Home > Some Things SOX Doesn't Say: SOX Myths
Book Chapter:
EMAIL THIS LICENSING & REPRINTS

Some Things SOX Doesn't Say: SOX Myths

14 Mar 2006 | For Dummies

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   

Sarbanes-Oxley for Dummies

By Jill Gilbert Welytok

384 pages; 21.99

 John Wiley & Sons Inc.


In this excerpt from Chapter 1 of Sarbanes-Oxley for Dummies, author Jill Gilbert Welytok demystifies four common myths about SOX.

Although SOX costs corporations billions of dollars and diverts massive resources from production and profit-generating activities, it's not all bad. In fact, there are things it doesn't require; this section puts to rest four common SOX myths.

Myth #1: Auditors can't provide tax services
SOX doesn't segregate to absurd extremes the services accountants can provide to companies. For example, in passing SOX, Congress recognized that in many cases it's practical and cost-efficient for audit firms to prepare tax returns. Although SOX precludes auditors from providing certain services to their clients to prevent Enron-type conflicts of interest, the legislation doesn't ban tax preparation services outright. Rather, the company's audit committee is charged with the responsibility of determining who provides tax services. However, some caveats must be considered in each case; for example, SOX's ban on software consulting may sound a death knell for audit firms that sell tax software to their audit clients and provide consulting services to support it.

Myth #2: Internal control means data security
Internal control refers to financial controls that impact financial statements, not data security. SOX doesn't specifically spell out any data security requirements for companies. Other legislation, such as the Health Insurance Portability and Accountability Act of 1996 (HIPAA), has rules about data security, but SOX is silent on things like password protection and encryption standards. This myth likely results (at least in part) from SOX's emphasis on internal control, which is a term sometimes used by information technology professionals.

More on SOX

Be prepared for your next audit. Visit our SOX Security School to receive free online training.

How does your organization stack up? Check your SOX compliance efforts with our SOX Scorecard.

Myth #3: The company isn't responsible for functions it outsources
Not true. Under SOX Section 404, it doesn't matter whether you outsource a system, process, or control or handle it internally -- if it impacts the financial statements, the reporting company is on the line. This means you may have to directly test the controls at your outside service providers. Or, in some circumstances, you may be able to get a special type of report called an SAS 70 (type 2) from the service provider; this report documents the effectiveness of the provider's internal controls. (For more on the SAS 70 report, flip to Chapter 13.)

Myth #4: My company met the deadline for Section 404 first-year compliance. We're home free!
Sorry, 404 certification is an annual event. And when it comes to Section 404 compliance, a corporation is never "done." Compliance is a continual and ongoing process. Your systems must evolve as the company evolves, and so must the tests that are performed on those systems.

Read the rest of Chapter 1 from Sarbanes-Oxley for Dummies

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


RELATED CONTENT
Sarbanes-Oxley Act
RSA attendees see data classification, rights management projects stumble
Hannaford breach illustrates dangerous compliance mentality
PCI compliance drives identity management spending, says IBM's GRC chief
Information security book excerpts and reviews
IBM to boost security spending, push PCI DSS program
What types of software can help a company perform a security risk assessment?
Industry group uses awareness month to lobby for data breach laws
Code Green pitches data protection for SMBs
Report: Companies still stumped by PCI DSS
COSO and COBIT: The value of compliance frameworks for SOX
Sarbanes-Oxley Act Research

COBIT
COSO and COBIT: The value of compliance frameworks for SOX
ISO 17799: A methodical approach to partner and service provider security management
Mapping the path toward information security program maturity
RSA Conference 2006
Introduction to COBIT for SOX compliance
How BS7799 and COBIT differ, part two
Standards-based compliance: A how-to guide
Competing regulations clog road to compliance
COBIT Research

Sarbanes-Oxley Act
Defining adequate security controls
Ongoing SOX compliance: A security team's to-do list
SOX Compliance for the Security Practitioner
Define security's role in the regulatory process
CSO INTERVIEW: Regulatory pain is a two-way street
SOX 404 compliance: Efficiency is key
Outfox SOX: How to make regulations work for you
Security compliance - Separating FUD from reality, part one: Sarbanes-Oxley
The real deal with Sarbanes-Oxley: Perspectives for the security manager

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
COBIT  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary


TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineWebcastsWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




All Rights Reserved, Copyright 2003 - 2008, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts