the most trusted source for computer security training, certification and research


Sarbanes-Oxley Information Technology Compliance Audit

Secure Passage
Abstract
This paper provides a basic review of the background literature (i.e. extensive but not exhaustive) and develops a process model so that a professional IT Auditor may readily appreciate the subtleties of the Sarbanes Oxley audit process. The case study is developed to illustrate some of the effects of the issues described in the literature and other issues developed in the process model. The literature, process model and case study develop sufficient detail so a professional IT Auditor may readily modify and apply it to a new audit. Experience demonstrates that the focus of IT audits conducted under the mandate of Sarbanes Oxley and its IT Section, Section 404, has important differences with the focus of a traditional IT audit.
<<Reading Room Home     <<Back to Category

Contact us: (301) 654-SANS(7267)
Monday - Friday 9am-8pm EST/EDT