How To
Sarbanes, Oxley and You
Fiona Williams, who is responsible for Deloitte & Touche's security services practice for North America, answers readers' questions about the Sarbanes-Oxley Act.
Management should be the overall driver of the effort and require involvement from affected stakeholders. Audit should not define and implement the control environment but may be involved in monitoring activities. IT will be required to implement the automated aspects of internal controls.
Q: I have heard that SEC recommends COSO as an internal control integrated framework. In the case of physical systems securities, such as application security and local area network security, what risk assessment procedures should an IT department take to ensure that controls are in place?
A: COSO is the recommended internal control framework that companies will implement. It requires that a formal risk assessment be performed to evaluate the internal and external factors that impact an organization's performance. The results of the risk assessment will determine the controls that need to be implemented.
sarbanes-oxley
Security Directions: A Virtual Conference
Available On Demand Sept. 30 - Dec. 30
Join us for a virtual event with candid, expert information on top security challenges and issues - all from the comfort of your desktop.
Protecting PII: How to Work with IT to Manage Risk
Understand the critical nature of the test data privacy problem and get tips on how to work with IT to implement a test data privacy program.



