Ads by TechWords

See your link here
Receive the latest technology news and information.
IT Management
Computerworld Daily News (First Look and Wrap-Up)
Computerworld Blogs Newsletter
The Weekly Top 10
Cloud Computing
View all newsletters




Privacy Policy
 

Double Dipping on SOX

Some companies are leveraging Sarbanes-Oxley investments for business; others are leveraging business investments to comply.

November 7, 2005 12:00 PM ET

Computerworld - Mention the Sarbanes-Oxley Act to a CIO or a corporate executive, and he's likely to roll his eyes or grimace.
That's because most executives view the compliance requirements as a grim burden, like cleaning out a pack rat's basement.
Large public companies have had to devote thousands of staff hours and invest millions of dollars to identify, document and audit internal controls within their organizations just to comply with Section 404 of the federal law. Often the result has been that other strategic initiatives and revenue-enhancing IT projects had to be put on the back burner.
Those pressures have continued unabated in 2005. U.S. companies are expected to spend nearly $15.5 billion on compliance-related activities this year, with technology spending on Sarbanes-Oxley alone expected to top $1.7 billion, according to Boston-based AMR Research Inc.
Mindful of these investments, some savvy companies have leveraged their Sarbanes-Oxley spending to benefit the business in ways that go beyond mere regulatory compliance, yielding more bang for the buck.

Kim Van Nostern, chief information security officer at Allstate Insurance
Kim Van Nostern, chief information security officer at Allstate Insurance
Northbrook, Ill.-based Allstate Insurance Co., for example, has adopted a holistic view of regulatory compliance, including steps it has taken to address the requirements of Sarbanes-Oxley, the Gramm-Leach-Bliley Act and the Health Insurance Portability and Accountability Act, says Kim Van Nostern, Allstate's chief information security officer. "We recognize that all those regulations require the same types of controls; they just apply a slightly different filter," says Van Nostern.
Two years ago, Allstate developed its own compliance and control management system to help document controls in its various IT divisions. One of those tools is a scanning system created last year to identify worms and viruses and prevent them from attacking any of Allstate's systems.
Beyond helping Allstate ensure that it has effective security controls in order to comply with Sarbanes-Oxley, the scanning tool has delivered a nice side benefit. It enables the company's asset management specialists to constantly survey Allstate's corporate network and identify and track PCs, servers and other pieces of equipment that they previously didn't have a record of, says Van Nostern.
Catching Exceptions
At the end of 2004, American Electric Power Co. (AEP) began using software from Oversight Systems Inc. in Atlanta to help it monitor transactions in its accounts payable group. If a manager authorizes a purchase above his spending limit, the system recognizes it and spits out an exception report, says Mike Sullivan, assistant controller at the Columbus, Ohio-based power company.
Those capabilities have helped AEP comply with Section 404 requirements. But


Jump to comments

IT Management

Additional Resources

WHITE PAPER
Approximately 60 percent of data migration projects overrun time or budget, while some fail completely. Download this white paper, "Enhancing Your Chance for Successful Data Migration," to learn the critical steps you need to take to execute a data migration project with minimum cost and risk to your business.
WHITE PAPER
Read the Gartner research note to learn why the TCO of a server-based computing deployment used to deliver all applications to users is around 50% lower than that of an unmanaged desktop deployment.
WHITE PAPER
Economic downturns have a tendency to accelerate emerging technologies, boost the adoption of effective solutions, and punish solutions that are not cost competitive or that are out of synch with industry trends. This IDC White Paper presents the results of an IDC survey of 330 companies in Western Europe, Asia/Pacific and the Americas that measures the receptiveness to Linux and takes into consideration changing views driven by the disruptive economic environment that businesses face today.