Compliance pressures still mounting

News
Mar 21, 20057 mins

Regulatory requirements, mainly Sarbanes-Oxley, continue to squeeze IT budgets and staff.

The tab for regulatory compliance continues to climb – and along with it, demand for IT projects to bolster security, storage and reporting capabilities.

U.S. companies will spend $15.5 billion on compliance-related activities this year, according to research published last week by AMR Research. A large chunk of the spending is designated for public companies’ projects related to the Sarbanes-Oxley (SOX) Act of 2002. SOX spending will grow 11% from $5.5 billion last year to $6.1 billion this year, AMR says. Other budget-consuming initiatives include compliance with the Health Insurance Portability and Accountability Act (HIPAA), Food and Drug Administration regulations, and the Basel II international banking accord.

In particular, SOX has put a spotlight on compliance initiatives since it affects a broader swath of companies than some of the industry- or geographic-specific regulations, says John Hagerty, vice president of research at AMR Research. Additionally, it’s getting budget priority over other regulatory projects because its deadlines are imminent. “Those with the shortest deadlines move to the top of the queue,” he says.

Passed in the wake of accounting scandals at companies such as Enron and WorldCom, SOX is designed to deter fraud and add transparency to public companies’ financial reporting procedures. Among the more onerous of the legislation’s requirements is Section 404, which calls for companies and their auditors to formally attest to the existence and adequateness of internal controls over financial reporting systems.

Establishing, testing and documenting such controls is a time-consuming effort that not only has financial departments scrambling but involves nearly every aspect of IT.

The toughest part of SOX compliance is the scrutiny it places on the IT department, says James Olson, CIO at Waterbury Hospital in Connecticut. SOX has increased the number and comprehensiveness of IT-related audits, he says. “It used to be that a 100-watt bulb would be turned toward IS once a year. Now we have a searchlight looking at us.”

Prior to the legislation, auditors examined the hospital’s patient accounting system. Today, audits extend to multiple applications, including accounting, payroll, materials management and decision support systems.

Auditors today look not only at backup, data center security and password administration but also division of labor within the department, Olson says. “They have increased what they are auditing and [now look into] the formality of the policies, procedures and processes supporting the department,” he says.

What makes SOX tough is that there’s no one-size-fits-all checklist for compliance, adds James Kritcher, vice president of IT at White Electronic Designs. “From an IT perspective, the actions that a company will need to take depend on what is discovered in the internal controls inspection. IT leaders need to work closely with the Sarbanes-Oxley auditors to make sure that they know what their companies’ weaknesses are.”

When it comes to choosing technology to help with Section 404 compliance, purchases run the gamut from security and document management to collaboration and performance management products. There’s no shortage of vendors offering SOX compliance assistance.

For example, OpenService this week is expected to release new versions of its flagship Security Threat Manager software, as well as Security Log Manager , an add-on monitoring application that alerts security managers to events that don’t comply with pre-defined SOX policies.

Last week, SAP announced a deal with compliance specialist Virsa Systems to offer its Compliance Calibrator software to SAP users to help keep tabs on ERP system controls and avoid segregation-of-duties conflicts among end users.

Getting help

To automate manual processes, Waterbury Hospital has purchased configuration control software for patching its servers, password control software and other technology, Olson says.

White Electronic Designs uses automated configuration management tools from Ecora and Tripwire to automate some of its SOX requirements, Kritcher says. The Phoenix company uses the tools to document baseline device configurations and detect unauthorized infrastructure changes, he says. “Without these types of tools, compliance would be much more difficult.”

Even with the tools, the burden of SOX is palpable. “A great deal of IT time over the past year has been spent on Sarbanes-Oxley compliance activities,” Kritcher says. “We had to defer a couple of planned, funded projects to divert staff resources to the compliance effort. The current year is looking much the same.”

One of the aspects of SOX that has surprised companies is that it’s an ongoing effort, Hagerty says. “People thought it would be a Y2K-like effort, but it’s not. Companies have to deal with SOX requirements perpetually.”

The ongoing nature of SOX compliance is disruptive and costly, Olson says. “The auditors will always find yet one more aspect that needs doing,” he says.

But there also are advantages for IT to SOX regulations, which can provide an impetus for companies to formalize their documentation and process controls. Many of the practices SOX has necessitated are good management practices, Olson says. “It is just we always gave them lower priority than our day-to-day stuff so implementation dragged,” he says. “Now we have no alternative.”

Mike Levinson, IT capacity planning and change manager at Hannaford Bros., a supermarket retailer in Portland, Maine, agrees. Levinson says SOX compliance helped him get management to approve the process-oriented approach he prefers to take. A former IBM systems administrator, Levinson always wanted to instill change management processes at the supermarket chain before SOX auditors hit the scene.

“Sarbanes-Oxley helped us get processes in place that probably should have been in place,” he says.

Levinson says an audit of Hannaford’s IT shop showed the company could improve its change management processes and its security controls such as defining separation of duties and establishing consistent policies across system platforms.

Levinson notes security policies on Windows, Unix, Linux and mainframe servers – all of which Hannaford has – differ and SOX will require the IT department to define consistent rules across the platforms. Also, SOX security policies, such as incident response, need to be clearly stated to avoid any ad hoc firefighting when, say, a virus breaks out.

Levinson estimates that his IT team spends about 60% of its time fixing problems, which take priority over long-term IT projects. Now with SOX compliance on their list of things to do as well, he says he can’t “accurately predict how many resources we will have for IT projects,” which means they could potentially miss scheduled deadlines.

Because Hannaford is owned by the Belgium-based Delhaize Group, the company has another year to get compliant with Section 404. The Securities and Exchange Commission this month granted small and midsize public companies with a market capitalization less than $75 million, as well as international companies, a one-year reprieve until July 15, 2006.

Large public companies with a market capitalization of at least $75 million – with some exceptions – must begin including internal control reports required by Section 404 in annual reports filed for their first fiscal year ending on or after Nov. 15, 2004.

Looking ahead, AMR’s Hagerty says companies will become more strategic about addressing SOX. Efforts this year will shift away from manual processes and toward automating compliance, he says. “Fixes are heavily manual today, but that can’t go on indefinitely or it would pose a real hindrance to business.”

Kritcher says he sees an opportunity to shed some compliance costs and free up IT resources “by implementing systems and processes that simplify the compliance monitoring and audit process.” As companies put compliance controls in place it makes sense to look for process re-engineering opportunities, he says.

Shifting SOX budgets from headcount-related costs to technology purchases reflect shifting mind-sets, Hagerty says.

Whereas companies spent about $1.1 billion in 2004 on SOX-related technology, this year they will spend $1.7 billion, he says. “People are spending more in ’05 than ’04 because they realize they have to automate a lot of the stuff they did by brute force last year.”

Next up is finding ways to use technology to remediate any compliance shortcomings. By the end of 2005, companies will begin to deploy technology not only to automate processes and identify gaps, but also to help automatically close up any gaps that appear, Hagerty says.

abednarz

Ann Bednarz is the executive editor of Network World. Ann is a longtime IT journalist and has spent 26 years writing and editing for Network World, where she has worked as a news reporter, managed product testing and reviews, and developed features and how-to articles for an audience of network professionals and data center managers. Over the last two years, she has conceived and edited award-winning content for Network World that includes 2025 Jesse H. Neal Award finalists, 2025 Azbee Award regional winners and national finalists, and 2024 Eddie & Ozzie Award finalists.

Ann holds a bachelor’s degree in architecture and spent the early part of her journalism career writing about architectural design and construction. In her free time, she keeps those skills alive through DIY projects.

More from this author

Denise Dubie

Denise Dubie is a senior editor at Network World with nearly 30 years of experience writing about the tech industry. Her coverage areas include AIOps, cybersecurity, networking careers, network management, observability, SASE, SD-WAN, and how AI transforms enterprise IT. A seasoned journalist and content creator, Denise writes breaking news and in-depth features, and she delivers practical advice for IT professionals while making complex technology accessible to all. Before returning to journalism, she held senior content marketing roles at CA Technologies, Berkshire Grey, and Cisco. Denise is a trusted voice in the world of enterprise IT and networking.

More from this author