Re: SOX Reporting Requirement

  • From: Andrew Kerber <andrew.kerber@xxxxxxxxx>
  • To: Jared Still <jkstill@xxxxxxxxx>
  • Date: Thu, 4 Sep 2014 10:31:32 -0500

Ill never forget the time the Sox auditor wanted to review copies of the
archive logs and redo logs.


On Thu, Sep 4, 2014 at 10:23 AM, Jared Still <jkstill@xxxxxxxxx> wrote:

>
> On Thu, Aug 28, 2014 at 10:40 AM, Frits Hoogland <frits.hoogland@xxxxxxxxx
> > wrote:
>
>> If you actually look at what is in SOX itself, you might be surprised.
>> There is no implementation description.
>>
>> In my experience the audit requirements which the auditor requests are
>> most of the time based on the imagination of the auditor.
>>
>> Hint: you might want to ask where the requested implementation is
>> specifically detailed black on white.
>>
>
> That is my experience as well.
>
> At my previous employer we went through a number auditors before settling
> on one to help write the SOX rules and implement them.
>
> Even after the rules are written they are subject to interpretation.
>
> Jared Still
> Certifiable Oracle DBA and Part Time Perl Evangelist
> Sr Oracle DBA at Pythian
> Pythian Blog http://www.pythian.com/blog/author/still/
> Oracle Blog: http://jkstill.blogspot.com
> Home Page: http://jaredstill.com
>



-- 
Andrew W. Kerber

'If at first you dont succeed, dont take up skydiving.'

Other related posts: