Sarbanes—Oxley and Enterprise Security: IT Governance — What It Takes to Get the Job Done

Q4 Social Sciences
William C. Brown, Frank Nasuti
{"title":"Sarbanes—Oxley and Enterprise Security: IT Governance — What It Takes to Get the Job Done","authors":"William C. Brown, Frank Nasuti","doi":"10.1201/1086.1065898X/45654.14.5.20051101/91010.4","DOIUrl":null,"url":null,"abstract":"Abstract Several sections of the Sarbanes— Oxley Act of 2002 (SOX) directly affect the governance of the information technology (IT) organization, including potential SOX certification by the chief information officer, Section 404 internal control assessments, “rapid and current” disclosures to the public of material changes, and authentic and immutable record retention. The Securities and Exchange Commission (SEC) requires publicly traded companies to comply with the Treadway Commission's Committee of Sponsoring Organizations (COSO) that defines enterprise risk and places security as a critical variable in enterprise risk assessment. Effective IT and security governance are examined in terms of SOX compliance. Motorola IT security governance demonstrates effective structures, processes, and communications; centralized security leaders participate with Motorola's Management Board to create an enabling security organization to sustain long-term change.","PeriodicalId":36738,"journal":{"name":"Journal of Information Systems Security","volume":"4 1","pages":"15 - 28"},"PeriodicalIF":0.0000,"publicationDate":"2005-08-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"44","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"Journal of Information Systems Security","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1201/1086.1065898X/45654.14.5.20051101/91010.4","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"Q4","JCRName":"Social Sciences","Score":null,"Total":0}
引用次数: 44

Abstract

Abstract Several sections of the Sarbanes— Oxley Act of 2002 (SOX) directly affect the governance of the information technology (IT) organization, including potential SOX certification by the chief information officer, Section 404 internal control assessments, “rapid and current” disclosures to the public of material changes, and authentic and immutable record retention. The Securities and Exchange Commission (SEC) requires publicly traded companies to comply with the Treadway Commission's Committee of Sponsoring Organizations (COSO) that defines enterprise risk and places security as a critical variable in enterprise risk assessment. Effective IT and security governance are examined in terms of SOX compliance. Motorola IT security governance demonstrates effective structures, processes, and communications; centralized security leaders participate with Motorola's Management Board to create an enabling security organization to sustain long-term change.
萨班斯-奥克斯利法案与企业安全:IT治理——如何完成工作
2002年《萨班斯-奥克斯利法案》(Sarbanes - Oxley Act of 2002,简称SOX)的若干条款直接影响信息技术(IT)组织的治理,包括首席信息官可能获得的SOX认证、第404条内部控制评估、向公众“快速和及时”披露重大变化,以及真实和不可变的记录保留。美国证券交易委员会(SEC)要求上市公司遵守特雷德韦委员会的赞助组织委员会(COSO),该委员会定义了企业风险,并将安全性作为企业风险评估的关键变量。根据SOX遵从性检查有效的IT和安全治理。摩托罗拉IT安全治理展示了有效的结构、流程和通信;集中的安全领导与摩托罗拉的管理委员会一起创建一个能够维持长期变化的安全组织。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
Journal of Information Systems Security
Journal of Information Systems Security Social Sciences-Safety Research
CiteScore
0.40
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术官方微信