Re: SOX Reporting Requirement

  • From: Jared Still <jkstill@xxxxxxxxx>
  • To: Frits Hoogland <frits.hoogland@xxxxxxxxx>
  • Date: Thu, 4 Sep 2014 08:23:17 -0700

On Thu, Aug 28, 2014 at 10:40 AM, Frits Hoogland <frits.hoogland@xxxxxxxxx>
wrote:

> If you actually look at what is in SOX itself, you might be surprised.
> There is no implementation description.
>
> In my experience the audit requirements which the auditor requests are
> most of the time based on the imagination of the auditor.
>
> Hint: you might want to ask where the requested implementation is
> specifically detailed black on white.
>

That is my experience as well.

At my previous employer we went through a number auditors before settling
on one to help write the SOX rules and implement them.

Even after the rules are written they are subject to interpretation.

Jared Still
Certifiable Oracle DBA and Part Time Perl Evangelist
Sr Oracle DBA at Pythian
Pythian Blog http://www.pythian.com/blog/author/still/
Oracle Blog: http://jkstill.blogspot.com
Home Page: http://jaredstill.com

Other related posts: