August 2, 2010

Overall IT Risk and Control Approach and Considerations When Complying with Sarbanes-Oxley

Questions & Answers from Protiviti's "Guide to The Sarbanes-Oxley Act: IT Risks and Controls"

This section of Protiviti's “Guide to the Sarbanes-Oxley Act: IT Risks and Controls – Frequently Asked Questions" addresses having an overall IT risk and control approach when complying with Sarbanes-Oxley. Topics covered include: Why is it so important to consider IT when evaluating internal control over financial reporting? How should Section 404 compliance teams define “IT risks and controls”? And, what guidance does COSO provide with respect to IT controls?