By Connie Spinelli, GRC Solutions
By now your company is likely in the Sarbanes-Oxley Section 404 mode. As internal auditors you are once again pondering what to do with what used to be SAS 70 reports, realizing that this year the issues are more complex. This article addresses the question: How do I know which vendors should be giving my organization SOC reports for the organization’s SOX compliance program?