September 13, 2010

Documentation

Questions & Answers from Protiviti's "Guide to The Sarbanes-Oxley Act: IT Risks and Controls"

This section of Protiviti's “Guide to the Sarbanes-Oxley Act: IT Risks and Controls – Frequently Asked Questions" addresses documentation issues. Topics covered include: How much documentation should the IT organization and the application and data owners have in place to evidence the controls and functioning of the applications? How should the Section 404 compliance project team document the IT controls at the entity level? And, how should the Section 404 compliance project team document the IT controls for the IT general controls at the activity/process level?