Technology to automate SOX compliance according to COBIT frameworks

Technology to automate SOX compliance according to COBIT frameworks

I heard about some new products that promise to automate SOX compliance, often using a specific framework like COBIT. What do these products actually do, and generally how effective are they at easing an enterprise's compliance burden?

    Requires Free Membership to View

    SearchSecurity.com members gain immediate and unlimited access to breaking industry news, virus alerts, new hacker threats, highly focused security newsletters, and more -- all at no cost. Join me on SearchSecurity.com today!

    Michael S. Mimoso, Editorial Director

    By submitting your registration information to SearchSecurity.com you agree to receive email communications from TechTarget and TechTarget partners. We encourage you to read our Privacy Policy which contains important disclosures about how we collect and use your registration and other information. If you reside outside of the United States, by submitting this registration information you consent to having your personal data transferred to and processed in the United States. Your use of SearchSecurity.com is governed by our Terms of Use. You may contact us at webmaster@TechTarget.com.

There are a variety of products that purport to help automate SOX compliance, largely via a combination of scan data analytics from a vulnerability analysis product, like those made by Qualys Inc. or Sourcefire Inc., and checklists of controls that are part of the standard COBIT framework.

I haven't done a detailed analysis of this space, but I highly suspect there is nothing in these products that can't be done equally well, if not better, by a good project manager, a good security manager and a spreadsheet program. Essentially, what is needed is someone who understands the technology and how it's deployed (a security manager), someone to track objectives and help interface with other groups when necessary (a project manager) and some software to track the goals and objectives (a spreadsheet). Like many things in the IT world, measuring compliance is a pretty basic task, though the actual details can get complicated.

The value of commercial compliance products really comes in if the company doesn't have the resources or time for a project manager or doesn't have a lot of in-house experience when it comes to dealing with audits and auditors. In that case, especially when using a product the auditors are familiar with, software like this may save some time during an audit.

For more information:

This was first published in November 2009

Join the conversationComment

Share
Comments

    Results

    Contribute to the conversation

    All fields are required. Comments will appear at the bottom of the article.