INFORMATION ASSURANCE: SARBANES OXLEY EDITION BECAUSE IT’S NOT WORTH MILLIONS IN FINES AND 10- 20 YEARS IN JAIL
THE PROBLEM • Public companies are forced to follow SOX and many I.T. departments don’t know how to build a SOX infrastructure. • Executives are subject to imprisonment up to 20 years with the company suffering millions in losses if not followed correctly.
PROPOSAL • Bring to light requirements • Display severity of consequences • Give an overview of a SOX compliant infrastructure • Show how it can be done
THE APPROACH • Review current controls if any are in place • Record retention policies • Backup Policies • User Account Tracking Policies • ERP and Production • Reporting / Notifications • Approval Tracking • Using Helpdesk • Financial Reporting • SOX Compliant Companies • Contract a Mock Audit
RECORD RETENTION • Check with Legal Department • Network and Database Activity • Internal Controls • Login Attempts • Account and User Activity • Information Access
USER ACCOUNT TRACKING • Windows Active Directory / Production Users • ERP System Users • ERP Privilege Review • Reporting and Notifications
APPROVAL TRACKING • Most I.T. departments have a helpdesk already • Approvals can be implemented into an already existing ticket for clean searching and archiving • Build Your Workflows
SOUND FINANCIAL REPORTING • Look for companies with a good track record • Inspect their certifications • Meet with them
DON’T SET YOURSELF UP FOR FAILURE • Don’t Rush! • If it seems easy or you’re convincing yourself you’ll come back to it, stop and do it right the first time
Recommend
More recommend