Sarbanes-Oxley Act and COBIT compliance

The Sarbanes-Oxley (SOX) Act of 2002 that is based on the 107th congress of the United States of America oversees the audit of public companies that are subject to the securities laws, and related matters, in order to protect the interests of investors.

SOX Section 404 mandates the management assessment over internal controls. For most organizations, internal controls span their information technology systems, which process and report the financial data of the company. The SOX Act provides specific details on IT and IT security. Many SOX auditors rely on standards, such as COBIT as a method to gauge and audit proper IT governance and control. The PowerSC Standard Edition SOX/COBIT XML configuration option provides the security configuration of AIX® and Virtual I/O Server (VIOS systems that is required to meet the COBIT compliance guidelines.

The IBM® Compliance Expert runs on the following version of the AIX operating system:
  • AIX 6.1
  • AIX 7.1
  • AIX 7.2

Compliance with external standards is a responsibility of an AIX system administrator’s workload. The PowerSC Standard Edition compliance expert feature is designed to simplify managing the operating system settings and the reports that are required for standards compliance.

The preconfigured compliance profiles delivered with the PowerSC Standard Edition reduce the administrative workload of interpreting compliance documentation and implementing those standards as specific system configuration parameters.

The capabilities of the PowerSC Standard Edition compliance expert feature are designed to help clients to effectively manage the system requirements, which are associated with external standard compliance that can potentially reduce costs while improving compliance. All external security standards include aspects other than the system configuration settings. The use of PowerSC Standard Edition compliance expert feature cannot ensure standards compliance. The PowerSC Standard Edition is designed to simplify the management of systems configuration setting that helps administrators to focus on other aspects of standards compliance.