![]() |
|
|
|
Registered
Join Date: May 2007
Location: Sapporo, Japan
Posts: 926
|
SOx - The Sarbanes-Oxley Act of 2002
I've just learned about this recently
![]() Can anybody tell me what kind of features in a software would be needed to fit these regulations? I've spent the past 3 days going through google and I just can't find something that makes it easier to understand. I get the concept of the Act (loool not that that one ![]() Maybe, I just should buy the book ... but I'm limited on time. hehe, thinking of building my own system ![]()
__________________
Carsten AKA Sapporo Guy ![]() 1982 SC -- US import it seems ... weeeeeeeeeeeeeeeeeeeee ![]() |
||
![]() |
|
Registered
|
This is something that is already flooded with products. Look at compliance software by Symantec, EMC, IBM, etc.
This has been a gravy train for the big companies for the last few years... There is also HIPPA, and Sunshine Laws (in Florida). Good luck!
__________________
tk 08 911 C2S - Sold 13 Audi A4 14 Jeep SRT 500HP |
||
![]() |
|
Slackerous Maximus
Join Date: Apr 2005
Location: Columbus, OH
Posts: 18,155
|
Let me sumarize the entire thing for you:
"Always ensure that documenation is documented in triplicate, and that as many unnesscary organizational roles as possible are created to ensure that data is not corrupted by management. If something does go wrong, managements a55 is going to get nailed. To ensure this does not happen, hire an expensive accounting company to deal with this, and get back to drinking whiskey."
__________________
2022 Royal Enfield Interceptor. 2012 Harley Davidson Road King 2014 Triumph Bonneville T100. 2014 Cayman S, PDK. Mercedes E350 family truckster. |
||
![]() |
|
Registered
Join Date: Jun 2003
Location: Calgary Alberta, CANADA
Posts: 2,113
|
Quote:
We're using Configuresoft (don't know if thats the vendor or the product name) and that seems to cover directory services, Unix, Windows, Oracle, Sybase and SQLServer. Other software we evaluated was N-Circle and two others that I can't remember. SOX Compliance can be really expensive... we had to use Guardium to audit database access, that alone is 1/4 million! Then you have to get PWC or Delloite -like audit firms. Once again is $,$ and $. Good luck!
__________________
We're all in the gutter,but some of us are looking at the stars. -Oscar Wilde |
||
![]() |
|
Formerly reformed
Join Date: Jan 2008
Location: Rutherfordton NC
Posts: 2,424
|
I know of two firms involved with SO. One was doing a great job of 'selling fear' based on SO; their software redacted metadata from electronic documents and apparently they were going around telling companies they'd be in violation of the act if they didn't have this type of software in use around the office. Another was using it to convince trucking companies to use cube based pricing rather than traditional methods.
I would suggest buying the book, but if it's anything like the voluminous tax code book we won't be hearing from you for a long, long time.
__________________
1968 911P (Paperweight) Last edited by 1968Cayman; 09-07-2008 at 06:37 PM.. |
||
![]() |
|
Registered
Join Date: Oct 2000
Location: agoura hills, ca 91301
Posts: 2,634
|
SOX:
1. A project that takes 1 hours will now take 2 days or more because of documentation. 2. Since it is all about documentation, it is the best time to be a consultant. |
||
![]() |
|
![]() |
Registered
Join Date: Jun 2001
Location: St. Louis Missouri
Posts: 1,454
|
I've done some work in the SOX field on the IT side in the past few years. SOX aka the "full employment for auditors" act.
The basic requirement for a publicly traded company is that they must know "for sure" that financial statements are accurate. I don't see this as a bad thing. If you have a system that ultimately feeds numbers to financial statements, you must ensure that the system data is appropriately protected. There was a lot of fear the first couple years and people went crazy, then things settled down a lot once the big 4 agreed on, imho, totally arbitrary levels of compliance. |
||
![]() |
|
Writer/Teacher
|
Big game for the Sox tomorrow - Tampa Bay is coming into town with only 1.5 games separating the two for the division lead...
__________________
Current Stable: Black 07 Porsche 987 Cayman S: Long-Tube Headers; FabSpeed Exhaust; VividRacing ECU Tune; IPD Plenum; 997GT3 Throttle Body. Blue 1983 Porsche 928S. 1985.5 Porsche 944 Rat Rod. 2011 Acura MDX. 2008 Mazda 3. Gone But Not Forgotten:Garnet Red 86 Porsche 951("The Purple Pig"). Alpine White 83 Porsche 944 ("Alpine Wolf"). Guards Red 84 Porsche 944. |
||
![]() |
|
Registered
Join Date: Apr 2001
Location: Linn County, Oregon
Posts: 48,493
|
Quote:
![]()
__________________
"Now, to put a water-cooled engine in the rear and to have a radiator in the front, that's not very intelligent." -Ferry Porsche (PANO, Oct. '73) (I, Paul D. have loved this quote since 1973. It will remain as long as I post here.) |
||
![]() |
|
Registered
|
Bingo!
__________________
Silver '88 RoW Carrera Grey '06 A4 Avant |
||
![]() |
|
Virginia Rocks!
Join Date: Oct 2003
Location: Just outside the beltway
Posts: 8,497
|
Tons of products out there and they only did part of the work. The easy part...low hanging fruit. The real work was in documenting all the stuff that didn't go through the software.
Happy to provide some advice, PM me if you'd like. Steve
__________________
Rosewood 1983 911 SC Targa | Black 1990 944 S2 | White 1980 BMW R65 | Past: Crystal 1986 944 na Guards Red is for the Unoriginal
|
||
![]() |
|
Super Moderator
|
Welcome to the Jungle!
I worked for a SOX software company for 2 years out of Cupertino. It's a rough game. We essentially helped facilitate the documentation. Keep in mind that this regulation generally applies to public companies, private companies do not need to worry, yet.
__________________
Chris ---------------------------------------------- 1996 993 RS Replica 2023 KTM 890 Adventure R 1971 Norton 750 Commando Alcon Brake Kits |
||
![]() |
|