ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


Compliance Toolkit

Sarbanes-Oxley: What IT managers need to know

Staff

Published: 18 Jan 2005 11:30 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Getting help with control activities
A control activity is a term coined by the Committee of Sponsoring Organisations of the Treadway Commission (commonly known as COSO). The original examples of control activities are within the two volume set, Internal Control Integrated Framework. Internal Control Integrated Framework is available for purchase through the American Institute of Certified Public Accountants (www.aicpa.org), but the original publication is very light on IT-related material.

A number of more comprehensive resources for IT professionals are free to download. One favourite of professional auditors includes a two-volume publication called Standards for Business Controls. You can download that document here and find examples of objectives, risk and control activities. Volume II is strictly for IT processes and is mainframe-oriented due to its age. However, you can update the control objectives by referring to another white paper called IT Objectives for Sarbanes Oxley at www.ISACA.org.

Last but not least, you can borrow sample objectives from SysTrust. However, because these resources are not specific to a particular technology, you will need to heavily customise their sample test plans to fit your organisation.

Next

Previous

1 2 3 4


  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Did you find this article useful?
230 out of 464 people found this useful


Full Talkback thread

0 comments


Loading Video Player ....

Featured Talkback

There will be further activation issues to watch out for as Microsoft plans to offer a similar service to independent software vendors whereby they can "control" licensing through activation and other measures similar to the Software Protection Platform.

By: DefenceIT

Read full story:
Microsoft outage down to 'human error'

Sentry Posts Blog

Nasa and the virus

Yesterday the BBC ran a story about a computer virus making it into orbit, which I read with incredulity. OK, it's a nice silly season story on the surface, but what really got me was... More

1 comment

Customer data found on eBay server hig...

The recent news about customer details being retrieved from a server sold on eBay is yet another story about the sorry state of information security in the electronic age (see: http://news.zdnet.co.uk/...m).... More

Post a comment

Does it matter if you are an aardvark...

In spam terms, apparently it does. According to Cambridge University security expert Richard Clayton, if your email address is aardvark at animal.net, you are more likely to receive... More

1 comment