SOX forces businesses to think holistic, says risk expert

By Vivian Yeo, ZDNet Asia
Wednesday, April 19, 2006 07:28 PM

SINGAPORE--The compliance wave created by regulatory requirements, such as Sarbanes-Oxley, gives businesses a reason to view security and risk in a more holistic manner.

Philip Chong, director of Deloitte & Touche Enterprise Risk Services, told participants at a security conference in the island-state that the SOX Act has had the "single greatest impact" in getting companies focused and disciplined around the area of IT controls.

That is because there has long been a disconnect between IT security and business requirements, and companies have not placed enough emphasis on maintaining tighter internal controls, explained the Singapore-based Chong.

The risk consultant said businesses need to have a reliable financial reporting system and proper documentation trail in place. By requiring businesses to demonstrate how IT controls enable the reliability of financial reporting, the SOX regulations facilitate the implementation of the right security controls, he added.

In the region, China, Hong Kong, Japan and Korea have come up with their own versions of SOX or have similar existing regulations in place, said Chong. Singapore is also considering amendments to its regulations regarding company listings.

According to Chong, corporate governance involving control and compliance is a result of sound security architecture, IT governance in the form of CobiT (Control Objectives for Information and Related Technologies), best practices in security management and IT operations, and the alignment of IT to business objectives.

In the area of risk management, companies should consider all types of business risk and not just focus on security, cautioned Chong.

Security is often "not the single biggest [business] risk", he noted.

Chong added that a business must not look to IT to manage every risk it faces. "The response to a risk need not be technology--it can be financial," he pointed out.

To illustrate the point, he noted that in the event of the avian flu breakout, a typical business would focus on issues relating to operations and business continuity, not technology. In contrast, a travel agency would be concerned with liquidity, and therefore would need to work out a cash flow plan, such as seeking indemnification from banks or getting insured, he added.


WORTHWHILE?

0

0 votes
Blog

Talkback 0 comments

There are currently no comments for this post.


Tech Jobs Now!

Search for your ideal tech job:

Common ways IT wastes money on development

Web Development

Examples include using developers as support staff and failing to calculate a project's ROI before giving it the go-ahead.


Read more »



  • Enterprise 2.0

    Vince Casarez, vice president of product management at Oracle, explains how Web 2.0 technologies, such as tags, wikis, and mash-ups, can be applied within an organization.
    Play video


  • Nehalem Architecture

    What makes next-generation Intel® Microarchitecture (Nehalem) such a superior successor?
    Play video

 
On demand CRM goes strategic
CRM technology has come of age, and is now able to align with your customer strategy and grow in step with your business.

» Learn more about Oracle’s CRM Solutions



Free the untapped potential of your IT infrastructure
Reduce bottlenecks to drive the efficiency and productivity of Business IT.
» Ultimate virtualization blade
» Scalable SAN solution
» Accelerate service delivery

Could this be the most critical budget for India?

Blog thumbnail

For business journalists in India, budget time is excitement time. It's like sports journos covering the Olympics. As a newspaper correspondent, I too had my fill of budget-time excitement. But..... by Swati Prasad

Read more »

Tags

  1. acquisition
  2. acquisitions
  3. ceo
  4. china
  5. financial
  6. google inc.
  7. green it
  8. india
  9. industry
  10. information technology
  11. it outsourcing
  12. job
  13. microsoft corp.
  14. network
  15. outsourcing
  16. revenue
  17. singapore
  18. software
  19. strategy
  20. u.s.