SOTEC Managed Services

Regulatory Compliance IT Managed Services

Sarbanes-Oxley

Key Provisions Affecting CIOs

The Sarbanes-Oxley Act of 2002, also known as the Public Company Accounting Reform and Investor Protection Act of 2002, is a United States federal law that set new or enhanced standards for all U.S. public company boards, management and public accounting firms.

Section 302: Certification of Financial Reports
Requirement SOTEC Remote Monitoring/Partner
  • CEO, CFO and an attesting public accounting firm must certify the accuracy of financial statements and disclosures in the periodic report.
  • Because IT systems generate periodic reports and control email, the primary tool for communicating information internally, CIOs must ensure host systems are secure and reliable.
  • CEO, CFO and an attesting public accounting firm must certify that the statements fairly present in all material aspects the operation and financial condition of the issuer.

SOTEC Remote Monitoring assists with the following:

Reliability:

  • System availability reports
  • System O/S reports
  • Network Utilization (NIC card)
  • Overall alerts/notification system
  • Exchange, Notes, Email application monitoring
  • Automatically reboot servers upon system or application failure

Security:

  • Vulnerability assessments
  • Firewall monitoring
  • Patch assessment
  • Material information used to generate periodic reports must be retained and made available to the public
  • Automatic archival of all reports for up to one year

Section 404: Certification of Internal Controls
Requirement SOTEC Remote Monitoring/Partner
  • Requires a statement of management's responsibility for establishing and maintaining adequate internal control over financial reporting for the company, attested to by the company's auditor
  • Includes an assessment of the controls and identification of the framework used for the assessment

Critical systems may include, but are not limited to:

  • Documentation/records management tool
  • Asset inventory
  • Layered security mechanisms to protect integrity of data
  • Reporting of material process changes every quarter
  • Process changes to meet compliance must be documented and implemented by the IS organization
  • Because the processes and internal controls are implemented principally in IT systems, section 404 audits involve a detailed assessment of those systems
  • Process used to generate statements must be accurate and meet the committee of sponsoring organizations of the Treadway Commission Standard
  • Enterprises must pass Section 302 & 404 audits before filing

Dell Remote Monitoring helps CIOs address the assessment, identification and documentation of internal controls:

  • Use Dell Remote Monitoring to take a quick "snapshot" and baseline network activity to establish what constitutes "normal" activity for comparison purposes
  • Asset report automatically discovers and documents resources across the IT infrastructure
  • Asset reports automatically identify all moves, adds, and changes
  • Notify on changes in access policies, changes in firewall configurations, router configurations, disk drive removals, and environmentals
  • Documentation of security controls: firewall logs, intrusion monitoring, vulnerability assessment, patch assessment, assurance that virus updates are current
  • Better differentiate between Denial of Service attacks and legitimate increases or spikes in network traffic
  • Aggregated firewall reports ensure firewall is in compliance with organization security policy
  • Archive up to one year's worth of history

Section 409: Material Event Reporting
Requirement SOTEC Remote Monitoring/Partner
  • Public companies must disclose information on material changes in their financial condition or operations on a rapid and current basis.
  • IT systems, as they support business operations and financial management, play a significant role in the detection and management of material events
  • Proactive use of IT solutions such as SOTEC Remote Monitoring enable earlier detection and mitigation of material events with multiple capabilities
  • Overall monitoring, alerting and notification system on network, system, application and security issues
  • Use of thresholds, severity and time-based alerts and escalations