Business Continity Plans 971
-
It had been my understanding that BCPs were required in the SOX Act. Was I mistaken or is it a liberal reading of the Act that requires it? If so, where is that written.
Thanks,
Andy
-
No actually, specifically excluded. However you do need to be able to re-create the financials in case of data loss, so you need backups etc.
This seems to me to be a weakness in the act, in view of the fact that it’s supposed to be about investor protection. You can invest in a company on Friday, it has a major incident over the weekend, and you’ve lost all your money on Monday because it had no BCP.
-
We have discussed the BCP challenges:
http://www.sarbanes-oxley-forum.com/modules.php?name=Forums-and-file=viewtopic-and-t=510