Email Archive requirements 2620
-
I was wondering if there is any stipulation where a bank or credit union, MUST archive all email in an unaltered state for discovery and disclosure as well as compliance. I am new to SOX and I provide IT solutions. I just want to get up to speed on what discussions I need to have with customers as their trusted advisor.
-
I think I didn’t search this topic…
http://www.sarbanes-oxley-forum.com/modules.php?name=Forums-and-file=viewtopic-and-t=2037-and-highlight=retention
-
Hi and welcome to the forums
… Yes, there is indeed a wealth of information available through the forum SEARCH facilities which I use often. Please feel free to post any additional questions as there are a number of subject matter experts in the forums.
Below are two resources shared into another post that might be helpful in meeting SOX 404 requirements for financial automated systems.
As COBIT is used by many external SAS auditors to provide guidelines for controlling automated financial systems, this resource may be helpful to research IT needs:
Free COBIT 4.x PDF copy by registering with ISACA
http://www.sarbanes-oxley-forum.com/modules.php?name=Forums-and-file=viewtopic-and-t=1920
Also, COSO provides excellent guidance in the general design of financial and workflow controls as noted here:
COSO Guidance - Monitoring
http://www.sarbanes-oxley-forum.com/modules.php?name=Forums-and-file=viewtopic-and-t=2470