Sarbanes-Oxley and the regulation of IT systems
In 2002 Sarbanes-Oxley (Sox) became law in the US. This requires a quite different and more rigorous form of company account with severe penalties for the chief executive who didn't comply, including prison sentences.Since all the data required to meet the auditing requirements would be in IT systems, the legislation has had a significant impact on IT management. In the UK and elsewhere it affects any company that has connection with the US, either thorough ownership, or having branches in the US.
Tasks
Introduce Sarbanes-Oxley, focussing on 404. Identify the issues it raised for IT management. Explain the impact of Sox on IT management, particularly on companies offering IT outsourcing.How did IT management respond? What is the value of CoBIT, ITIL and ISO20000 in responding to Sox? What is the process by which IT services should prepare to be Sox compliant?