Sarbanes - Oxley and Enterprise Security: IT Governance - What It Takes to Get the Job Done
نویسندگان
چکیده
everal sections of the Sarbanes– Oxley Act of 2002 (SOX) directly affect the governance of the information technology (IT) organization, including potential SOX certification by the chief information officer, Section 404 internal control assessments, “rapid and current” disclosures to the public of material changes, and authentic and immutable record retention. The Securities and Exchange Commission (SEC) requires publicly traded companies to comply with the Treadway Commission’s Committee of Sponsoring Organizations (COSO) that defines enterprise risk and places security as a critical variable in enterprise risk assessment. Effective IT and security governance are examined in terms of SOX compliance. Motorola IT security governance demonstrates effective structures, processes, and communications; centralized security leaders participate with Motorola’s Management Board to create an enabling security organization to sustain long-term change.
منابع مشابه
Using IT governance and COBIT to deliver value with IT and respond to legal, regulatory and compliance challenges
With Sarbanes–Oxley and other legislation, securing IT within a company has become law. This article takes a look at how compliance legislation can be used to get more support from the Board when it comes to security issues, and how information assets still need to be protected further. a 2006 Elsevier Ltd. All rights reserved.
متن کاملWhat ERP systems can tell us about Sarbanes-Oxley
Purpose – To provide background for senior and middle management in information technology organizations who may be in the implementation phase of compliance for Sarbanes-Oxley (SOX). As the information technology (IT) organization looks forward to additional compliance or other IT control frameworks such as COBIT, the paper can help construct a roadmap. Other audiences include senior managemen...
متن کاملCapital Structure , Corporate Governance , and the Effect of Sarbanes - Oxley
The Sarbanes-Oxley Act represented a major legislative action designed to increase transparency and accountability in U.S. corporations. Within the context of agency theory and corporate governance, the expectation is that the enactment of Sarbanes-Oxley impacted the agency relationship of firms and hence affected the corporate governance structure. With these changes, the question arises as to...
متن کاملUsing SAP System Configuration Security Test to Comply with Sarbanesoxley Act
Most observers would agree that the Sarbanes-Oxley Act (SOA) is the single most important piece of legislation affecting corporate governance, financial disclosure and the practice of public accounting. On the other hand, the SAP system is the most widely used ERP (Enterprise Resource Planning) system in the world. There are thousands of seamlessly linked components and subsystems. Conducting s...
متن کاملSarbanes-Oxley Links IT to Corporate Compliance
In the wake of financial frauds and related audit issues, the US Congress passed the Sarbanes-Oxley (SARBOX) Act of 2002. Key to becoming SARBOX compliant are information systems (IS) that satisfy the mandates regarding internal controls, corporate governance, and fraud detection. These legal developments focusing senior management's attention on (1) internal controls are present and functionin...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید
ثبت ناماگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید
ورودعنوان ژورنال:
- Information Systems Security
دوره 14 شماره
صفحات -
تاریخ انتشار 2005