abednarz
Executive Editor

Congoleum lays solid foundation for SOX compliance

News
Apr 10, 20064 mins

When it comes to Sarbanes-Oxley, one of the hardest parts of compliance is getting started. Flooring manufacturer Congoleum knew what Section 404 of the legislation required – that it develop and be able to validate the adequateness of controls put in place to protect its financial reporting systems and processes. But to do so meant first documenting its in-house systems and processes.

Congoleum’s existing documentation wasn’t up to par, says Ron Duchesneau, information systems director at the Mercerville, N.J., company. “A lot of the documents either weren’t in place or they were obsolete. Our whole set of policies and standards – and even some operating procedures – had to be developed pretty much from scratch.”

That’s no easy feat. “We spent the first six to eight months of the SOX project figuring out how we were going to do this,” Duchesneau recalls. After a couple of false starts, Duchesneau realized the company needed a solid base for its documentation efforts so that it could work from there to address any gaps in its system and process controls.

“Since we didn’t have a lot of our policies, procedures and standards documented, we needed to come up with a basic framework that we could use to get started,” Duchesneau says. For this key foundation, Congoleum is using the Command Center platform from Scalable Software.

Scalable’s Command Center software is designed to identify gaps between a company’s current operations and SOX requirements. It includes an auditable, centralized repository for policies and controls, as well as vast libraries and templates to help users get started. Reporting and incident management features help companies evaluate risk and respond to audit inquiries.

Command Center’s library of policies and standards helped jumpstart Congoleum’s implementation. “Once we adopted a framework for developing policies, standards and procedures, we made really good progress,” Duchesneau says. “The documentation process really started to fall into place.”

With the documentation hurdle surmounted, Congoleum could turn its attention to implementing any necessary SOX controls the system flagged. “We still have a lot more work to do, but as far as the documentation and general infrastructure of our processes, it’s pretty much done,” Duchesneau says.

For its next phase of SOX compliance, Congoleum invested in tools to help automate some of the ongoing monitoring requirements. For example, it’s using software from Bsafe Information Systems to analyze security logs from its IBM AS/400 systems – something IT staff used to do manually in the past, Duchesneau says. It’s also using TurnOver change management software from SoftLanding Systems to monitor and log changes to application programs.

Using automated tools for these tasks not only saves IT time, but also provides a much more audit-friendly trail. “If you’re able to show that this information is coming from a system like TurnOver or Bsafe, then you’re given a whole lot more latitude as far as the amount of auditing that you need to do to prove that a particular control works,” Duchesneau says.

Next up, Duchesneau hopes to find ways to further streamline the auditing process. With the documentation complete and controls in place, the challenge of SOX will be maintaining compliance – and validating compliance through regular audits. “What concerns us is the effort to maintain the control processes and perform the audits that SOX 404 seemingly suggests we need to do,” Duchesneau says. “That’s going to take a lot of time.”

Fortunately, Congoleum is right where it wants to be in terms of SOX compliance – ahead of the deadlines. Based on its size and fiscal calendar, Congoleum is due to begin complying with Section 404 when its fiscal year ends in December of next year. But the company plans to be compliant by mid-2006, “so that if there are any little bumps along the way, we’ll be able to handle them,” Duchesneau says. “That’s why we’ve been pressing forward to get our processes in place and get to the point where we can do internal audits by July.”

Looking back on what Congoleum has accomplished since launching its SOX efforts in earnest last February, Duchesneau says there are good and bad results. On the downside, SOX has consumed a lot of IT focus. “It’s definitely eating into other IT projects. We’ve had to scale back on some projects until our executive group is satisfied that we’re compliant,” Duchesneau says.

On the plus side, the company is better off for all its work formalizing its processes and procedures, Duchesneau says. “A lot of the documents that we’ve produced over the last six months are documents that we’re glad to have, and we’re glad we went through the process.”

See also:

Qualcomm shares two years of SOX experience

Blue Rhino tackles SOX with tools on hand

The SOX tax

abednarz

Ann Bednarz is the executive editor of Network World. Ann is a longtime IT journalist and has spent 26 years writing and editing for Network World, where she has worked as a news reporter, managed product testing and reviews, and developed features and how-to articles for an audience of network professionals and data center managers. Over the last two years, she has conceived and edited award-winning content for Network World that includes 2025 Jesse H. Neal Award finalists, 2025 Azbee Award regional winners and national finalists, and 2024 Eddie & Ozzie Award finalists.

Ann holds a bachelor’s degree in architecture and spent the early part of her journalism career writing about architectural design and construction. In her free time, she keeps those skills alive through DIY projects.

More from this author