Regulatory Compliance IT Managed Services
Sarbanes-Oxley
Key Provisions Affecting CIOs
The Sarbanes-Oxley Act of 2002, also known as the Public Company Accounting Reform and Investor Protection Act of 2002, is a United States federal law that set new or enhanced standards for all U.S. public company boards, management and public accounting firms.
Section 302: Certification of Financial Reports
| Requirement |
SOTEC Remote Monitoring/Partner |
- CEO, CFO and an attesting public accounting firm must certify the accuracy of financial statements and disclosures in the periodic report.
|
- Because IT systems generate periodic reports and control email, the primary tool for communicating information internally, CIOs must ensure host systems are secure and reliable.
|
- CEO, CFO and an attesting public accounting firm must certify that the statements fairly present in all material aspects the operation and financial condition of the issuer.
|
SOTEC Remote Monitoring assists with the following:
Reliability:
- System availability reports
- System O/S reports
- Network Utilization (NIC card)
- Overall alerts/notification system
- Exchange, Notes, Email application monitoring
- Automatically reboot servers upon system or application failure
Security:
- Vulnerability assessments
- Firewall monitoring
- Patch assessment
|
- Material information used to generate periodic reports must be retained and made available to the public
|
- Automatic archival of all reports for up to one year
|
Section 404: Certification of Internal Controls
| Requirement |
SOTEC Remote Monitoring/Partner |
- Requires a statement of management's responsibility for establishing and maintaining adequate internal control over financial reporting for the company, attested to by the company's auditor
- Includes an assessment of the controls and identification of the framework used for the assessment
|
Critical systems may include, but are not limited to:
- Documentation/records management tool
- Asset inventory
- Layered security mechanisms to protect integrity of data
|
- Reporting of material process changes every quarter
- Process changes to meet compliance must be documented and implemented by the IS organization
- Because the processes and internal controls are implemented principally in IT systems, section 404 audits involve a detailed assessment of those systems
- Process used to generate statements must be accurate and meet the committee of sponsoring organizations of the Treadway Commission Standard
- Enterprises must pass Section 302 & 404 audits before filing
|
Dell Remote Monitoring helps CIOs address the assessment, identification and documentation of internal controls:
- Use Dell Remote Monitoring to take a quick "snapshot" and baseline network activity to establish what constitutes "normal" activity for comparison purposes
- Asset report automatically discovers and documents resources across the IT infrastructure
- Asset reports automatically identify all moves, adds, and changes
- Notify on changes in access policies, changes in firewall configurations, router configurations, disk drive removals, and environmentals
- Documentation of security controls: firewall logs, intrusion monitoring, vulnerability assessment, patch assessment, assurance that virus updates are current
- Better differentiate between Denial of Service attacks and legitimate increases or spikes in network traffic
- Aggregated firewall reports ensure firewall is in compliance with organization security policy
- Archive up to one year's worth of history
|
Section 409: Material Event Reporting
| Requirement |
SOTEC Remote Monitoring/Partner |
- Public companies must disclose information on material changes in their financial condition or operations on a rapid and current basis.
|
- IT systems, as they support business operations and financial management, play a significant role in the detection and management of material events
- Proactive use of IT solutions such as SOTEC Remote Monitoring enable earlier detection and mitigation of material events with multiple capabilities
- Overall monitoring, alerting and notification system on network, system, application and security issues
- Use of thresholds, severity and time-based alerts and escalations
|