Create an account Home  ·  Topics  ·  Downloads  ·  Your Account  ·  Submit News  ·  Top 10  
Modules
· Home
· Content
· Directory
· Downloads
· FAQ
· Forums
· Search
· Sox_Admin
· Statistics
· Submit News
· Surveys
· Top 10
· Your Account

Sarbox Compliance
The appropriately named Sarbanes-Oxley Compliance Toolkit includes a whole range of materials specifically put together to both introduce, and take you through this most important of legislation.

For detailed information see the toolkit's own website: Sarbanes-Oxley Compliance


SOX Act and Security
As security is such a major theme on the Act, many organizations are using the international ISO standards. The ISO 27001 Portal outlines these. A copy of the standards, and security policies, can be obtained via the ISO 17799 Toolkit.

The SOX email storage requirements can be fulfilled using the GFI MailArchiver


SOX Advertisers


Sarbanes What?
Our server logs indicate some interesting mis-spellings: Sarbannes Oxley, Sorbane Oxley, Sarbanne Oxley, Sarbaines Oxley, Sarbanesoxley, Sorbanes Oxley, Sabanes Oxley, Sarbane Oxley, and Sarbanes Oaxley, to name but a few!

Sarbanes-Oxley Act Forum: Forums

The Sarbanes Oxley Act :: View topic - Cobit maturity level for SOX compliance
 Forum FAQForum FAQ   SearchSearch   UsergroupsUsergroups   ProfileProfile   Login to check your private messagesLogin to check your private messages   LoginLogin 

Cobit maturity level for SOX compliance

 
Post new topic   Reply to topic    The Sarbanes Oxley Act Forum Index -> Control Methodologies
View previous topic :: View next topic  
Author Message
petrenko
Newbie
Newbie


Joined: May 18, 2006
Posts: 4

PostPosted: Thu May 18, 2006 4:19 am    Post subject: Cobit maturity level for SOX compliance Reply with quote

Hello, Colleagues!

Need your advice on Subject.

What maturity level of Cobit should we comply with to be compliant with SOX? References to source materials are welcome!

Thanks in advance.
Back to top
View users profile
harrywaldron
SoxGuru
SoxGuru


Joined: Jan 12, 2006
Posts: 849
Location: Roanoke, Virginia

PostPosted: Thu May 18, 2006 2:31 pm    Post subject: Reply with quote

Hi and welcome ... The following post has some key links in it for the COSO/COBIT standards:

http://www.sarbanes-oxley-forum.com/modules.php?name=Forums&file=viewtopic&p=5035#5035

Based on the quote below, it appears that the latest version 4.0 framework is recommended. If you're starting with a brand new adaptation of COBIT standards, it would be beneficial to use the latest and greatest icon_smile.gif However, if you're already using an existing earlier version of COBIT, I couldn't find references defining the minimum baseline for SOX compliancy.

Quote:
COBIT is an IT governance framework and supporting toolset that allows managers to bridge the gap between control requirements, technical issues and business risks. COBIT enables clear policy development and good practice for IT control throughout organizations. ITGI’s latest version— COBIT® 4.0—emphasizes regulatory compliance, helps organizations to increase the value attained from IT, enables alignment and simplifies implementation of the COBIT framework.

It does not invalidate work done based on earlier versions of COBIT but instead can be used to enhance work already done based upon those earlier versions. When major activities are planned for IT governance initiatives, or when an overhaul of the enterprise control framework is anticipated, it is recommended to start fresh with COBIT 4.0. COBIT 4.0 presents activities in a more streamlined and practical manner so continuous improvement in IT governance is easier than ever to achieve.
Back to top
View users profile Visit posters website
lekatis
SoxGuru
SoxGuru


Joined: Feb 15, 2005
Posts: 302
Location: USA

PostPosted: Thu May 18, 2006 3:05 pm    Post subject: Reply with quote

The absolute minimum is Maturity Level 3. Almost all external auditors are ok with it (no deficiency identified etc.)
_________________
George Lekatis
President of the Sarbanes Oxley Compliance Professionals Association (SOXCPA)
www.sarbanes-oxley-association.com
Back to top
View users profile Send email Visit posters website
harrywaldron
SoxGuru
SoxGuru


Joined: Jan 12, 2006
Posts: 849
Location: Roanoke, Virginia

PostPosted: Fri May 19, 2006 6:55 am    Post subject: Reply with quote

Thanks George for the clarification, as I couldn't find this documented
Back to top
View users profile Visit posters website


Display posts from previous:   
Post new topic   Reply to topic    The Sarbanes Oxley Act Forum Index -> Control Methodologies All times are GMT - 6 Hours
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
Forums ©

 
Trademarks referenced on the SOX Act Forum are property of their respective owners. Comments are property of their respective posters.
Sarbanes-Oxley Act Implementation Portal: Sarbanes Oxley compliance, information, software, & internal audit committee resources. Sarbox.
Site source is copyright nuke (c)2003, and is Free Software under the GNU / GPL licence agreement. All Rights Are Reserved.