Home > Data management / BI News > Shop Talk: Know your compliance priorities
Data management / BI News:
EMAIL THIS

Shop Talk: Know your compliance priorities

By Paul Gillin
17 Jan 2006 | SearchSMB.com

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


The 173-word Section 404 of the Sarbanes-Oxley Act of 2002 (SOX) will cause publicly held mid-market companies to spend an average of $1.5 million in the first year to comply, according to a survey by consulting firm CRA International. One study estimated business's total costs of Section 404 to be $6 billion in spending on storage alone. And the costs fall disproportionately on smaller firms. The Small Business Association found that small companies spend nearly 50% more on compliance per person than large companies.

For more information

Picking the right SOX tool in 2006

Read analysts predictions for SOX spending in 2006

The Wikipedia online encyclopedia defines ''gold rush'' as "a period of feverish migration…into the area of a dramatic discovery of commercial quantities of gold." By that definition, compliance is the gold rush of the first part of the 21st century.

Tech companies have jumped into the breech to sell you solutions to your compliance problems. Type ''compliance'' at Bitpipe.com and get a list of 335 advisory white papers, many of which are SOX-related, from a who's-who of the top vendors in the industry. One company offers a self-administered test that is supposed to tell you in five minutes how vulnerable you are to compliance failures. Google's search results page on compliance can't accommodate all the ads from tech firms.

Network vendors will tell you that compliance is a network reliability and security problem. Information security vendors say you should get your identity management act together. Storage companies say you need more disk space.

And the audit companies, whose shoddy work created the need for Section 404 in the first place, are only too eager now to sell you their solutions for prices beginning in the low six figures.

I don't mean to imply that vendors don't have useful tools to help you get compliant. But the IT industry sees technology as a hammer and every problem as a nail. There's no mention of software or hardware in Section 404. In fact, most experts agree that the last thing you should do is go out and buy technology. You need to get your processes and objectives in place first.

Start by understanding the requirements of Section 404. SearchSMB.com has an excellent IT Management Guide on Compliance, aimed at small and midsized companies. SearchCIO.com has an informative Executive Guide to SOX. The IT Compliance Institute is a rich source of news and advice on the topic. Compliance Pipeline has good content just for IT professionals.

Then get a committee together. If you're the CIO, you'd better be on it because your neck is on the line. Now may be the time to bring in a consultant but devote your time to analyzing what the law actually requires and where your shortfalls are. And while you're at it, identify any other compliance problems you need to address. Gartner just issued a report saying it can cost 10 times as much to address various compliance issues piecemeal as it does to tackle them at once.

When it comes to technology, the key is setting priorities. Once you know what you have to fix, then go back and start reading those white papers. Consult documents from several vendors so that the competing marketing messages cancel each other out.

Focus on fixing your processes. The best e-mail archiving software in the world won't work if your employees are using instant messaging. Consult colleagues at other companies who are further along in their compliance efforts and find out where the gotchas are.

Document your shortfalls and the steps you plan to take to address them. They'll come in handy if the regulators come knocking. Then, and only then, seek technology solutions from vendors. But don't let marketing messages define your compliance priorities.


Paul Gillin is a technology writer and consultant and former editor-in-chief of TechTarget. His Web site is www.gillin.com.


This article originally appeared on SearchSMB.com.

Tags: Financial reporting and compliance data managementSarbanes-Oxley in the EnterpriseVIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



RELATED CONTENT
Financial reporting and compliance data management
Business intelligence in financial services: Special report
Business Objects customer frustrated with SAP licensing, technical hiccup
Microsoft gives PerformancePoint Server's financial planning component new life
New data analysis apps part of IBM's industry-specific BI vision
What are the best analytical tools for business intelligence for finance?
Disjointed eDiscovery practices exposing companies to legal risk, rising costs
Business intelligence software helps states track federal stimulus spending
An overview of Sarbanes-Oxley compliance software
Automating Sarbanes-Oxley compliance: Understanding SOX software
Sarbanes-Oxley compliance quiz: Are you SOX savvy?

Sarbanes-Oxley in the Enterprise
Study: SOX-compliant firms see drop in costs in year 2
Some things SOX doesn't say: SOX myths
Sarbanes-Oxley – Prepare or put off?
SearchSecurity.com's SOX Security School
Former SEC chair is SOX fan -- with exceptions
Government regulations: How do they affect your security strategy -- or do they?

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
compliance  (SearchDataManagement.com)
consumer privacy  (SearchDataManagement.com)
Patriot Act  (SearchDataManagement.com)
privacy  (SearchDataManagement.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



Data Management: Business Intelligence, Data Integration, Data Compliance
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2005 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts