Sarbanes-Oxley - How is it Affecting You?
Grant Barrett asks: "All I hear from IT directors is Sarbanes-Oxley, Sarbanes-Oxley, Sarbanes-Oxley. SOX, as they're calling it, is taxing manpower, swallowing time, and adding huge administrative headaches--not to mention incurring fees and salaries paid out to staff or third-party firms hired to ensure compliance--and that's just the IT department. How are you dealing? Did you make your compliance deadline even after the extension? Are you joining the the backlash?"
You can see from the above that I'm hugely in favor of this law. The World Trade Center bombing:
1) Killed thousands of highly productive people
2) Shut down a section of a major US city for days
3) Destroyed extremely expensive buildings which then required a very expensive clean up effort
4) Shut down a all foreign trade for days
5) Shut down a good chunk of the US transportation system for days
6) Resulted in large permanent increases in US airline ticket prices
7) Resulted in 2 wars
8) Resulted in an increase of oil prices from $20 barrel to about $40-50
9) May have increased cancer rates and other long term health costs for something on the order of 2 million people.
Depending on how you add this up you are talking $200b-600b in costs. I'd say Bin Ladin has Ebbers and Lay beat by about two orders of magnatide. I'd love to see Ebbers and Lay do 20 years and lose everything they own in fines. Bin Ladin is way beyond merely a criminal.
I'm posting this anonymously as I wouldn't want it traced back to me, but I can tell you not only is it costly and burdensome, but it doesn't work. We are now in "compliance", but the changes we had to make to our systems not only didn't have any affect on my ability to alter financial data, but they made them less secure in the process, because external auditors know nothing about our systems, they only have a checklist of features that have to be enabled. It's nothing more than a costly joke that wastes my time and keeps me from doing work that would actually improve our systems. I've started avoiding small, quick projects that would benefit the users, because I would spend 5 minutes making the changes and then 2 hours spread over several days documenting them and getting the required approvals to implement them.