Home > Security News > Survey sheds light on SOX spending
Security News:
EMAIL THIS

Survey sheds light on SOX spending

By Ed Parry, News Editor
06 Oct 2004 | SearchSecurity.com

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   

Spam and the Sarbanes-Oxley Act (SOX) are registering much bigger blips on the radars of U.S. CIOs, according to a recent survey from the Society for Information Management.

SIM polled nearly 250 senior IT executives from its membership in North America.

Taking a stab at spam

Of the respondents whose companies have annual revenues of more than $1 billion, 75% have invested in antispam software.

Smaller companies are not far behind. Of the respondents whose firms have annual revenues of less than $1 billion, 70% have bought software to stem the surge of spam in company inboxes.

And the antispam software can't afford to take a break. Last month, three out of every four e-mails processed by e-mail security firm Postini Inc. was junk.

St. George Crystal Ltd. is a smaller firm that has invested in antispam software. Richard Service, CIO of the Jeannette, Pa.-based company, said he's spent about $1,000 on his e-mail system. He'd like to spend more.

"There are just too many other priorities," he said.

Service believes that the amount of spam is even higher than estimates like Postini's. He's worried that it may be a threat to e-mail itself.

"It's overwhelming -- there's so much. [I'm afraid] that it's going to get so bad [that] it's going to make e-mail useless," he said.

Henry Volkman, CIO of Lake Forest, Calif.-based Del Taco Inc., was slightly more succinct in an e-mail to SearchCIO.com.

"I'm as impotent as everyone else in how to deal with this problem on my end," he wrote.

SOX and the CIOs

With the Nov. 15 deadline creeping up for compliance with Section 404 of the federal law, SIM asked its survey pool about their investments in SOX compliance. In the billion-plus club, 43% are not spending a dime on SOX, 29% are spending less than 1% of their budget on it and 18% are investing 1%-5%.

The sub-billion revenue companies in the survey are spending even less. Nearly 70% aren't investing anything on SOX compliance, 18% are spending less than 1% of their budgets and 11% are directing between 1% and 5% to the SOX cause.

CIO Bob Denis is spending more to comply with SOX than he is to spear spam. His company, Trimble Navigation Ltd. in Sunnyvale, Calif., is public and does less than $1 billion in annual revenue.

"SOX compliance is huge for us -- it's certainly approaching the million-dollar mark," he said. "Given our size, we're spending an enormous amount of time and money on it."

For those CIOs who may be low-balling the costs of compliance, Denis has an ominous message.

"You've got something coming," he warned.

"We're hearing stories that even certain auditors are dropping clients because they're not putting enough effort into it. Get serious about it."

This story originally appeared on SearchCIO.com.

Tags: Sarbanes-Oxley ActVIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



RELATED CONTENT
Sarbanes-Oxley Act
SOX compliance burdens midmarket security teams
Ex-SEC chief Pitt decries state of Sarbanes-Oxley, risk management
Information security book excerpts and reviews
Internal audits for Sarbanes Oxley and internal IT support
Internal auditors and CISOs mitigate similar risks
Implement security and compliance in a risk management context
Does password sharing in international branches violate SOX?
Consensus Controls project aims to set benchmarks for compliance
Security visualization helps make log files work
The Little Black Book of Computer Security, 2nd Edition
Sarbanes-Oxley Act Research

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



More Tips to Secure Your Network
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts