Sarbanes Oxley Compliance Sarbanes-Oxley Compliance Kit

Mandated regulations impact IT

Security White Paper

The audit spotlight now shines on IT. After years of regulation and embarrassing data breaches, the highest levels of management now comfortably discuss IT controls and audit results. However, their quality expectations are rising. Where IT once performed audits annually, many now support quarterly, monthly, and ad hoc exercises. Each audit expands the scope of the technologies assessed, measured, and proven compliant. Broader scope means more complexity and more work. With the Sarbanes Oxley Compliance Kit you can increase timeliness and accuracy of audit data while reducing IT audit effort, disruption, and cost.

Order SOX compliance kitDownload Table of Contents
Sarbanes-Oxley Section 404 requires that:

  • Enterprises have an enterprise wide security policy;
  • Enterprises have enterprise wide classification of data for security, risk, and business impact;
  • Enterprises have security related standards and procedures;
  • Enterprises have formal security based documentation, auditing, and testing in place;
  • Enterprise enforce separation of duties; and
  • Enterprises have policies and procedures in place for Change Management, Help Desk, Service Requests, and changes to applications, policies, and procedures.

SOX adopted the COSO model of controls, which is the same model that SAS 70 audits have utilized since inception. SOX heightened the focus placed on understanding the controls over financial reporting and identified a type II SAS 70 report as the only acceptable method of obtaining third-party assurance regarding the controls at a service organization. Security "certifications" are excluded as acceptable substitutes for a type II SAS 70 audit report.

In addition the ISO 27000 standard is used in SAS 70 reports. The Security Manual Template contains an ISO 27000 Security Process Audit Checklist. These two items directly address a service organization's descriptions of controls. The auditor can use these to help them in the evaluation of the service organization's control framework.

Preparation for Disaster Recovery / Business continuation in light of SOX has two primary parts. The first is putting systems in place to completely protect all financial and other data required to meet the reporting regulations and to archive the data to meet future requests for clarification of those reports. The second is to clearly and expressly document all these procedures so that in the event of a SOX audit, the auditors clearly see that the DR plan exists and will appropriately protect the data.

To meet these needs the Sarbanes Oxley Compliance Resource Kit, which comes in four editions (Standard, Silver, Gold, and Platinum) contains:

  • Security Policies (all editions);
  • Threat & Vulnerability Assessment Tool (all editions);
  • Business & IT Impact Questionnaire Risk Assessment Tool (all editions);
  • Safety Program Template (all editions);
  • Disaster Recovery Template (all editions);
  • Outsourcing guide update to reflect what you vendors need to do (all editions);
  • Internet and IT Job Descriptions (Silver, Gold, and Platinum Editions) and;
  • IT Service Management Template (Platinum Edition) includes
    • Service Request Policy and Standard
    • Help Desk Policy, Procedure, Standard, and Service Level Agreement
    • Change Control Standard, Quality Assurance Standard, and Management Workbook
    • Documentation Standard
    • Version Control Policy and Standard
    • Sensitive Information Standard
    • Blog and Personal Web Site Policy
    • Travel and Off-Site Meetings Security Policy
    • Internet, e-mail and electronic communication Policy

See Table Below for a summary of the contents of each of the versions of the Sarbanes-Oxley Compliance kit

Order SOX compliance kitDownload Table of Contents

Sarbanes-Oxley Compliance Resource Kit - StandardOrder SOX Compliance KIt

  • Sarbanes-Oxley Compliance Summary
  • Security Manual Template
  • Sensitive Information Policy Template
  • Disaster Recover - Business Continuity Template
  • Safety Manual Template
  • Threat & Vulnerability Assessment Tool
  • Business & IT Impact Questionnaire
  • Practical Guide for IT Outsourcing Template
  • Job Description for Chief Security Officer (CSO)

Update Service is avaiilable

Sarbanes-Oxley Compliance Resource Kit - SilverOrder SOX Compliance KIt

  • Sarbanes-Oxley Compliance Summary
  • Security Manual Template
  • Sensitive Information Policy Template
  • Disaster Recover - Business Continuity Template
  • Safety Manual Template
  • Threat & Vulnerability Assessment Tool
  • Business & IT Impact Questionnaire
  • Practical Guide for IT Outsourcing Template
  • Job Description for Chief Security Officer (CSO)
  • Internet and IT Job Descriptions HandiGuide PDF format

Update Service is avaiilable

Sarbanes-Oxley Compliance Resource Kit - GoldOrder SOX Compliance KIt

  • Sarbanes-Oxley Compliance Summary
  • Security Manual Template
  • Sensitive Information Policy Template
  • Disaster Recover - Business Continuity Template
  • Safety Manual Template
  • Threat & Vulnerability Assessment Tool
  • Business & IT Impact Questionnaire
  • Practical Guide for IT Outsourcing Template
  • Job Description for Chief Security Officer (CSO)
  • Internet and IT Job Descriptions HandiGuide PDF format
  • Internet and IT Job Description - 260 individual Microsoft WORD files

Update Service is avaiilable

Sarbanes-Oxley Compliance Resource Kit - PlatinumOrder SOX Compliance KIt

  • Sarbanes-Oxley Compliance Summary
  • Security Manual Template
  • Sensitive Information Policy Template
  • Disaster Recover - Business Continuity Template
  • Safety Manual Template
  • Threat & Vulnerability Assessment Tool
  • Business & IT Impact Questionnaire
  • Practical Guide for IT Outsourcing Template
  • Job Description for Chief Security Officer (CSO)
  • Internet and IT Job Descriptions HandiGuide PDF format
  • Internet and IT Job Description - 281 individual Microsoft WORD files
  • IT Service Management Template

Update Service is avaiilable

COBITOrder SOX Compliance KIt

COBIT Compliance Toolkit contains all of the tools that are needed to meet the COBIT requirements.

COBIT 4.1 is an IT governance framework and supporting toolset that allows managers to bridge the gap between control requirements, technical issues and business risks. COBIT enables clear policy development and good practice for IT control throughout organizations. COBIT emphasizes regulatory compliance, helps organizations to increase the value attained from IT, enables alignment and simplifies implementation of the enterprises' IT governance and control framework.

The kit includes:

  • Compliance Management White Paper -- R-00201
  • Record Management Retention and Destruction Policy -- R-00188
  • IT Infrastructure, Strategy, and Charter Template -- R-00156
  • Disaster Recovery Business Continuity Template -- P-SP010
  • Practical Guide for IT Outsourcing -- P-SP121
  • Service Level Agreement Policy Template with Sample Metrics -- P-00872
  • Metrics for the Internet, Information Technology, and Service Management -- P-SP008
  • IT Service Management (ITSM) Service Oriented Architecture (SOA) -- R-00108
  • Internet and Information Technology Position Descriptions HandiGuide -- P-00880
  • Security Policies and Procedures -- P-SP111
  • Security Audit Program -- R-00182
  • Business and IT Impact Questionnaire -- P-SP119
  • IT Salary Survey -- R-00554

 

Order SOX compliance kitDownload Table of Contents