SlideShare une entreprise Scribd logo
1  sur  17
Télécharger pour lire hors ligne
SOX: IT Perspective




   Neelabh Srivastava
SOX: IT Perspective

    Agenda
      Background
      Facts about SOX ACT
      Objective
      Section 404: Key Points
      A Burden or Opportunity
      Challenges
      Sox Benefits
      SOX Compliance Frameworks
      FAQs
      Conclusion


2    Neelabh Srivastava                         September 2012
SOX: IT Perspective

    Background

     Two largest US companies goes bankrupt.
     Other financial frauds follow.
     Investors lost money & faith in companies
     Debacle in Stock Market.
     US govt. took action.
     Sarbanes and Oxley Act was made Law.




3     Neelabh Srivastava                         September 2012
SOX: IT Perspective

    Facts about SOX Act
     The Act was passed on 30 July, 2002.
     Names after its Architects US Senator
         Paul Sarbanes and US Representative
         Michael Oxley.
        Also Known as SOA (Sarbanes-Oxley Act)
        Applies to Publicly-traded companies in US.
        The act consists of 11 sections.
        Known as one of the worst Tech related Bills
         of all time.

4       Neelabh Srivastava                              September 2012
SOX: IT Perspective

    Objective:
     Fundamentally, Sarbanes-Oxley (SOX) requires that financial
       reports are based on
       accurate information and that
       the processes by which this
       information is collected are
       themselves accurate & controlled.

     Rebuilding Public Trust.




5     Neelabh Srivastava                             September 2012
SOX: IT Perspective

    Section 404: Key Points
     Refers to “Management assessment of Internal Controls”
     With only 180 words, this section has created a furor in
      various depts. including IT.
     As IT controls financial processing and reporting,
      therefore falls in SOX ambit.
     Effectively it is forced implementation of the best
      practices.
     404 Most contentious part of SOX.


6     Neelabh Srivastava                            September 2012
SOX: IT Perspective

    A Burden or An Opportunity




                  It’s a matter of Perspective.
    Classic Example of “Glass Half Empty or Half Full”


7     Neelabh Srivastava                           September 2012
SOX: IT Perspective

    Challenges:
     High Compliance Costs
     Segregation of Duties
       (too few people)
     Increase in Project Durations.
     High Administrative work.
     Increased workload on IT staff.




8    Neelabh Srivastava                         September 2012
SOX: IT Perspective

    SOX Benefits:
     Standardizing/Eliminating Variation of Computing Envt.
     Automation of Manual Processes.
     Identification and addressing risks and in your
         environment.
        Improved efficiencies through consolidation.
        Reduced Operating costs.
        Reduced Incidents
        Documentation for every process/operation.

9       Neelabh Srivastava                          September 2012
SOX: IT Perspective

     SOX Compliance Frameworks
      COBIT (Control Objectives for Information and Related
          Technology)
         COSO (Committee of Sponsoring Organizations).
         ITIL (Information Technology Infrastructure Library)
         COCO (Criteria of Control).
         Tumbull Framework
         King Framework

     COSO is the most widely adopted framework in US.

10       Neelabh Srivastava                          September 2012
SOX: IT Perspective

     FAQ:
     1) How often do companies need to comply with
     SOX - annually or quarterly?
     All publicly traded companies must comply with SOX both
     annually and quarterly. Section 404 is an annual evaluation of
     internal controls which requires annual compliance, whereas
     other sections like 302 and 906 are both quarterly
     certification requirements.



11     Neelabh Srivastava                             September 2012
SOX: IT Perspective

     FAQ:
     2) What does Section 404 mean from practical
        perspective?
         In practice it will depend on the external auditor to
         define what aspects of the overall operations that they feel
         are material and then to what degree. It can be based on
         multiple criterion including their own control objectives.




12     Neelabh Srivastava                              September 2012
SOX: IT Perspective

     FAQ:
     3) If the SOX is intended for Financial reforms then
        how does IT came in picture?
         The thing to remember about SOX is that it is primarily
         focused on the accuracy of financial reporting data. IT per
         say is important under SOX only to the extent that it
         enhances the reliability and integrity of that reporting
         which of course can be achieved by having full controls
         over IT infra, Change management, IT security etc…


13     Neelabh Srivastava                             September 2012
SOX: IT Perspective

     FAQ:
     4) Whether non-production systems such as Dev, QA,
         Test etc.. systems should be in-scope for SOX?
         They might not be in the "direct" scope of SOX, but these
         environments certainly play a role in the Change
         Management process and other Life Cycles. Thus, they
         cannot be completely ignored.




14     Neelabh Srivastava                           September 2012
SOX: IT Perspective

     FAQ:
     5) If this is ever going to finish?
        Unfortunately No, there will be an ongoing need to update
     and validate the processes and supporting documentation.




15     Neelabh Srivastava                          September 2012
SOX: IT Perspective

     Conclusion:
       The better reason to have good controls over IT and IT
       security, however, is not because it will make you SOX
       compliant but because it will make your business more
       efficient, enable you to better utilize your data, and allow
       you to trust ALL the data, not just financial reporting
       data.




16    Neelabh Srivastava                             September 2012
SOX: IT Perspective

     References:

      http://en.wikipedia.org/wiki/Sarbanes–Oxley_Act
      http://en.wikipedia.org/wiki/Information_technology_controls
      http://www.securityfocus.com/columnists/322
      http://www.sarbanes-oxley-101.com




17    Neelabh Srivastava                              September 2012

Contenu connexe

Tendances

ISO/IEC 27001:2022 – What are the changes?
ISO/IEC 27001:2022 – What are the changes?ISO/IEC 27001:2022 – What are the changes?
ISO/IEC 27001:2022 – What are the changes?
PECB
 
Governance, Risk & Compliance Management Solution
Governance, Risk & Compliance Management SolutionGovernance, Risk & Compliance Management Solution
Governance, Risk & Compliance Management Solution
Rishabh Software
 

Tendances (20)

Sox Compliance Solution
Sox Compliance SolutionSox Compliance Solution
Sox Compliance Solution
 
ISO/IEC 27001:2022 – What are the changes?
ISO/IEC 27001:2022 – What are the changes?ISO/IEC 27001:2022 – What are the changes?
ISO/IEC 27001:2022 – What are the changes?
 
27001 awareness Training
27001 awareness Training27001 awareness Training
27001 awareness Training
 
IT Control Objectives for SOX
IT Control Objectives for SOXIT Control Objectives for SOX
IT Control Objectives for SOX
 
How can the ISO 27701 help to design, implement, operate and improve a privac...
How can the ISO 27701 help to design, implement, operate and improve a privac...How can the ISO 27701 help to design, implement, operate and improve a privac...
How can the ISO 27701 help to design, implement, operate and improve a privac...
 
ISO/IEC 27001:2013 An Overview
ISO/IEC 27001:2013  An Overview ISO/IEC 27001:2013  An Overview
ISO/IEC 27001:2013 An Overview
 
Compliance framework
Compliance frameworkCompliance framework
Compliance framework
 
Control and audit of information System (hendri eka saputra)
Control and audit of information System (hendri eka saputra)Control and audit of information System (hendri eka saputra)
Control and audit of information System (hendri eka saputra)
 
Basics in IT Audit and Application Control Testing
Basics in IT Audit and Application Control Testing Basics in IT Audit and Application Control Testing
Basics in IT Audit and Application Control Testing
 
Iso iec 27001 foundation training course by interprom
Iso iec 27001 foundation training course by interpromIso iec 27001 foundation training course by interprom
Iso iec 27001 foundation training course by interprom
 
ISO 27001
ISO 27001ISO 27001
ISO 27001
 
Coso framework
Coso frameworkCoso framework
Coso framework
 
Introduction to it auditing
Introduction to it auditingIntroduction to it auditing
Introduction to it auditing
 
Governance, Risk & Compliance Management Solution
Governance, Risk & Compliance Management SolutionGovernance, Risk & Compliance Management Solution
Governance, Risk & Compliance Management Solution
 
Compliance Risk Assessment
Compliance Risk AssessmentCompliance Risk Assessment
Compliance Risk Assessment
 
IT compliance
IT complianceIT compliance
IT compliance
 
ISO27001: Implementation & Certification Process Overview
ISO27001: Implementation & Certification Process OverviewISO27001: Implementation & Certification Process Overview
ISO27001: Implementation & Certification Process Overview
 
Project plan for ISO 27001
Project plan for ISO 27001Project plan for ISO 27001
Project plan for ISO 27001
 
ISO 27001 2013 isms final overview
ISO 27001 2013 isms final overviewISO 27001 2013 isms final overview
ISO 27001 2013 isms final overview
 
ISO 27001 Awareness/TRansition.pptx
ISO 27001 Awareness/TRansition.pptxISO 27001 Awareness/TRansition.pptx
ISO 27001 Awareness/TRansition.pptx
 

En vedette

Sarbanes-Oxley Act 2002
Sarbanes-Oxley Act 2002Sarbanes-Oxley Act 2002
Sarbanes-Oxley Act 2002
Syed Shah
 
sap security interview_questions
sap security interview_questionssap security interview_questions
sap security interview_questions
sumitmsn2
 
Sarbanes Oxley Act
Sarbanes Oxley ActSarbanes Oxley Act
Sarbanes Oxley Act
les561
 
Segregation of Duties Solutions
Segregation of Duties SolutionsSegregation of Duties Solutions
Segregation of Duties Solutions
Ahmed Abdul Hamed
 
SAP GRC AC 10.1 - ARM Workflows
SAP GRC AC 10.1 - ARM WorkflowsSAP GRC AC 10.1 - ARM Workflows
SAP GRC AC 10.1 - ARM Workflows
Rohan Andrews
 
SAP Security important Questions
SAP Security important QuestionsSAP Security important Questions
SAP Security important Questions
Ragu M
 

En vedette (20)

Sarbanes-Oxley Act 2002
Sarbanes-Oxley Act 2002Sarbanes-Oxley Act 2002
Sarbanes-Oxley Act 2002
 
Sarbanes-Oxley act
Sarbanes-Oxley actSarbanes-Oxley act
Sarbanes-Oxley act
 
Sarbanes-Oxley Act (SOX)
Sarbanes-Oxley Act (SOX)Sarbanes-Oxley Act (SOX)
Sarbanes-Oxley Act (SOX)
 
Sox In Telecom Industry
Sox In Telecom IndustrySox In Telecom Industry
Sox In Telecom Industry
 
Rethinking Segregation of Duties: Where Is Your Business Most Exposed?
Rethinking Segregation of Duties: Where Is Your Business Most Exposed?Rethinking Segregation of Duties: Where Is Your Business Most Exposed?
Rethinking Segregation of Duties: Where Is Your Business Most Exposed?
 
sap security interview_questions
sap security interview_questionssap security interview_questions
sap security interview_questions
 
Sarbanes Oxley Act
Sarbanes Oxley ActSarbanes Oxley Act
Sarbanes Oxley Act
 
Profiling for SAP - Compliance Management, Access Control and Segregation of ...
Profiling for SAP - Compliance Management, Access Control and Segregation of ...Profiling for SAP - Compliance Management, Access Control and Segregation of ...
Profiling for SAP - Compliance Management, Access Control and Segregation of ...
 
Sarbanes Oxley Act
Sarbanes Oxley ActSarbanes Oxley Act
Sarbanes Oxley Act
 
Effective Segregation of Duties for PeopleSoft 2011-02-23
Effective Segregation of Duties for PeopleSoft 2011-02-23Effective Segregation of Duties for PeopleSoft 2011-02-23
Effective Segregation of Duties for PeopleSoft 2011-02-23
 
Automating PeopleSoft Segregation of Duties: HCM and Financials
Automating PeopleSoft Segregation of Duties: HCM and FinancialsAutomating PeopleSoft Segregation of Duties: HCM and Financials
Automating PeopleSoft Segregation of Duties: HCM and Financials
 
Grc 10 training
Grc 10 trainingGrc 10 training
Grc 10 training
 
Segregation of Duties Solutions
Segregation of Duties SolutionsSegregation of Duties Solutions
Segregation of Duties Solutions
 
SAP GRC AC 10.1 - ARM Workflows
SAP GRC AC 10.1 - ARM WorkflowsSAP GRC AC 10.1 - ARM Workflows
SAP GRC AC 10.1 - ARM Workflows
 
SAP grc
SAP grc SAP grc
SAP grc
 
Segregation of duties in SAP @ ISACA Pune presentation on 18.4.2015
Segregation of duties in SAP @ ISACA Pune presentation on 18.4.2015 Segregation of duties in SAP @ ISACA Pune presentation on 18.4.2015
Segregation of duties in SAP @ ISACA Pune presentation on 18.4.2015
 
Introduction to SAP Security
Introduction to SAP SecurityIntroduction to SAP Security
Introduction to SAP Security
 
SAP Security important Questions
SAP Security important QuestionsSAP Security important Questions
SAP Security important Questions
 
Practical guide for sap security
Practical guide for sap security Practical guide for sap security
Practical guide for sap security
 
SAP GRC 10 Access Control
SAP GRC 10 Access ControlSAP GRC 10 Access Control
SAP GRC 10 Access Control
 

Similaire à SOX- IT Perspective

8 reasons you need a strategy for managing information..before it's too late
8 reasons you need a strategy for managing information..before it's too late8 reasons you need a strategy for managing information..before it's too late
8 reasons you need a strategy for managing information..before it's too late
Vander Loto
 
IT Governance Security questions and answers for Dr.Sidney. I will p.docx
IT Governance Security questions and answers for Dr.Sidney. I will p.docxIT Governance Security questions and answers for Dr.Sidney. I will p.docx
IT Governance Security questions and answers for Dr.Sidney. I will p.docx
careyshaunda
 
201306 CIO NET The Value of IT Frameworks
201306 CIO NET The Value of IT Frameworks201306 CIO NET The Value of IT Frameworks
201306 CIO NET The Value of IT Frameworks
Francisco Calzado
 
WEEK 1Resources Frameworks and Plenitude Please respond to t.docx
WEEK 1Resources Frameworks and Plenitude Please respond to t.docxWEEK 1Resources Frameworks and Plenitude Please respond to t.docx
WEEK 1Resources Frameworks and Plenitude Please respond to t.docx
jessiehampson
 
ISO Monday Web Seminar - See A Lot By Looking
ISO Monday Web Seminar - See A Lot By LookingISO Monday Web Seminar - See A Lot By Looking
ISO Monday Web Seminar - See A Lot By Looking
afaber
 
Newcastle conclusion2013
Newcastle conclusion2013Newcastle conclusion2013
Newcastle conclusion2013
Lee Schlenker
 

Similaire à SOX- IT Perspective (20)

GOVERNING INFORMATION SECURITY IN CONJUNCTION WITH COBIT AND ISO 27001
GOVERNING INFORMATION SECURITY IN CONJUNCTION WITH COBIT AND ISO 27001GOVERNING INFORMATION SECURITY IN CONJUNCTION WITH COBIT AND ISO 27001
GOVERNING INFORMATION SECURITY IN CONJUNCTION WITH COBIT AND ISO 27001
 
AN IT EXECUTIVE'S OVERVIEW
AN IT EXECUTIVE'S OVERVIEWAN IT EXECUTIVE'S OVERVIEW
AN IT EXECUTIVE'S OVERVIEW
 
Convergence SOA & BI Presentation June 2010
Convergence SOA & BI Presentation June 2010Convergence SOA & BI Presentation June 2010
Convergence SOA & BI Presentation June 2010
 
Ontology and taxonomy creation presented dc 3day
Ontology and taxonomy creation presented dc 3dayOntology and taxonomy creation presented dc 3day
Ontology and taxonomy creation presented dc 3day
 
8 reasons you need a strategy for managing information..before it's too late
8 reasons you need a strategy for managing information..before it's too late8 reasons you need a strategy for managing information..before it's too late
8 reasons you need a strategy for managing information..before it's too late
 
Cutter Journal: Surfing the SOX wave thanks to CMMi ®, 2007
Cutter Journal: Surfing the SOX wave thanks to CMMi ®, 2007 Cutter Journal: Surfing the SOX wave thanks to CMMi ®, 2007
Cutter Journal: Surfing the SOX wave thanks to CMMi ®, 2007
 
IT Governance Security questions and answers for Dr.Sidney. I will p.docx
IT Governance Security questions and answers for Dr.Sidney. I will p.docxIT Governance Security questions and answers for Dr.Sidney. I will p.docx
IT Governance Security questions and answers for Dr.Sidney. I will p.docx
 
201306 CIO NET The Value of IT Frameworks
201306 CIO NET The Value of IT Frameworks201306 CIO NET The Value of IT Frameworks
201306 CIO NET The Value of IT Frameworks
 
Israel IT Market 2006 2008
Israel IT Market 2006 2008Israel IT Market 2006 2008
Israel IT Market 2006 2008
 
Grove Ventures Shift Happens Report
Grove Ventures Shift Happens ReportGrove Ventures Shift Happens Report
Grove Ventures Shift Happens Report
 
Grove Ventures Shift Happens Report
Grove Ventures Shift Happens ReportGrove Ventures Shift Happens Report
Grove Ventures Shift Happens Report
 
ITIL continual service improvement
ITIL continual service improvementITIL continual service improvement
ITIL continual service improvement
 
Fast IT Mariano O'Kon, Cisco Live Cancun 2014
Fast IT Mariano O'Kon, Cisco Live Cancun 2014Fast IT Mariano O'Kon, Cisco Live Cancun 2014
Fast IT Mariano O'Kon, Cisco Live Cancun 2014
 
WEEK 1Resources Frameworks and Plenitude Please respond to t.docx
WEEK 1Resources Frameworks and Plenitude Please respond to t.docxWEEK 1Resources Frameworks and Plenitude Please respond to t.docx
WEEK 1Resources Frameworks and Plenitude Please respond to t.docx
 
ISO Monday Web Seminar - See A Lot By Looking
ISO Monday Web Seminar - See A Lot By LookingISO Monday Web Seminar - See A Lot By Looking
ISO Monday Web Seminar - See A Lot By Looking
 
Why Modern Systems Require a New Approach to Observability
Why Modern Systems Require a New Approach to ObservabilityWhy Modern Systems Require a New Approach to Observability
Why Modern Systems Require a New Approach to Observability
 
The Room | Innotrain systematization
The Room | Innotrain systematization The Room | Innotrain systematization
The Room | Innotrain systematization
 
COBIT 5 Basic Concepts
COBIT 5 Basic ConceptsCOBIT 5 Basic Concepts
COBIT 5 Basic Concepts
 
SOA Course - SOA governance - Lecture 19
SOA Course - SOA governance - Lecture 19SOA Course - SOA governance - Lecture 19
SOA Course - SOA governance - Lecture 19
 
Newcastle conclusion2013
Newcastle conclusion2013Newcastle conclusion2013
Newcastle conclusion2013
 

Dernier

EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptxEIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
Earley Information Science
 
CNv6 Instructor Chapter 6 Quality of Service
CNv6 Instructor Chapter 6 Quality of ServiceCNv6 Instructor Chapter 6 Quality of Service
CNv6 Instructor Chapter 6 Quality of Service
giselly40
 

Dernier (20)

Handwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed textsHandwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed texts
 
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot TakeoffStrategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
 
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
 
From Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time AutomationFrom Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time Automation
 
Finology Group – Insurtech Innovation Award 2024
Finology Group – Insurtech Innovation Award 2024Finology Group – Insurtech Innovation Award 2024
Finology Group – Insurtech Innovation Award 2024
 
Exploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone ProcessorsExploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone Processors
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected Worker
 
[2024]Digital Global Overview Report 2024 Meltwater.pdf
[2024]Digital Global Overview Report 2024 Meltwater.pdf[2024]Digital Global Overview Report 2024 Meltwater.pdf
[2024]Digital Global Overview Report 2024 Meltwater.pdf
 
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
 
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law DevelopmentsTrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
 
How to convert PDF to text with Nanonets
How to convert PDF to text with NanonetsHow to convert PDF to text with Nanonets
How to convert PDF to text with Nanonets
 
The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024
 
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptxEIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
 
Boost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivityBoost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivity
 
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemkeProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
 
CNv6 Instructor Chapter 6 Quality of Service
CNv6 Instructor Chapter 6 Quality of ServiceCNv6 Instructor Chapter 6 Quality of Service
CNv6 Instructor Chapter 6 Quality of Service
 
Understanding Discord NSFW Servers A Guide for Responsible Users.pdf
Understanding Discord NSFW Servers A Guide for Responsible Users.pdfUnderstanding Discord NSFW Servers A Guide for Responsible Users.pdf
Understanding Discord NSFW Servers A Guide for Responsible Users.pdf
 
Scaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organizationScaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organization
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected Worker
 
Partners Life - Insurer Innovation Award 2024
Partners Life - Insurer Innovation Award 2024Partners Life - Insurer Innovation Award 2024
Partners Life - Insurer Innovation Award 2024
 

SOX- IT Perspective

  • 1. SOX: IT Perspective Neelabh Srivastava
  • 2. SOX: IT Perspective Agenda  Background  Facts about SOX ACT  Objective  Section 404: Key Points  A Burden or Opportunity  Challenges  Sox Benefits  SOX Compliance Frameworks  FAQs  Conclusion 2 Neelabh Srivastava September 2012
  • 3. SOX: IT Perspective Background  Two largest US companies goes bankrupt.  Other financial frauds follow.  Investors lost money & faith in companies  Debacle in Stock Market.  US govt. took action.  Sarbanes and Oxley Act was made Law. 3 Neelabh Srivastava September 2012
  • 4. SOX: IT Perspective Facts about SOX Act  The Act was passed on 30 July, 2002.  Names after its Architects US Senator Paul Sarbanes and US Representative Michael Oxley.  Also Known as SOA (Sarbanes-Oxley Act)  Applies to Publicly-traded companies in US.  The act consists of 11 sections.  Known as one of the worst Tech related Bills of all time. 4 Neelabh Srivastava September 2012
  • 5. SOX: IT Perspective Objective:  Fundamentally, Sarbanes-Oxley (SOX) requires that financial reports are based on accurate information and that the processes by which this information is collected are themselves accurate & controlled.  Rebuilding Public Trust. 5 Neelabh Srivastava September 2012
  • 6. SOX: IT Perspective Section 404: Key Points  Refers to “Management assessment of Internal Controls”  With only 180 words, this section has created a furor in various depts. including IT.  As IT controls financial processing and reporting, therefore falls in SOX ambit.  Effectively it is forced implementation of the best practices.  404 Most contentious part of SOX. 6 Neelabh Srivastava September 2012
  • 7. SOX: IT Perspective A Burden or An Opportunity It’s a matter of Perspective. Classic Example of “Glass Half Empty or Half Full” 7 Neelabh Srivastava September 2012
  • 8. SOX: IT Perspective Challenges:  High Compliance Costs  Segregation of Duties (too few people)  Increase in Project Durations.  High Administrative work.  Increased workload on IT staff. 8 Neelabh Srivastava September 2012
  • 9. SOX: IT Perspective SOX Benefits:  Standardizing/Eliminating Variation of Computing Envt.  Automation of Manual Processes.  Identification and addressing risks and in your environment.  Improved efficiencies through consolidation.  Reduced Operating costs.  Reduced Incidents  Documentation for every process/operation. 9 Neelabh Srivastava September 2012
  • 10. SOX: IT Perspective SOX Compliance Frameworks  COBIT (Control Objectives for Information and Related Technology)  COSO (Committee of Sponsoring Organizations).  ITIL (Information Technology Infrastructure Library)  COCO (Criteria of Control).  Tumbull Framework  King Framework COSO is the most widely adopted framework in US. 10 Neelabh Srivastava September 2012
  • 11. SOX: IT Perspective FAQ: 1) How often do companies need to comply with SOX - annually or quarterly? All publicly traded companies must comply with SOX both annually and quarterly. Section 404 is an annual evaluation of internal controls which requires annual compliance, whereas other sections like 302 and 906 are both quarterly certification requirements. 11 Neelabh Srivastava September 2012
  • 12. SOX: IT Perspective FAQ: 2) What does Section 404 mean from practical perspective? In practice it will depend on the external auditor to define what aspects of the overall operations that they feel are material and then to what degree. It can be based on multiple criterion including their own control objectives. 12 Neelabh Srivastava September 2012
  • 13. SOX: IT Perspective FAQ: 3) If the SOX is intended for Financial reforms then how does IT came in picture? The thing to remember about SOX is that it is primarily focused on the accuracy of financial reporting data. IT per say is important under SOX only to the extent that it enhances the reliability and integrity of that reporting which of course can be achieved by having full controls over IT infra, Change management, IT security etc… 13 Neelabh Srivastava September 2012
  • 14. SOX: IT Perspective FAQ: 4) Whether non-production systems such as Dev, QA, Test etc.. systems should be in-scope for SOX? They might not be in the "direct" scope of SOX, but these environments certainly play a role in the Change Management process and other Life Cycles. Thus, they cannot be completely ignored. 14 Neelabh Srivastava September 2012
  • 15. SOX: IT Perspective FAQ: 5) If this is ever going to finish? Unfortunately No, there will be an ongoing need to update and validate the processes and supporting documentation. 15 Neelabh Srivastava September 2012
  • 16. SOX: IT Perspective Conclusion: The better reason to have good controls over IT and IT security, however, is not because it will make you SOX compliant but because it will make your business more efficient, enable you to better utilize your data, and allow you to trust ALL the data, not just financial reporting data. 16 Neelabh Srivastava September 2012
  • 17. SOX: IT Perspective References: http://en.wikipedia.org/wiki/Sarbanes–Oxley_Act http://en.wikipedia.org/wiki/Information_technology_controls http://www.securityfocus.com/columnists/322 http://www.sarbanes-oxley-101.com 17 Neelabh Srivastava September 2012