Compliance

You are here: silicon.com > Research > Special Reports > Compliance

Compliance

SOX compliance diverts funding from IT security

Companies in danger of ignoring other risks...

By Steve Ranger

Published: 11 July 2005 16:27 BST

The multi-million pound cost of complying with the Sarbanes-Oxley Act (SOX) is diverting spending away from protecting against other security threats.

International security association the Information Security Forum (ISF) calculates that many of its members expect to spend more than $10m on information security controls for Sarbanes-Oxley.

ISF consultant Andy Jones said that although SOX was designed to improve corporate governance and accountability, it has proved difficult to interpret for information security professionals.

"As neither the legislation nor the official guidance specifically mentions the words 'information security', the impact on security policy and the security controls that need to be put into place must be determined by each individual organisation in the context of their business," he said.

The ISF warns that SOX ignores security issues that are extremely important when dealing with risks to information, such as business continuity and disaster recovery. This makes it important to integrate compliance into a wider IT security and corporate governance strategy, it said.

Jones also warned that SOX could divert attention from more pressing security risks: "For organisations whose business is not primarily financial, for example manufacturing or product-service industries, the diversion of information security attention from other risk areas to SOX compliance may lead to important business risks being neglected."

"It is important that Sarbanes-Oxley does not push organisations into following a compliance-based approach rather than a risk-based approach that may compromise information security," he added.

UK members of the ISF include Abbey National, Alliance & Leicester and AstraZeneca.

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure
Compliance News

Decision on Microsoft antitrust fine to take "weeks"
€2m-per-day penalty on hold

Are compliance headaches only just beginning?
Financial services IT managers, get ready...

Gartner: SOX is boosting IT spend
'Budgets to increase by 10 to 15 per cent next year'

CIO Agenda, part 1: The 2006 IT shopping list
IT governance and compliance steal security's top spot

IT the key to cutting SOX costs
The compliance work isn't over yet...

Compliance Extra

Stories from around the web...

Relief from Sarbanes-Oxley on the way? CNET News.com

Chief risk officer: A valuable addition to the C-suite Globe and Mail

IT complexity confounds financial sector compliance Accounting and Finance 365 - registration required

The secret to success LegalWeek

Sarbox: The appliance of compliance Accountancy Age

RELATED RESEARCH

Make your voice heard

silicon.com and the Bathwick Group have created an opportunity for business and IT executives to share their experience with each other and thus enhance their knowledge of the IT marketplace.

Join our research panel, and you'll be asked to participate in short surveys - and then will be privy to the answers of all your colleagues, as we send you tailored versions of the results.

For more about the Research Panel and how to join, click here



Quick Sitemap Links: