Sarbanes - Oxley and Enterprise Security: IT Governance - What It Takes to Get the Job Done

نویسندگان

  • William Brown
  • Frank Nasuti
چکیده

everal sections of the Sarbanes– Oxley Act of 2002 (SOX) directly affect the governance of the information technology (IT) organization, including potential SOX certification by the chief information officer, Section 404 internal control assessments, “rapid and current” disclosures to the public of material changes, and authentic and immutable record retention. The Securities and Exchange Commission (SEC) requires publicly traded companies to comply with the Treadway Commission’s Committee of Sponsoring Organizations (COSO) that defines enterprise risk and places security as a critical variable in enterprise risk assessment. Effective IT and security governance are examined in terms of SOX compliance. Motorola IT security governance demonstrates effective structures, processes, and communications; centralized security leaders participate with Motorola’s Management Board to create an enabling security organization to sustain long-term change.

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Using IT governance and COBIT to deliver value with IT and respond to legal, regulatory and compliance challenges

With Sarbanes–Oxley and other legislation, securing IT within a company has become law. This article takes a look at how compliance legislation can be used to get more support from the Board when it comes to security issues, and how information assets still need to be protected further. a 2006 Elsevier Ltd. All rights reserved.

متن کامل

What ERP systems can tell us about Sarbanes-Oxley

Purpose – To provide background for senior and middle management in information technology organizations who may be in the implementation phase of compliance for Sarbanes-Oxley (SOX). As the information technology (IT) organization looks forward to additional compliance or other IT control frameworks such as COBIT, the paper can help construct a roadmap. Other audiences include senior managemen...

متن کامل

Capital Structure , Corporate Governance , and the Effect of Sarbanes - Oxley

The Sarbanes-Oxley Act represented a major legislative action designed to increase transparency and accountability in U.S. corporations. Within the context of agency theory and corporate governance, the expectation is that the enactment of Sarbanes-Oxley impacted the agency relationship of firms and hence affected the corporate governance structure. With these changes, the question arises as to...

متن کامل

Using SAP System Configuration Security Test to Comply with Sarbanesoxley Act

Most observers would agree that the Sarbanes-Oxley Act (SOA) is the single most important piece of legislation affecting corporate governance, financial disclosure and the practice of public accounting. On the other hand, the SAP system is the most widely used ERP (Enterprise Resource Planning) system in the world. There are thousands of seamlessly linked components and subsystems. Conducting s...

متن کامل

Sarbanes-Oxley Links IT to Corporate Compliance

In the wake of financial frauds and related audit issues, the US Congress passed the Sarbanes-Oxley (SARBOX) Act of 2002. Key to becoming SARBOX compliant are information systems (IS) that satisfy the mandates regarding internal controls, corporate governance, and fraud detection. These legal developments focusing senior management's attention on (1) internal controls are present and functionin...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

عنوان ژورنال:
  • Information Systems Security

دوره 14  شماره 

صفحات  -

تاریخ انتشار 2005