Big4Guy

Welcome to Big4Guy.com. Big4Guy is an online resource where I will share with you the latest news, insights, knowledge and some experiences as a Big 4 consultant. We will discuss some of the important issues which organisations are facing today in the areas of information security, security and controls in SAP R/3, Oracle Applications, J.D.Edwards, Peoplesoft and various other ERP's. You will also find information on latest complaince regulations like Sarbanes Oxley, Basel II and so on. Big4guy will also attempt to provide valuable resources for individuals interested in examinations the CISA, CISM, CISSP, PMP and various other security certifications considered essential for entry in any Big 4 accounting, auditing and consulting firms. You are invited to post your comments and viewpoints to posts here. I sincerely hope this online journal will be useful to everyone from a budding student to a professional in the accounting, auditing, management and consultancy professions.

Post details: Section 404 Implementation IT Best Practices

12/22/05

Permalink 10:43:45 pm, Categories: Sarbanes Oxley, 251 words   English (US)

Section 404 Implementation IT Best Practices

In any 404 implementation, IT plays a crucial role. In the 404 implementations that I have been involved with, IT needs to be integrated into the process. It cannot be seperate. One of the major financial services company where I was providing consulting services for their 404 implemention, had created a special position under the CIO for improving IT controls. Such a part time or full time position indeed helps in building better internal controls in the company. Below, I am discussing some IT best practices that I have seen during Section 404 implementation.

Formalized Change Management Processes - Some of the best companies having a strong control environment have a formalized process for reviewing significant system changes. Triggers are built into the process which escalate the issues to upper management if some criteria is not met. Rigorous testing takes place before a system is put into production environment.

Automated IT Controls - Many companies are now using automated IT general controls. Access controls as well as application changes can now be tracked using online monitors. This can be possible using company wide vendor products. Application changes can now be controlled through change management software.

Common Business & IT control framework - Most companies I have been associated with have used COSO as the control framework for both business as well as IT processes. COBIT is also available but looks prmarily at the IT side of things. IT's better not to get involved with too many frameworks since it makes the job confusing and all the more difficult.

Comments:

No Comments for this post yet...

Official Websites

Search

Google

Web Big4Guy.com

January 2009
Mon Tue Wed Thu Fri Sat Sun
<<  <   >  >>
      1 2 3 4
5 6 7 8 9 10 11
12 13 14 15 16 17 18
19 20 21 22 23 24 25
26 27 28 29 30 31  

Misc

Syndicate this blog XML

What is RSS?