
Sarbanes-Oxley, IT Governance and Enterprise Change Management
Address
Julie Vaishnav jvaishnav@mks.com
Sarbanes-Oxley compliance has become one of the most dominant business challenges facing corporations today. As technology is at the core of business operation, governance rigor now absolutely applies to the CIO and his/her Information Technology organization. One of the principle concerns facing IT departments is how to produce well-defined and repeatable processes to help mitigate risk and achieve audit compliance.
This paper focuses on one framework, COBIT, which has been developed by the IT Governance Institute as a generally applicable and accepted standard for good Information Technology (IT) security and control practices. The paper includes discussion on:
1) Expressing IT control practices through Maturity Models for benchmarking measurements
2) Measuring outcome and performance of IT processes through Key Performance Indicators
3) Getting processes under control using Critical Success Factors
Enterprise Software Change Management (ESCM) is recommended as a solution to combine process methodologies such as COBIT with the infrastructure necessary to manage and store process workflows and then measure the results of those processes. Any business process, including all software development processes, can be automated with full audit trails, and thus, ESCM can play an integral part in achieving Sarbanes-Oxley compliance.
Reviews (0)
Be the first to review this listing!
