Sarbanes-Oxley IT Compliance Using COBIT and Open Source Tools

Although Section 404 isn t very specific as to what needs to be done to comply with the Sarbanes-Oxley Act, it is very clear about what needs to be reported and attested.
In accordance with Section 404 Executive Management of a public company:
State the responsibility of management for establishing and maintaining an adequate internal control structure and procedures for financial reporting.
Contain an assessment, as of the end of the most recent fiscal year of the issuer, of the effectiveness of the internal control structure and procedures of the issuer for financial reporting.
It is the responsibility of the CEO and CFO to provide the attestment and sign off on the company s SEC filing. An understanding by the CFO, CIO, or IT Director of what compliance means and how best to comply will be crucial to the success or failure of the compliance efforts. In this chapter, we discuss the consequences of noncompliance and the benefits of compliance, and look at areas that have the potential to impede or facilitate your efforts to comply.
The following is an excerpt from an article published in the February 07, 2005 edition of Computerworld, titled IT role in Sarb-Ox problems is unclear :
Many clients of Meta Group Inc. were keeping their fingers crossed that the auditors weren t going to dig as deep in Year 1 around all of the IT areas, said John Van Decker, an analyst at the research firm in Stamford, Conn.
Van Decker expects that up...