Home > Introduction to COBIT for SOX compliance
Book Chapter:
EMAIL THIS LICENSING & REPRINTS

Introduction to COBIT for SOX compliance

20 Dec 2005 | Syngress

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   

Sarbanes-Oxley IT Compliance Using COBIT and Open Source Tools

By Christian Lahti, Roderick Peterson, Steve Lanza
Syngress
356 Pages; $49.95

In this excerpt from Chapter 2 of Sarbanes-Oxley IT Compliance Using COBIT and Open Source Tools, authors Christian Lahti, Roderick Peterson, Steve Lanza, introduce COBIT and the standard's six components.


Sarbanes-Oxley compliance will significantly impact the IT organization of most public companies. However, there is one enormous problem: there is no specific mention of IT in Section 404, and more importantly, there are no specifics as to what controls have to be established within an IT organization to comply with Sarbanes-Oxley legislation.

If there is no specific mention in Section 404 as to what IT needs to do to comply with Sarbanes-Oxley, the logical question would be,"How can I comply with something without knowing what I need to do to comply?" Although there are various standards a company can use for defining and documenting its internal controls -- ITIL (IT Infrastructure Library), Six Sigma, and COBIT -- the majority of auditors have adopted COBIT.

ITIL is an international series of documents used to aid the implementation of a framework for IT Service Management.The intent of the framework is to define how Service Management is applied within specific organizations. Given that the framework consists of guidelines, it is agnostic of any application or platform and can therefore be applied in any organization.
MORE INFORMATION

Read Chapter 2, SOX and COBIT defined

Learn more about SOX compliance with our Learning Guide

Visit our resource center for more information on COBIT

In many organizations, Six Sigma simply means a measure of quality that strives for near perfection. Six Sigma is a disciplined, data-driven approach and methodology for eliminating defects (driving toward six standard deviations between the mean and the nearest specification limit) in any process—from manufacturing to transactional and from product to service.

COBIT stands for Control Objectives for Information and Related Technology. While the COBIT guidelines have been around since 1996, the guidelines and best practices have almost become the de facto standard for auditors and SOX compliance, mostly because the COBIT standards are platform independent.There are approximately 300 generic COBIT objectives, grouped under six COBIT Components. When reviewing and applying the COBIT guidelines and best practices, keep in mind that they will need to be tailored to your particular environment.

The six COBIT components

COBIT consists of six components:

  • Executive Summary Explains the key concepts and principles.

  • Framework Foundation for approach and COBIT elements. Organizes the process model into four domains:
    -- Plan and organize
    -- Acquire and implement
    -- Deliver and support
    -- Monitor and evaluate

  • Control Objective Foundation for approach and COBIT elements. Organizes the process model into the four domains (discussed in a moment).

  • Control Practices Identifies best practices and describes requirements for specific controls.

  • Management Guidelines Links business and IT objectives and provides tools to improve IT performance.

  • Audit Guidelines Provides guidance on how to evaluate controls, assess compliance and document risk with these characteristics:
    -- Define "internal controls" over financial reporting
    -- Internally test and assess these controls
    -- Support external audits of controls
    -- Document compliance efforts
    -- Report any significant deficiencies or material weaknesses

    In conclusion, although an IT organization is free to select any predefined standards, or even one they develop to assist them in obtaining Sarbanes-Oxley compliance, the mostly widely accepted standard is COBIT. Subsequently, you may find that selecting COBIT will be the path of least resistance to Sarbanes-Oxley compliance.

    Read the rest of Chapter 2, SOX and COBIT defined

    Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


    RELATED CONTENT
    Sarbanes-Oxley Act
    Consensus Controls project aims to set benchmarks for compliance
    Security visualization helps make log files work
    The Little Black Book of Computer Security, 2nd Edition
    Information security book excerpts and reviews
    RSA attendees see data classification, rights management projects stumble
    Hannaford breach illustrates dangerous compliance mentality
    Does SOX provision email archiving?
    PCI compliance drives identity management spending, says IBM's GRC chief
    How to conduct an efficient and thorough employee access review.
    IBM to boost security spending, push PCI DSS program
    Sarbanes-Oxley Act Research

    COBIT
    Mix of Frameworks and GRC Satisfy Compliance Overlaps
    GRC: Over-Hyped or Legit?
    Does SOX provision email archiving?
    COSO and COBIT: The value of compliance frameworks for SOX
    ISO 17799: A methodical approach to partner and service provider security management
    Mapping the path toward information security program maturity
    RSA Conference 2006
    How BS7799 and COBIT differ, part two
    Standards-based compliance: A how-to guide
    Competing regulations clog road to compliance
    COBIT Research

    Standards
    IT Infrastructure Library: Regulatory compliance benefits and training options
    Establishing Essential Controls
    Alphabet soup: Understanding standards for risk management and compliance
    What's new in the revision of ISO 17799
    Standards-based compliance: A how-to guide
    Security building blocks with ISO 17799

    RELATED GLOSSARY TERMS
    Terms from Whatis.com − the technology online dictionary
    COBIT  (SearchSecurity.com)

    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary




  • Search Additional Security Research and Solutions
    Find Security Channel Research for Resellers and Partners
    TechTarget Security Media
    Information Security View this month\\'s issue and subscribe today.
    Information Security Decisions Apply online for free conference admission.
    SearchSecurity.com
    HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




    All Rights Reserved, Copyright 2003 - 2008, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts