THE MAGAZINE

IT Security Requirements of Sarbanes-Oxley

By Peter Piazza

Section 404 of the Sarbanes-Oxley Act requires companies to include in their annual reports a report of management of the company's internal control over financial reporting. How IT risks and controls are affected is explained in a Q&A format in a new publication from risk-consulting company Protiviti. The 32-page guide describes an overall approach to IT risk and control considerations, from identifying and prioritizing IT tasks to understanding how outsourcing any part of the IT function might affect reporting. It divides the subject into nine sections, including documentation, testing, IT control considerations in relation to business processes, and addressing deficiencies.

@ Link to the Protiviti paper, Guide to the Sarbanes-Oxley Act: IT Risks and Controls, through SM Online.

AttachmentSize
Protiviti_Sarbanes0604.pdf525.54 KB

Comments

 

The Magazine — Past Issues

 

ASIS 2012 Seminar