| Home > SOX reality check: Compliance management products | |
| Security School: |
|
||
![]() by Richard Mackey Sarbanes-Oxley compliance is a major undertaking. It requires the understanding of requirements by people across departments, the coordination of employees and auditors from a variety of technical and business departments, and painstaking tracking of compliance status. SOX compliance also requires accurate documentation and tracking of a wide array of technical, business and legal aspects of the enterprise. Despite the all-encompassing nature of SOX, some vendors claim their single tool can do it all. Let's take a look at what these products can and can't do for you.
What they can't do
What they can do Compliance tools range from portals, like the SOX Portal in Protiviti's SOX suite, that aid in communications, to document management tools like Certus' 404 and 302 products, to Hyperion's Compliance Management Dashboard that present a graphical display.
Many companies, Microsoft among them, turn to more generic portal and office automation products like Microsoft Sharepoint, Microsoft Office and Microsoft Project to be the centerpieces of their SOX communications and documentation efforts. SharePoint is often used to communicate project goals, meeting schedules, status and documentation across a widely dispersed project group. While not structured specifically with SOX in mind, these generic tools help many organizations achieve compliance.
The rest is up to you Compliance is a multifaceted problem that simply can't be addressed by one or even a whole set of tools. After all, compliance is about maintaining the integrity of your financials. This is accomplished by applying business and technical controls where they are needed for your business. Technical checks and balances, like change control, provisioning workflow and access control, log review, and vulnerability management, need to be applied alongside business controls to provide assurance that no one can attempt to perpetrate fraud without one or more of these controls detecting or preventing it.
'); // -->
|
|
||||||||||||||||||||||||||||||||||
|
|||||||||||||||||||||||||||
|
||||||||||