Newsletters Welcome, Guest Log In | Register

Governance and Risk

From regulatory compliance to corporate governance structure, everyone is involved

About this Blogger RSS

Subscribe

Sign up now and get the best business technology insights direct to your inbox.

  • Daily Edge
  • CTO Edge Update
  • Business Tools & Templates
  • Aligning IT & Business Goals
  • Maximizing IT Investments

0

Sarbox Compliance Cheat Sheet

Posted by Lora Bentley Feb 27, 2008 4:16:34 PM

In Tuesday's Sarbanes-Oxley Compliance Journal, Syrinx Consulting CEO Andrew Gelina outlines several do's and don'ts for CIOs who are implementing a Sarbanes-Oxley compliance program in their companies. Though they are most likely review for many, they zero in on one important fact that is often forgotten:

[A]ny compliance effort requires the cooperation of people, and people are imperfect.

To that end, the "Do" list includes such advice as:

  1. Start with good IT governance, then move to financial controls. Always let the IT and financial managers involved know ahead of time that a Sarbanes-Oxley compliant protocol is in the works and that it will help, rather than harm, department efficiencies.
  2. Make it an enterprise-wide effort to define the compliance program's goals and the processes necessary to meet those goals. That way, they're more likely to take ownership of the program's success.
  3. Keep it simple.
  4. Use technology to increase data visibility and improve process efficiency.
  5. Make sure processes, technology driven or otherwise, are auditable.

And on the "Don't" list:

  1. Hurry. Analyze your IT and financial controls and define your compliance goals before you think about purchasing technology.
  2. Deploy a huge new system across the entire organization all at once. Such "bomb dropping," as Gelina calls it, will ...
  3. shove a square peg into a round hole. Find the technology that will do the job that needs to be done.
  4. Confuse compliance with disaster recovery.

Add a comment Leave a comment on this blog post.

There are no comments on this post

Lowering Your IT Costs with Oracle Database 11g Release 2

This white paper identifies the key capabilities a database management solution needs to successfully deliver more information with higher quality of service, make more efficient use of IT budgets, and reduce the risk of change in data centers.

Software Forum: Information On Demand Virtual Experience

This interactive virtual forum presents leading IT experts providing the insights you need to turn your information into a strategic driver for innovation, business optimization and competitive differentiation.

Information Management

Tools, tips and solutions to help you manage your data more efficiently to tackle today's challenging economic environment.

Service Oriented Architecture (SOA)

Service-Oriented Architecture is the catalyst that allows today’s companies to respond to business demands faster and more effectively than ever.

Data Management

Data management tips and techniques that insure ease of access, comprehensive security and absolute privacy for your invaluable company information.

Optimized Infrastructure

Hardware and software tools to create an enterprise infrastructure for data and business optimization.

Six Sigma Framework for IT

This collection of tutorials, calculators, and templates will show you how to apply six sigma thinking to IT service management.

Learn more >

Strategic IT Planning & Governance Best Practices Guide

Use this guide — along with the more than 60 templates included — to ensure the overall success of your entire IT department.

Learn more >