Docsity
Docsity

Prepare for your exams
Prepare for your exams

Study with the several resources on Docsity


Earn points to download
Earn points to download

Earn points by helping other students or get them with a premium plan


Guidelines and tips
Guidelines and tips

Sarbanes-Oxley Act: Key Provisions and IT Implications, Slides of Business Management and Analysis

The sarbanes-oxley act (sox) is a us law enacted in 2002 to improve corporate governance and financial transparency. An overview of sox titles, key provisions, and it implications. Sox sections 302 and 404 focus on internal control certifications and assessments, respectively. It systems play a crucial role in financial reporting and require adequate controls. Frameworks like coso and cobit are used for sox compliance, with cobit being more it-focused. Key controls include database triggers, email systems, and it audits. General controls cover security policies, change management, and administration of duties/rights. Separation of duties, least privilege, and user provisioning are essential principles. If these principles are not in place, the it system may fail sox compliance, requiring remediation.

Typology: Slides

2011/2012

Uploaded on 12/20/2012

devashish
devashish 🇮🇳

4.3

(24)

116 documents

1 / 15

Toggle sidebar

Related documents


Partial preview of the text

Download Sarbanes-Oxley Act: Key Provisions and IT Implications and more Slides Business Management and Analysis in PDF only on Docsity! IT and Sarbanes-Oxley Docsity.com Introduction • Corporate & Accounting Scandals • Public confidence • Signed in July 30, 2002 • Reach Docsity.com SOX Section 404 • Management must report on the effectiveness of the company's internal controls over financial reporting. – A statement of management's responsibility over internal controls – Management's assessment of the effectiveness of the company's internal control – Identify the framework used to evaluate controls – State that their auditor has reported on their internal controls as well Docsity.com SOX Section 404 • In today’s business environment IT systems initiate, process, and report most financial transactions • Because they are so involved in the day to day financial transactions, the IT systems become key to financial reporting • Making the controls over the IT systems key to financial reporting as well Docsity.com SOX Section 404 • Management is required to implement an internal control framework. • COSO is most widely used framework for SOX compliance – Pays little attention to IT controls • COBIT is one of the better known frameworks that relate to IT controls Docsity.com Administration of Duties/Rights • Separation of Duties – Individual Permissions Roles • Least Privilege – Individual only given privileges needed to do their job • User Provisioning – New users set up with correct privileges – Standard profile for each user Docsity.com What if these 3 principles are not in place? The IT system has failed to meet SOX Compliance The Auditor must: • Note the exception • Flag it up to Management for remediation Docsity.com Strategies for Sarbanes-Oxley Compliance • Understand SOX requirements • Set aside sufficient resources • Get everyone involved • Create independent audit committee • Educate everyone • Evaluate auditors • Make required changes • Prepare for the future Docsity.com
Docsity logo



Copyright © 2024 Ladybird Srl - Via Leonardo da Vinci 16, 10126, Torino, Italy - VAT 10816460017 - All rights reserved