Print this page

Provisioning for SOX IT Compliance

IT Regulatory Compliance

According to Gartner Research, anywhere from 30% to 50% of all financial reporting controls are IT based, making IT regulatory compliance critical. In order to protect financial records, the SEC requires they are stored and managed on a network that conforms to a set of best practices.

For mid-sized companies, IT can be a bit of a black hole. For example, there's a lack of clarity and specificity in the SOX language regarding what a 'competent' IT infrastructure looks like. Given the current lack of set precedents, auditors are trying themselves to discern what to audit and when. Many fall back on old standards such as SAS 70 or struggle to compile checklists that change from year to year.

In addition, accountability is often vague, leaving many companies somewhere behind the curve of best practices.  As the CFO, you have a dilemma.

Should you invest in your own IT infrastructure to achieve and maintain compliance or outsource?

CenterBeam manages the IT infrastructure for hundreds of companies across North America and has helped many of our clients dramatically simplify regulatory compliance. The lessons learned from building and managing our own SAS 70 Type II compliant infrastructure are brought to bear in solving our customer's IT issues. CenterBeam can serve as a facilitator to SOX, HIPAA and other regulatory compliance for our customers by providing three functions: 

  1. Consulting: Certain parts of the SOX language require strategic decisions and planning be done. CenterBeam can and often does help our customers in this area.
  2. Enabling: By coming onto the CenterBeam service we enable our customers to meet some audit criteria by virtue of our own existing processes, e.g., when CenterBeam provides Server and Network management our customers automatically inherit a fully developed and functioning Change Control Process that they themselves may be lacking. To the extent CenterBeam provides services we enable these control objectives to be met.
  3. Providing: Lastly, CenterBeam can directly provide compliance for certain criteria, e.g., if we are providing you with desktop services, we automatically provide anti-virus, patch management, etc., so you are compliant without the need for doing this work and possible capital investment yourself.