BeyondTrust

Security in Context: The BeyondTrust Blog

Welcome to Security in Context

Bringing you news and commentary on solutions and strategies for protecting critical IT infrastructure in the context of your business.

The Cost Of SOX Is Declining?

Posted June 30, 2011    Peter McCalister

No, I’m not talking about socks that protect your feet, I’m talking about the government regulation that most of you are worried about. Protiviti just released a new study on the effectiveness and costs of Sarbanes-Oxley compliance with a number of interesting insights for IT managers who are concerned about the effectiveness and costs of their IT controls. The overall results are encouraging.

According to Protiviti’s 2011 Sarbanes-Oxley Compliance Survey, the cost of SOX compliance is declining and most participant believe the benefits of the controls outweigh the costs. Now I am little skeptical that all of the companies surveyed are including the full impact of SOX controls on IT costs, especially since less than 50% track and report the hours and costs of compliance. I suspect some companies have just gotten comfortable that some of the activities they added are just part of a new normal. Sort of like the metaphor of a slowly boiling frog not jumping out of the pot.

Nevertheless, the way companies are approaching the continuous improvement in their SOX controls is telling. They are simultaneously reducing costs and increasing the effectiveness and efficiency of operations by following a number of key strategies:

-Using the COSA framework to define best practices. COBIT would provide a similar framework for IT
-Increase use automated controls and continuous monitoring including a shift to preventative rather than detective controls
-Use of data mining and analytics to increase understanding of process performance
-Consolidating IT processes, platforms and systems

These are all things IT can embrace and as a strategic vendor of compliance and security solutions to the enterprise, things we should and can help our customers with. Implementing least privilege across physical, virtual and cloud-computing environments can also add to this savings.

Leave a Reply

Additional articles

How To Implement The Australian Signals Directorate’s Top 4 Strategies

Posted October 20, 2014    Morey Haber

The Australian Signals Directorate (ASD), also known as the Defence Signals Directorate, has developed a list of strategies to mitigate targeted cyber intrusions. The recommended strategies were developed through ASD’s extensive experience in operational cyber security, including responding to serious security intrusions and performing vulnerability assessments and penetration testing for Australian government agencies. These recommendations…

Tags:
, , , ,
asp-mvc

Exploiting MS14-059 because sometimes XSS is fun, sometimes…

Posted October 17, 2014    BeyondTrust Research Team

This October, Microsoft has provided a security update for System.Web.Mvc.dll which addresses a ‘Security Feature Bypass’. The vulnerability itself is in ASP.NET MVC technology and given its wide adoption we thought we would take a closer look. Referring to the bulletin we can glean a few useful pieces of information: “A cross-site scripting (XSS) vulnerability exists…

Tags:
4bestpracticesaudits-blog

Four Best Practices for Passing Privileged Account Audits

Posted October 16, 2014    Chris Burd

Like most IT organizations, your team may periodically face the “dreaded” task of being audited. Your process for delegating privileged access to desktops, servers, and infrastructure devices is a massive target for the auditor’s microscope. An audit’s findings can have significant implications on technology and business strategy, so it’s critical to make sure you’re prepared…

Tags:
, , , ,