Re: SOX Reporting Requirement

From: Andrew Kerber <andrew.kerber_at_gmail.com>
Date: Thu, 4 Sep 2014 10:31:32 -0500
Message-ID: <CAJvnOJZv7VxzWWTwcdox8fsmyUvZr2o+VJeCsw2pnz2+YzEccA_at_mail.gmail.com>



Ill never forget the time the Sox auditor wanted to review copies of the archive logs and redo logs.

On Thu, Sep 4, 2014 at 10:23 AM, Jared Still <jkstill_at_gmail.com> wrote:

>
> On Thu, Aug 28, 2014 at 10:40 AM, Frits Hoogland <frits.hoogland_at_gmail.com
> > wrote:
>
>> If you actually look at what is in SOX itself, you might be surprised.
>> There is no implementation description.
>>
>> In my experience the audit requirements which the auditor requests are
>> most of the time based on the imagination of the auditor.
>>
>> Hint: you might want to ask where the requested implementation is
>> specifically detailed black on white.
>>
>
> That is my experience as well.
>
> At my previous employer we went through a number auditors before settling
> on one to help write the SOX rules and implement them.
>
> Even after the rules are written they are subject to interpretation.
>
> Jared Still
> Certifiable Oracle DBA and Part Time Perl Evangelist
> Sr Oracle DBA at Pythian
> Pythian Blog http://www.pythian.com/blog/author/still/
> Oracle Blog: http://jkstill.blogspot.com
> Home Page: http://jaredstill.com
>

-- 
Andrew W. Kerber

'If at first you dont succeed, dont take up skydiving.'

--
http://www.freelists.org/webpage/oracle-l
Received on Thu Sep 04 2014 - 17:31:32 CEST

Original text of this message