
Lessons Learned
COSO, COBiT and Other Emerging Standards for SOX Compliance
BY ROBERT PUTRUS, PE, CMC, CFE
After nearly three years, many companies still are coming to grips with the Sarbanes-Oxley Act, specifically Sec. 404, and other new compliance laws, such as HIPAA and Gramm-Leach-Bliley.
And even now, there are lessons to learn regarding tools and methodologies used during these early stages of Sec. 404 compliance.
Although SOX is relatively new, the compliance methodologies that companies employ are well-established and are direct outgrowths of established best practices.
Adopted frameworks used in rendering Sec. 404 compliance services include The Committee of Sponsoring Organizations' Internal Control-Integrated Framework and Control Objectives for Information and Related Technologies

|