August 16, 2010

Entity-Level Considerations

Questions & Answers from Protiviti's "Guide to The Sarbanes-Oxley Act: IT Risks and Controls"

This section of Protiviti's “Guide to the Sarbanes-Oxley Act: IT Risks and Controls – Frequently Asked Questions" addresses entity-level considerations. Topics covered include: How does management consider the entity-level issues around IT risks and controls? Are there separate “entities” which just include IT operations or processes? And, what IT governance issues should be considered for purposes of complying with Sections 404 and 302 of Sarbanes-Oxley?