Security Basics mailing list archives

Re: SOX Compliance and assesment


From: "mr.happy" <sadplanet () chello be>
Date: Sun, 16 Jan 2005 12:24:17 +0100

On Fri, 2005-01-14 at 10:42 -0500, aixroot () mindspring com wrote:
I will simply say this:  My company has recently worked on SOX for '04.  I will say that we had nothing but 
exasperation while working with PwC ( Price Waterhouse Cooper) as they were our Consultants.  They had little more 
knowledge of anything other than to ask "is this a mainframe or a server thingy".  Even after telling them we only 
have two mainframes they continued to ask.  They made the difficult task much harder and far more expensive than 
necessary.  

We worked with Deloitte. Although they did understand our
infrastructure, I did not have a very confident feeling of the SOX
knowledge of the consultants. Too many times they didn't know the answer
or assumed(?) it was a certain way.

Perhaps this is because SOX is still new, still it shouldn't be an
excuse.

greets,
DD
-- 
Wiggle your big toe.


Current thread: