3 ms·
I mean, this is hilarious if that's the approach you have been taking throughout your career but for anyone else reading this comment it's wholly inaccurate.
by lavezzi 9y ago
I mean, this is hilarious if that's the approach you have been taking throughout your career but for anyone else reading this comment it's wholly inaccurate.
- jedberg 9y agoI've personally been part of it at two public companies, and my friends have been in many other public companies, and we've all had the same experience. So sure, maybe it's different elsewhere, but amongst the people I know, that's how it works.
- lavezzi 9y agoYou may have been part of it but you clearly do not have a good comprehension of it. In another comment you stated "Another great example is password rotation. The law demands you have a password rotation policy.". This is completely false, Section 404 deals with the adequacy of the company's internal control on financial reporting (ICFR), it does not contain such specific IT mandates or requirements. As you mentioned, Sarbanes-Oxley is written at a very high level but that is meant to provide flexibility for a wide range of companies and their associated IT systems. It can be implemented badly if neither party truly understand the requirements, which looks to be the case here.
- jedberg 9y ago> It can be implemented badly if neither party truly understand the requirements, which looks to be the case here. On that I totally agree with you. But my main point is that the law is so poorly written, almost no one, including most auditors, don't understand it, and you end up with a lot of "better safe than sorry". If you're someone who truly understands the law then I applaud you and I wish you were my auditor, but is seems that almost no one is as well informed as you, which is the crux of the problem.
- BenchRouter 9y agoFWIW I've been part of it at two public companies as well, and my experience nicely lines up with yours. Incredibly vague mandates that result in extremely complex rules and systems. Lots of things being marked as "financially sensitive" even though they weren't at all - because better safe than sorry. In both instances it quite literally cost the company several employees who were assigned to put the SOX systems in place, because it was so incredibly frustrating (and, well, boring), that they ended up quitting down the road and directly attributing their leaving to SOX compliance.
- btilly 9y agoCan you provide evidence that it is inaccurate? What has your role and experience been upon which your opinion is based? What I have seen of SOX compliance when it came in for multiple companies that I was involved. Every time what I saw matches the description pretty closely. The auditor comes in, sees what you are doing, reads the rules, negotiates with you a set of procedures that you can do and in their opinion will bring you in compliance with the rules, then you execute that. The rules themselves are so vague that what they will be interpreted to mean varies widely by auditor. But the legal requirements for the company are met if the auditor signs off on it, so you do whatever your auditor says to do. Those involved knows that a lot of the created procedures are silly, but the legal problems if you don't go through the charade are quite real, so you have to do them anyways. That is not to say that real problems aren't regularly uncovered. I'm sure that they are. But there is a tremendous amount of arbitrariness in, "Here is what you need to do to be compliant."
- lavezzi 9y agoI've had significant experience performing IT Audit for SOX 404 from both an Internal and External perspective.
- btilly 9y agoAnd your experience is that the procedure arrived at isn't highly arbitrary? If so, can you explain why your experience is so sharply different from everyone else's? (Note, internet claims of "I have significant experience" are the same as claims of "I am an expert" - only credible when they come with other evidence from which we can judge expertise.)