMA Budgeting Survey: Benchmarks and Issues
- How are other financial professionals dealing with the issues you face? This report offers you an inside peak into what the minds at...
- Thinking Outside The Data Warehouse
- This high level, business problem focused eBook uses 5 customer scenarios to show how people and organizations are tackling real issues using IBM...
- Using BD for Smarter Decision Making
- This paper looks at new developments in business analytics and discusses the benefits analyzing big data bring to the business.
- Forrester Whitepaper: IT Operations Managers Must Rethink Their Approach to Private Cloud
- Organizations of all types are attracted by the promises of private cloud computing, but few actually have the virtual maturity to be successful....
- Roadmap to the Cloud Summary HP Brochure
- This white paper reveals the key steps you need to take in order to build an effective cloud computing infrastructure. Start building your... All ROI White Papers
- Live Webcast
Data Privacy and Protection in Production Environments: New Research from Ponemon Institute - Date: Wednesday, June 13, 2012, 1:00 PM EDT / 10:00 AM PDT
In a recent study conducted by Ponemon Institute, fifty-five percent of respondents... - Live Webcast
A Geek's Guide to Presenting to Business People - Live Webcast: Wednesday, June 20th at 1:00 PM EDT
Join this live webinar with Paul Glen, author of Leading Geeks, to learn how to... - Live Webcast
Today's NAS: A Solution Beyond Old Limits - Date: Tuesday, July 17, 2012 2:00 PM EDT
Traditional NAS systems don't scale beyond fixed limits. Proliferation of NAS systems leads to management... - Seven Deadly Sins of Cloud Security (Video)
- As cloud computing gains popularity, too few people are aware of the security threats that are emerging. In this short video, experts from...
- Delivery Management -- Extending Lifecycle Management
- Date: Wednesday, June 20, 2012, 1:00 PM EDT
Siloed organizations continue doing the wrong things and doing things wrong, leading to increased costs,... - Leverage automation today to reduce IT complexity
- Date: Tuesday, June 5, 2012, 2:00 PM EDT
Whether your B2B complexity is caused by multiple technologies due to M&A, business or application specific... - Redefine Expectations in the Data Center
- Need to do more with less? Watch this video to learn how HP ProLiant Gen8 servers can help your business deploy servers three...
- BMC Control-M - Single Point of Control Demo
- With BMC Control-M, you schedule and manage everything - down to the very last platform and application - from one simple interface. It's... All ROI Webcasts