Public Corporations Compliance
(Sarbanes-Oxley)
Public
corporations are under increasing demands to build, maintain and ensure a secure
and reliable information assets. In response to various corporate accounting
scandals, the Sarbanes-Oxley (SOX) Act was passed to compel public companies
into implementing monitoring and security measures that can verify the proper
operation of financial reporting and analysis. While the SOX rules cover
mostly accounting matters, Anitian has built a all-inclusive practice to cover
sections 403 and 302 of the SOX act, which covers information security, privacy,
and monitoring.
Anitian uses our exclusive
Industry Security Maturity ProfilesTM (ISMP)
to analyze and audit your environment for compliance with SOX and its associated
policies and standards. These profiles combine established security standards
such as ISO17799, CobiT and ITIL with the SOX requirements to provide a public
institutions a focused maturity profile. Using this profile, our team can
audit your security posture in comparison to other, similar public
organizations, thus providing an audit that is uniquely relevant to your
organization. Moreover, our profiles are tuned specifically for your industry.
Anitian has developed security maturity profiles for financial, manufacturing,
entertainment, and communications industries (to name a few).
Our typical SOX audit includes:
-
Organizational Analysis
Anitian conducts an analysis of your
entire organization and how it uses, manages, procures, and delivers IT
services.
-
Infrastructure Analysis
Anitian's veteran network engineers review the infrastructure for best
practices and security.
-
Policy and procedure review
Review of all organization security policies and procedures for alignment
with standards.
-
Security assessment
Assess networks, systems and access for security weaknesses.
-
Standards adherence
Analyze business against established standards using Anitian's exclusive
Industry Security Maturity ProfilesTM.
-
Compliance with SOX
Review environment for compliance with the Sarbanes-Oxley Act.
-
Remediation Reporting
Report results of audit and develop remediation measures. Anitian's reports
include high-level executive reporting as well as detailed, technical
reports.
-
Implement Security Improvements
Architect and implement necessary security improvements.
-
Train & Educate Staff
Educate staff on proper security practices and procedures.
-
Monitoring
On-going monitoring and validation to ensure compliance.
The result is a comprehensive and rigorous
process that ensures your agency meets all requirements and can easily gain SOX
compliance with sections 404 and 302. Anitian has performed assessments for
numerous public organizations in many different industries.
For additional information, please contact
info@anitian.com.