Offering regional and national programs, CIO (and CSO) events bring together some of the most respected names and thought leaders in information technology and security. Presented by CIOs and other senior level executives, these invitation-only programs offer timely topics and strong networking. Learn More »
June 17, 11:30 AM - 12:30 PM U.S./ET (GMT-4)
Larry Bonfante, CIO of the U.S. Tennis Association, will discuss the skills and approaches that your rising IT leaders must learn to be effective in an executive capacity.
How to Handle Your New CEO: Managing Turnover at the Top
June 18, 11:00 AM - 12:00 PM U.S./Eastern (GMT-4)
Turbulent times have increased turnover at the top. Find out what Council CIOs have done to "break in" new CEOs—build relationships, set expectations, educate on the role of IT.
Mid-Market CIO Panel: Tips and Techniques for Improving Vendor Relationships
July 15, 4:00 PM - 5:00 PM U.S./Eastern (GMT-4)
We'll highlight relationship priorities and best practices identified in a Council study, and we'll interact with a CIO panel on the approaches they've used to improve strategic vendor partnerships.
Executive Competencies Assessment Tool
Assess Your Business Leadership Skills with the Council's new benchmarking tool. Rate yourself in change leadership, strategy, customer focus and more.
Learn more about the CIO Executive Council »Apply today for a FREE subscription to CIO Magazine!
September 01, 2005 — CIO —
It’s impossible to talk about I.T. process frameworks without mentioning the Sarbanes-Oxley audit. Publicly traded companies are now required to have tight control over financial reporting and must pass two annual audits substantiating that: one for finance and one for the IT systems that produce and contain financial data. The Securities and Exchange Commission has all but formally endorsed the COSO (Committee of Sponsoring Organizations) framework as the standard for evaluating financial controls. There has been no such SEC guidance, however, for the IT audit. In the absence of specific direction, CIOs have turned to existing IT frameworks, including the IT Infrastructure Library (ITIL), to ensure that their processes for supporting financial data are sound.
Christine Rose, director of global IT at Finisar, a computer hardware manufacturer, says that the best practices in ITIL support some of the processes now required by Sarbox. "Having ITIL in place gives you a solid foundation," she says. ITIL isn’t a Sarbox solution in and of itself, however. Dave Erickson, a partner at PricewaterhouseCoopers, says Sarbox is about assessing risk. While risk assessment is an element of ITIL, it isn’t the framework’s primary focus. Furthermore, CIOs who put ITIL or any other IT framework in place solely to comply with Sarbox will have gone overboard, says Erickson. The Sarbanes-Oxley Act requires only that companies establish controls over the systems relating directly to financial reporting. ITIL, Cobit and other frameworks for IT help companies put in place general controls for IT—a good thing to have, but much broader than the narrow scope required by law.