Sarbanes-Oxley IT Compliance Using Open Source Tools, Second Edition

"Corporate IT professionals lack a critical understanding of risk and compliance issues and pose a barrier to collaborating on compliance initiatives with audit and compliance professionals, based on a study by the Ponemon Institute."
Robert Westervelt Excerpt from ComputerWeekly.com article published August 9, 2007
In case the intent of the above quote is not self evident, for our discussion it refers to the fact that IT's ability to understand compliance and compliance issues will be critical to the success of compliance. In chapter 3, we discussed that on May 24, 2007, the PCAOB adopted Auditing Standard No. 5, to replace Auditing Standard No. 2, and some of the benefits of this change. What we did not discuss however was why this is probably the most significant motivating factor for the new standard and one of the most significant changes as it relates to guidance for management. Over the last five years or so Sarbanes-Oxley has proven to be a financial drain on companies, not only small but large companies as well. For this reason the SEC working with the PCAOB developed the new audit standard AS5. In developing the new standard the SEC and the PCAOB determined that small companies should have leeway to use discretion in tailoring an evaluation that takes into account their individual circumstances. The following is an excerpt from Christopher Cox testimony before the Committee on Small Business, U.S. House of Representatives, on June 5, 2007.
"We expect the unduly high costs of...