SOX Compliance Don’t fight what can help you. Skye L. Rogers  9 Years experience working in Systems & Operations in various roles.  4 years focusing.

Slides:



Advertisements
Similar presentations
VALUE OF INTERNAL AUDITING: ASSURANCE, INSIGHT, OBJECTIVITY A PRESENTATION TO STAKEHOLDERS ABOUT THE VALUE OF INTERNAL AUDITING.
Advertisements

Auditing, Assurance and Governance in Local Government
Sarbanes-Oxley Act of 2002 UAA – ACCT 316 – Fall 2003 Accounting Information Systems Dr. Fred Barbee.
Chapter 7 Control and AIS Copyright © 2012 Pearson Education, Inc. publishing as Prentice Hall 7-1.
Core principles in the ASX CGC document. Which one do you think is the most important and least important? Presented by Casey Chan Ethics Governance &
Forces of Change Don H. Hansen Health Care Services Partner
Sodexo.com Group Internal Audit. page 2 helps an organization accomplish its objectives by bringing a systematic, disciplined approach to evaluate and.
Chapter Twelve Financial Reporting and the Securities and Exchange Commission Copyright © 2015 McGraw-Hill Education. All rights reserved. No reproduction.
Security and Personnel
Sarbanes-Oxley Act. 2 What Is It? Act passed by Congress in response to the recent and continuing corporate scandals. Signed into law July 30, Established.
Fraud and SOX Compliance McGraw-Hill/Irwin Copyright © 2012 by The McGraw-Hill Companies, Inc. All rights reserved.
Chapter © 2009 Pearson Education, Inc. Publishing as Prentice Hall.
Sarbanes Oxley Act. WHY? Public Company Accounting Reform and Investor Protection Act of 2002 Response to a number of major corporate and accounting scandals.
Chapter © 2009 Pearson Education, Inc. Publishing as Prentice Hall.
Chapter 29 Ethics in Accounting
Security Controls – What Works
WELCOME Annual Meeting & Compliance Seminar. Code of Conduct - Impact on Corporate Culture by Andy Greenstein Knight Capital Group, Inc.
Adam Bearhalter Kristy Kelly Julie Bland Alex Tiset.
Current Information Technology Issues Norbert Mika NJ Mika Consulting Inc.
Chapter 7 Control and AIS Copyright © 2012 Pearson Education, Inc. publishing as Prentice Hall 7-1.
1 Sarbanes-Oxley IT Audits. 2 Sarbanes-Oxley 2002 Recommended “audit firms place a high priority on enhancing the overall effectiveness of auditors’ work.
ITS Offsite Workshop 2002 PolyU IT Security Policy PolyU IT/Computer Systems Security Policy (SSP) By Ken Chung Senior Computing Officer Information Technology.
Sarbanes Oxley Act. WHY? Public Company Accounting Reform and Investor Protection Act of 2002 Public Company Accounting Reform and Investor Protection.
Sarbanes-Oxley Act a.k.a. “SOX”
ECM Project Roles and Responsibilities
Chapter 4 IDENTIFYING RISKS AND CONTROLS IN BUSINESS PROCESSES.
Chapter 11.  The board is ultimately responsible for risk management  Oversee strategic risks, operational risks, and financial risks  Many federal.
Chapter 7 Database Auditing Models
Emerging Latino Communities Initiative Webinar Series 2011 June 22, 2011 Presenter: Janet Hernandez, Capacity-Building Coordinator.
Spreadsheet Management. Sarbanes-Oxley Act (SOX, 2002) Requires “an effective system of internal control” for financial reporting in publicly- held companies.
 Corporate governance is based on three interrelated components: corporate governance principles, functions and mechanisms.
Internal Auditing and Outsourcing
Chapter 7 Corporate Governance.
IT Control Objectives for Sarbanes-Oxley
HROFFICE USER CONFERENCE 2005 Creating an Effective Ethics and Compliance Program Ascentis User Group September, 2005.
CORPORATE COMPLIANCE Tim Timmons Vice President Compliance and Regulatory Services Health Future, LLC.
Vijay V Vijayakumar.  SOX Act  Difference between IT Management and IT Governance  Internal Controls  Frameworks for Implementing SOX  COSO - Committee.
Implementation Issues of Sarbanes-Oxley CASE Presentation September 23, 2004 By Denise Farnan.
Chapter 5 Internal Control over Financial Reporting
Sarbanes Oxley Act (2002) A brief summary. What is Sarbanes-Oxley? Legislation intended to restore the public’s confidence in investing and the securities.
© 2013 Cengage Learning. All Rights Reserved. 1 Part Four: Implementing Business Ethics in a Global Economy Chapter 9: Managing and Controlling Ethics.
Implementing and Auditing Ethics Programs
Important acronyms AO = authorizing official ISO = information system owner CA = certification agent.
Scandals (in the public and private sector)  Enron  Worldcom  Livent  Nortel  HRDC  Sponsorship Scandal.
Corporate Responsibility and Compliance After Enron and Sarbanes-Oxley 6th National Congress on Health Care Compliance February 2003 John Bentivoglio
1 Today’s Presentation Sarbanes Oxley and Financial Reporting An NSTAR Perspective.
Policy Review (Top-Down Methodology) Lesson 7. Policies From the Peltier Text, p. 81 “The cornerstones of effective information security programs are.
Sarbanes Oxley Act. The Sarbanes Oxley Act consists of 11 Sections I – Public Company Accounting Oversight Board II – Auditor independence III – Corporate.
Auditing Information Systems (AIS)
TWO FIELDS…ONE JOB: THE RELATIONSHIP BETWEEN ACCOUNTING AND IT By: Jodi L. Benson July 2005.
1 A Common Sense Look at Sarbanes-Oxley Presentation to the MIT Auditing Committee of the Corporation June 8, 2003.
Private & Confidential1 (SIA) 13 Enterprise Risk Management The Standard should be read in the conjunction with the "Preface to the Standards on Internal.
Database Security and Auditing: Protecting Data Integrity and Accessibility Chapter 7 Database Auditing Models.
Information Security Governance and Risk Chapter 2 Part 3 Pages 100 to 141.
LeToia Crozier, Esq., CHC Vice President, Compliance & Regulatory Affairs Corey Wilson Director of Technical Services & Security Officer Interactive Think.
Disaster Recover Planning & Federal Information Systems Management Act Requirements December 2007 Central Maryland ISACA Chapter.
© The McGraw-Hill Companies, Inc., 2008 McGraw-Hill/Irwin Principles of Accounting (Accounting 1 for BBA - Undergraduate) SBS Victor Yerris, PhD
Sarbanes-Oxley (SOX) John H. Messing, Esq. Law-on-Line,Inc. Providing 3 E’s -- E-Security, Encryption, E-Signatures 3900 E. Broadway Blvd., Suite 201 Tucson,
Casualty Loss Reserve Seminar General Session II September 9, 2003 Section 302/404 of Sarbanes-Oxley Act What Actuaries Need to Know Jan A. Lommele, FCAS,
A Guide for Management. Overview Benefits of entity-level controls Nature of entity-level controls Types of entity-level controls, control objectives,
Accounting and Information Systems: a powerful combination.
Sarbanes-Oxley Act a.k.a. “SOX” Georgia CTAE Resource Network Curriculum Office, February 2009 To accompany curriculum for the Georgia Peach State Career.
HIPAA Compliance Case Study: Establishing and Implementing a Program to Audit HIPAA Compliance Drew Hunt Network Security Analyst Valley Medical Center.
F8: Audit and Assurance. 2 Audit and Assurance Designed to give you knowledge and application of: Section A: Audit Framework and Regulation Section B:
Important acronyms AO = authorizing official ISO = information system owner CA = certification agent.
1 Vereniging van Compliance Officers The Compliance Function in Banks Amsterdam, 10 June 2004 Marc Pickeur CBFA CBFA.
Lecture 5 Control and AIS Copyright © 2012 Pearson Education 7-1.
Business Continuity Planning 101
Overview of Tampa Electric’s Compliance Program APPA Reliability Standards and Compliance Program January 10, 2007.
Presentation transcript:

SOX Compliance Don’t fight what can help you

Skye L. Rogers  9 Years experience working in Systems & Operations in various roles.  4 years focusing on SOX related tasks.  Currently working with TransCore.  Skye is not an attorney or an auditor.

TransCore  Approaching 70 years in the transportation industry  Installations and products in 46 countries around the world  Key technologies: RFID, wireless communications, GPS, web-based information systems Fleet Management Operations Management Rail-Intermodal Track and Trace Financial Services Freight Matching Compliance Services

What is SOX?  SOX provides the foundation for new corporate governance rules, regulations & standards issued by the Securities and Exchange Commission. It covers a range of topics from criminal penalties to Corporate Board responsibilities. SOX also covers issues such as independent auditing requirements, corporate governance, internal control assessment, and enhanced financial disclosure.  CEO’s of publicly traded companies will be held accountable for the quality of the controls established which enable accurate Financial reporting (including IT processes, systems & roles).

Penalties  Section 802(a) of the SOX states: “ Whoever knowingly alters, destroys, mutilates, conceals, covers up, falsifies, or makes a false entry in any record, document, or tangible object with the intent to impede, obstruct, or influence the investigation or proper administration of any matter within the jurisdiction of any department or agency of the United States or any case filed under title 11, or in relation to or contemplation of any such matter or case, shall be fined under this title, imprisoned not more than 20 years, or both.”

What prompted SOX?  Sarbanes-Oxley was passed in the wake of a number of notable corporate accounting scandals including Enron and WorldCom.

SOX on the horizon?  The primary thing to remember is that SOX is about mitigating the risk of fraud, financial transparency and process control. This will change how you do things but that does not have to be a bad thing.

A hint on policies.  Bear in mind that you will be held to the letter of all policies your company develops related to SOX even if they exceed federal requirements. This is very important to remember when drafting policies.  Policies should ensure that corporate behavior is consistent, controlled, and can be proven.

A word on Frameworks There are many frameworks out there to assist you with SOX compliance. The key is to find a framework that works for your team, commit to it, train on it, and use it to your best possible advantage.

Examples of COBIT Controls  Network Security – Firewalls, secure network configuration including x  Virus Protection –anti- virus and anti-spyware updated regularly

Examples of COBIT Controls  Backups & Restore – Regularly tested procedures  IT Continuity – Disaster Recovery Procedures

Examples of COBIT Controls  Files Access Privilege Controls  Identity Management – password strength/age and access. Who has access and is that appropriate now?

Examples of COBIT Controls  Risk Evaluation Programs – Risk Assessment and internal auditing.  Employee IT Security Training – Training of end users related to utilization of resources.

Examples of COBIT Controls  Management support/buy in – Executive level oversight of projects related to IT.  IT as part of strategic planning – The business must be supported by technologies.

Change Management (Skye’s favorite) Standardized change control is a great place to find fast rewards in pursuit of compliance.  Change Approval  Change Categorization  Change Documentation  Change Prioritization  Formal Request for Change Process  A body of subject matter experts that oversee change.

Consistent Logging  Change Management  Configuration Mgmt.  Event Management  Incident Management  Knowledge Mgmt.  Problem Management

“Operationalize” information.  Connect the internal changes needed with the strategic objectives of the company.  Illustrate that real-time information flow enhances your organization’s ability to make decisions while making compliance easier.  Point out the significance of new activities that may seem mundane or inconsequential. This will help actions taken by staff at every level feel more relevant and less painful.

Remember W. Edward Deming? SOX Compliance is not a fix it and forget it endeavor. As companies and the ecosystems that support them change new compliance quandaries will come up.

Wait, how can SOX help me?  Perspectives on operational control, consistency, and quality take on a whole different meaning once they have a clear relationship to fiduciary responsibility.  It is amazing how different the conversation about project prioritization becomes once executive management are offered the opportunity to make decisions guiding it.

Questions? This is assuming that we have time for any.

FIN Thank you very much for your kind attention.