« How are your security procedures working in case of an emergency? | Main | Pwned! »

One SOX to rule them all

If you like it here, please consider subscribing to the RSS feed or spreading the news among your friends who also care about security.

Why is SOX your friend during an assessment? For the same reason as every established set of rules or requirements — it leaves as little space for interpretation as possible and gives an assessor a foundation on which they can rely. Of course, such a strict set of guidelines cuts both ways, just like every checklist. But what it can do for you is change your trouble gathering information into business owner’s trouble providing it.

It simply serves as an excellent excuse for insisting on being provided certain evidence of appropriate security controls being in place. And an evidence in this case really means evidence, meaning an admin going “It’s there man. For real. Got my word for that” is not enough no matter how much you happen to like him and believe his words. It’s official, everybody knows that and there is no place for discussion — either evidence is provided or the SOX gap is reported.

And it is in the best interest of a Business Owner to have as little SOX gaps as possible, obviously.

TrackBack

TrackBack URL for this entry:
http://sobiegraj.com/blog/mt-tb.cgi/30

Post a comment

(If you haven't left a comment here before, you may need to be approved by the site owner before your comment will appear. Until then, it won't appear on the entry. Thanks for waiting.)

© 2006-2007 Michał Sobiegraj. All rights reserved. The views expressed here are my own, and not necessarily endorsed by any former or current employer.

About

This page contains a single entry from the blog posted on January 23, 2007 9:46 PM.

The previous post in this blog was How are your security procedures working in case of an emergency?.

The next post in this blog is Pwned!.

Many more can be found on the main index page or by looking through the archives.

Powered by
Movable Type 3.34