Our guide shows you how automation can create a sustainable control and reporting system – a must-have with mandated quarterly and annual assessments. If you've already prepared for, and experienced, your first Sarbanes-Oxley audit, you'll want to read this guide on sustainability.
Executive Overview ....................................................................................................................... 3 Sustaining Sarbanes-Oxley IT Internal Controls .................................................................................. 4 Sarbanes-Oxley Overview ............................................................................................................................... 4 Section 302: Corporate Responsibility for Financial Reports.......................................................................... 4 Section 404 -- Management Assessment of Internal Controls ......................................................................... 5 A Brief Review of Controls over IT Systems ....................................................................................... 6 Evaluating IT Relevance.................................................................................................................................. 6 Testing Internal Controls ................................................................................................................................. 7 Building a Sustainable Model for IT General Controls ........................................................................ 8 Change - The Nemesis of Sustainable Compliance......................................................................................... 8 From an IT general control perspective any change needs to be managed to maintain compliance. These changes include (but are not limited to):.......................................................................................................... 8 Change and Configuration Management ......................................................................................................... 9 IT General Controls Sustainability ................................................................................................................ 10 IT Controls and Automation .......................................................................................................................... 11 A Template for Sustainable IT General Controls........................................................................................... 11 Systems Security............................................................................................................................................ 13 Configuration Management ........................................................................................................................... 16 Operations...................................................................................................................................................... 17 Data Management .......................................................................................................................................... 18 Summary........................................................................................................................................................ 19
Practical Guide to Sarbanes-Oxley Internal Controls 2Executive Overview
Sarbanes-Oxley is the most comprehensive financial regulatory law in US history. It places responsibility for accurate and reliable corporate financial reporting in the hands of the CEO and CFO. It holds senior management specifically responsible for any and all shortcomings.
Senior managers are now responsible for the design, implementation, and internal assessment of internal controls for financial reporting. In today's world a significant part of those controls are embedded in the IT department.
The first (and much delayed) deadlines have come and gone. Despite the pain of meeting the deadline, many companies are now seeing the benefits of comprehensive internal examination of the processes, systems, and people involved in financial reporting systems.
Companies have now experienced what Sarbanes-Oxley means in terms of compliance. For most it was a time-consuming, intense exercise. The resources re... [download for more]