Home > Step 3: Establishing an IT Control Framework
Compliance School:
EMAIL THIS

Step 3: Establishing an IT Control Framework

01 Feb 2006

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   

As we mentioned, COSO is the de facto internal control framework associated with Sarbanes-Oxley. Therefore, COBIT is a natural choice for the IT Control Framework. The COBIT Framework is a set of 34 high-level control objectives organized into the four areas described in the financial and technical standards section.


About Compliance School

In Compliance School, guest instructor Richard Mackey shows you exactly what you need to do to meet regulations' ongoing demands and arms you with actionable items to ensure your business remains continuously compliant. Best of all you can attend any of the following on-demand lessons when it's most convenient for you:

Ensuring compliance across the extended enterprise

Compliance improvement: Get better as you go forward  

Gauging your SOX progress  

SOX compliance basics: Taking Action   

Understanding
compliance-related technology
The diagram above shows the 34 high-level control objectives and their relationship to the four areas. While a majority of the controls have elements that are important in SOX compliance, a number of the high-level objectives stand out.

In the area of Planning and Organization:

  • Determine the information architecture
  • Define the IT organization and relationships
  • Ensure compliance with external requirements
  • Assess risks
Virtually all of the elements of Acquisition and Implementation:
  • Acquire and maintain application software
  • Acquire and maintain technology infrastructure
  • Develop and maintain procedures
  • Install and accredit systems
  • Manage changes
Many of the elements of Delivery and Support:
  • Ensure systems security
  • Educate and train users
  • Manage the configuration
  • Manage problems and incidents
  • Manage data
  • Manage facilities
  • Manage operations
And all of the elements associated with Monitoring:
  • Monitor the processes
  • Assess internal control adequacy
  • Obtain independent assurance
  • Provide for independent audit
Using these objectives, COBIT recommends organizations follow a plan, do, check, correct cycle. This philosophy, if followed, will help to improve the effectiveness of IT operations and, at the same time, help an organization achieve SOX compliance.


Home: Introduction
Step 1: Understanding compliance -- Financial and technical standards
Step 2: Scope of compliance
Step 3: Establishing an IT Control Framework
Step 4: Detailed objectives and policies
Step 5: Measuring compliance
Step 6: Managing and tracking compliance
Step 7: The changing nature of compliance


BROWSE BY TAG
COBIT,   Security Audit, Compliance and Standards,   VIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



RELATED CONTENT
COBIT
Tony Spinelli: Prioritize Information Security over Compliance
Security survey finds increase in security standards adoption
Mix of Frameworks and GRC Satisfy Compliance Overlaps
GRC: Over-Hyped or Legit?
Is the Orange Book still relevant for assessing security controls?
Does SOX provision email archiving?
COSO and COBIT: The value of compliance frameworks for SOX
ISO 17799: A methodical approach to partner and service provider security management
Mapping the path toward information security program maturity
RSA Conference 2006
COBIT Research

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
COBIT  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary




Search Additional Security Research and Solutions
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts