So the small company I work for was just acquired by a major corporation and now I am being slammed with changes to my entire infrastructure in order to become compliant with the Sarbanes Oxley Act.<\/p>\n
Advertisement
Currently the biggest hurdle I need help with is all of the Documenting. Does anyone here have experience with SOX Burdens that can recommend a good program for documenting? I realize this is a completely broad question but I’m hoping someone knows of a good program that I can make entries to for my maintenance, server changes, keep tract of user access request forms, etc.<\/p>\n
Advertisement
Like I said… Complete shot in the dark but I couldn’t be more curious.<\/p>","upvoteCount":6,"answerCount":4,"datePublished":"2014-06-19T16:15:52.000Z","author":{"@type":"Person","name":"jonathanstrange4763","url":"https://community.spiceworks.com/u/jonathanstrange4763"},"acceptedAnswer":{"@type":"Answer","text":"
Jonathan3056<\/p>\n
I work for a financial software company and am the compliance manager for our IT auditing. It sounds like you may be confusing two different things. SOX (Sarbanes Oxley) and SOC (Service Organization Controls) Types 1, 2 and 3 are different things entirely. SOX has to do with transparency of financial accounting while SOCs are controls that your company establishes to ensure clients that data is protected in different ways.<\/p>\n