home
NEWS       BLOGS       FORUMS       NEWSLETTERS       RESEARCH       EVENTS       DIGITAL LIBRARY       CAREERS  
Network Computing Network Computing Powered by InformationWeek Business Technology Network

IMMERSE YOURSELF:

SOA

  |

Data Center

  |

802.11n

  |

Data Privacy

  |
APO  |

Virtualization

  |

NAC

  |

Security

  |

Network Mgmt

  |

Enterprise Apps

  |

Storage & Servers



The Business of IT
F E A T U R E  
Feds Reach Out and Touch IT

  July 10, 2003
  By Sean Doherty


>> continued from previous page

Sarbanes-Oxley
TOC Issue TOC
Printer Print full article
Printer Print this page
Printer Download as PDF
E-Mail E-Mail this URL
Discuss Discuss this article
flame author Flame the author
 
  In this article
arrow
Introduction
arrow
All in the Implementation
arrow
Gramm-Leach-Bliley
arrow
Whip Out the Crystal Ball
arrow
HIPAA
arrow
An Open Door Policy
arrow
Sarbanes-Oxley
arrow
Executive Summary
arrow
Law vs. Regulation
arrow
FYI
arrow
With 1386, California Leads the Way
arrow
Hospitals Get HIPAA
arrow
Web Links
arrow
Epoll Results

Following on the heels of the Enron and WorldCom debacles last year, legislators fired the first salvos to combat corporate fraud and abuse in securities with the passage of the Sarbanes-Oxley Act of 2002. This year, the SEC is finalizing regulations to implement Sarbox. Contrary to what you might read or hear in the news, the sky is not falling on IT. But it may fall on your corporate directors and officers unless you help.

In one sense, Sarbox is a knee-jerk response to corporate abuse. Among other things, it prohibits record tampering with the intent to impair a record's integrity or availability for use in official proceedings. It requires any accountant who conducts an audit of a public company to maintain his or her working papers for a period of seven years after the audit or review is completed. In addition, it mandates directors, officers and principal stockholders to publish beneficial ownership reports of equity securities issued to them by the company. Beyond the reflexive action, Sarbox makes clear that Congress wants some accountability in financial reporting that will involve information systems and IT.

Sarbox aims to protect investors and improve the accuracy of corporate disclosures (read: reporting) by issuers under the Securities and Exchange Act of 1934 (read: public companies). Section 404 requires that management teams of public companies establish and maintain adequate internal controls over their financial reporting systems. In addition, management must assess the effectiveness of these internal controls in their annual reports to the SEC. The company's auditor must also attest to and report on management's assessment of the effectiveness of their internal controls and procedures for financial reporting in accordance with standards established by the Public Company Accounting Oversight Board.


The PCAOB was established by the SEC (pursuant to Sarbox) to oversee the audit of public companies. The PCAOB's mission is to protect investors and secure the public interest in the preparation and publication of informative and accurate audit reports of public securities. The board registers public accounting firms, establishes rules and standards related to audit reports, and conducts investigations and disciplinary proceedings.



Sarbox in a Nutshell

click to enlarge

Defining internal controls over financial reporting will be the key to satisfying the requirements of Sarbox. These internal controls are largely in the realm of IT, where business processes meet software algorithms. Adequate controls will include processes designed or supervised by the company's principal executives and financial officers that provide reasonable assurances that financial reporting and preparation of financial statements are in accordance with generally accepted accounting principles. The controls include the policies and procedures to maintain accurate records that reflect the transactions and dispositions of assets; ensure that transactions are properly recorded and reported; and safeguard assets against unauthorized or improper use.

Sound familiar? Sarbox's controls are not unlike those in GLBA and HIPAA to safeguard data against unauthorized and improper use--except the SEC is squarely focused on corporate accountability in financial reporting. And blind faith in an IT financial reporting system will not be a good defense. The rules formally acknowledge corporate responsibility to create and maintain controls to identify and manage the risks that result in inaccurate data or fraudulent reporting.

The risks associated with accurate reporting are not far removed from the risks identified in industries governed by GLBA and HIPAA. IT security risks are nondiscriminatory and apply equally to banks, financial institutions and medical facilities as well as educational organizations, manufacturing and transportation.

Many IT shops look to a risk-assessment framework from the ISO 17799 standard; 17799 treats IT security as a business issue and covers all the familiar topics, such as system operation and maintenance, backup and restore, document handling and data integrity. Beyond that, many of the same solutions that satisfy GLBA and HIPAA--specifically, policy-management packages, log analyzers and change-control procedures--can apply to Sarbox to assert and monitor controls over financial reporting systems.

Many vendors are updating their products or announcing new ones aimed to comply with Sarbox. For example, Oracle and PricewaterhouseCoopers developed Internal Controls Manager, which works with Oracle's

E-business suite. And Plumtree Software, with HandySoft Corp., released Accelerator, which brings business-process software to Plumtree's portal to create and establish internal controls and reporting procedures while maintaining collaboration tools for corporate officers, directors and their auditors. These and other solutions will bring business processes in line with software logic and put them in plain view for investors' review.

Management also needs to assess the reliability of internal controls and disclose any material weakness in their financial reporting. If one or more weaknesses exist, management will not be able to conclude that the company's internal controls are effective, and this will affect the bottom line. Investors will be leery about supporting a public company without effective controls on its internal financial systems. This may require consultants and service organizations that can supply more than IT security solutions. Public companies can look to full-service consultants such as EDS, Greenwich Technology and PricewaterhouseCoopers for technology as well as financial and legal help. Other providers are vying for a growing market to advise and consult enterprises on IT and government regulations. An example is PeopleSoft's bid to acquire J.D. Edwards.

Sarbox will be remembered as the regulation that fights the good fight against corporate fraud and abuse. But for IT, Sarbox means Uncle Sam is demanding corporate accountability in financial reporting systems. If that does not happen, heads may roll. Anyone who falsely certifies that financial conditions and the results of operations are accurate while knowing that they do not reflect financial reality will be fined up to $1 million or imprisoned up to 10 years--or both.

But there is a rhyme to all the government's reasons for Sarbox. Investors will be more confident when reviewing financial reports and more willing to invest. Unfortunately for the public, the reporting requirements do not go into effect for most companies until April 15, 2005.

Sean Doherty is a technology editor and lawyer based at our Syracuse University Real-World Labs®. A former project manager and IT engineer at Syracuse University, he helped develop centrally supported applications and storage systems. Write to him at sdoherty@nwc.com.

Post a comment or question on this story.


start top  An Open Door Policy Executive Summary 





Ready to take that job and shove it?

Function:

Keyword(s):

State:
SPONSOR
RECENT JOB POSTINGS
CAREER NEWS
Go beyond Google and get vertical. These specialized search sites will help you find the business information you need -- fast.

Ari Balogh was named to the post of chief technology officer as the companys for a "realignment" of employees.










InformationWeek U.S. IT Salary Survey 2008
Salaries for business technology professionals are falling. Here's what you need to know in order to make good hiring decisions and personal career choices. Download Today
 
ROLLING RIGHT ALONG
Follow key Network Computing Reviews from conception to completion. This Week: Holistic APM.



Network Computing Reports Emerging Enterprise Podcast Series: Secrets to Success








TechSearch


Microsite of the Week


Powerful Information at Your Fingertips



InformationWeek Business Technology Network
InformationWeekInformationWeek 500InformationWeek 500 ConferenceInformationWeek AnalyticsInformationWeek CIO
InformationWeek EventsInformationWeek ReportsInformationWeek MagazinebMightyByte and SwitchDark Reading
Digital LibraryIntelligent EnterpriseInternet EvolutionNetwork ComputingNo JitterPlug Into The Cloud
space
Techweb Events Network
InteropVoiceConWeb 2.0 ExpoWeb 2.0 SummitEnterprise 2.0 ConferenceMobile Business ExpoSoftware ConferenceCSI - Computer Security Institute
Black HatGTECEnergy CampMashup CampStartup Camp
space
Light Reading Communications Network
Light ReadingLight Reading EuropeUnstrungLight Reading's Cable Digital NewsConstantinopleInternet EvolutionPyramid Research
Heavy ReadingLight Reading Live!Light Reading InsiderEthernet ExpoOptical ExpoTeleco TVTower Technology Summit
space
Financial Technology Network
Advanced TradingBank Systems & TechnologyInsurance & TechnologyWall Street & TechnologyAccelerating Wall StreetBank Systems & Technology Executive SummitBuyside Trading SummitInsurance & Technology Executive Summit
space
Microsoft Technology Network
MSDN MagazineTechNetThe Architecture Journal
space


App Infrastructure   |   Messaging & Collaboration   |   Network & Systems Mgmt   |   Network Infrastructure   |   Security  |   Storage & Servers   |   Wireless   |   Enterprise Apps
About Us  |  Contact Us  |  Site Map  |  Technology Marketing Solutions  |  Advertising Contacts  |   Briefing Centers
Copyright © 2009  United Business Media LLC  |  Privacy Statement  |  Terms of Service  |  Your California Privacy Rights