Home > Windows News > Preparing for a SOX audit
Windows News:
EMAIL THIS

Preparing for a SOX audit

By Jennifer Lawinski, News Writer
01 Mar 2005 | SearchWinIT.com

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   

Fourth in a series.

In a recent interview, Alex Bakman, CEO of Ecora Software Corp., in Portsmouth, N.H., offered his top five tips for IT administrators when preparing for a Sarbanes-Oxley (SOX) audit.

1. Select a set of controls -- and test repeatedly. The essence of the SOX audit is to prove that you do what you say you do. The Sarbanes-Oxley Act doesn't require people to have a specific set of IT controls, but whatever set of controls you pick, you need to demonstrate that you have a credible way of testing them.

For more information

Special report: Coming to terms with compliance

2. Develop a sound password policy. This involves establishing password duration and password aging policies and requiring complex passwords. Many organizations are guilty of allowing users to create obvious passwords, such as the name of a pet.

3. Review permissions. The first thing auditors do is go into "shares" to find out who has access to what. You should review shares with an eye toward whether such permissions are in line with documented policies.

4. Validate access control lists. Test credentials against critical line-of-business systems. Auditors will look to see if your lists for who should have access to an application really govern who has access.

5. Plug database holes. Review database management systems and be able to validate that from a DBMS-authorization perspective that there are no holes. A common problem that auditors look at involves how many production systems that are housing sensitive data are running with the full credentials.



Tags: Enterprise Infrastructure ManagementVIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
AutoRun  (SearchWinIT.com)
enterprise content management (ECM)  (SearchWinIT.com)
incident management (IcM)  (SearchWinIT.com)
problem management  (SearchWinIT.com)
Windows 7  (SearchWinIT.com)
Windows Server Update Services  (SearchWinIT.com)
x86  (SearchWinIT.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



Windows IT Solutions: SharePoint, Client Virtualization, Enterprise IT

Deep discounts with the latest notebook coupons from Notebook Review

HomeNewsTopicsITKnowledge ExchangeTipsAsk the ExpertsMultimediaWhite PapersIT Downloads
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 1999 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts