Publisher: Syngress Pub Date: September 2005 Print ISBN-10: 1-59749
Total Page:16
File Type:pdf, Size:1020Kb
This document was created by an unregistered ChmMagic, please go to http://www.bisenter.com to register it. Thanks. Sarbanes-Oxley IT Compliance Using COBIT and Open Source Tools By Christian Lahti, Steve Lanza, Roderick Peterson ............................................... Publisher: Syngress Pub Date: September 2005 Print ISBN-10: 1-59749-036-9 Print ISBN-13: 978-1-59-749036-8 Pages: 450 Table of Contents | Index A Toolkit for IT Professionals Whether you work for a publicly traded or pre-IPO company or as an IT consultant, you are familiar with the daunting task of complying with the Sarbanes-Oxley Act. You have no doubt seen the hour and dollar estimates for compliance go up and up. With this book, you can now regain control of your budget and schedule. This ground-breaking, fully integrated book and bootable "live" CD provide all the information and the Open Source tools for you to use to achieve IT SOX compliance. This book illustrates the many Open Source cost-saving opportunities that public companies can deploy in their IT organizations to meet the mandatory compliance requirements of the Sarbanes-Oxley Act. Streamline IT SOX Compliance Using the Live CD: Use the tools on the bootable Linux CD to automate and manage workflow, disseminate information, track projects, manage groups, and much more. Understand the Liability of Noncompliance: Learn the penalties associated with noncompliance resulting from both intentional and unintentional filing of an inaccurate certification. Deploy COBIT Standards and Best-Known Methods (BKMs) in Your Organization: Master the six components of COBIT: Executive summary, framework, control objective, control practices, management guidelines, and audit guidelines. Create an IT SOX Compliance Policy: Learn to write, implement, and enforce an effective IT compliance policy that will be supported by both users and management. Realize the Benefits of Open Source Tools: Deploy Open Source applications throughout your enterprise to reduce cost and improve security. Plan and Organize Your COBIT Strategy: Develop strategic IT plans that support business objectives and can stand the test of time. Acquire Requisite Applications and Implement Your Plan: Ensure that you have the right people, skills, and tools to implement, test, certify, and maintain both existing and newly developed systems. Deliver and Support New Systems: Ensure that new systems perform as expected upon implementation and that they continue to perform in accordance with established expectations. Monitor the Progress of Your COBIT Deployment: Use service level agreements (SLAs) or established baselines to quantify performance against expectations and proactively troubleshoot problems. This document was created by an unregistered ChmMagic, please go to http://www.bisenter.com to register it. Thanks. Sarbanes-Oxley IT Compliance Using COBIT and Open Source Tools By Christian Lahti, Steve Lanza, Roderick Peterson ............................................... Publisher: Syngress Pub Date: September 2005 Print ISBN-10: 1-59749-036-9 Print ISBN-13: 978-1-59-749036-8 Pages: 450 Table of Contents | Index Copyright Acknowledgments Authors Contributors Author Acknowledgments Chapter 1. Overview: The Goals of This Book Section 1.1. The Audit Experience: An Introduction Section 1.2. Who Should Read This Book? Section 1.3. The Live CD Concept Section 1.4. The Portals Section 1.5. Summary Section 1.6. Solutions Fast Track Section 1.7. Frequently Asked Questions Chapter 2. SOX and COBIT Defined Section 2.1. SOX Overview Section 2.2. Why IT COBIT? Section 2.3. Are the Developers of COBIT Controls Crazy? Is This Practical? Section 2.4. Sustainability Is the Key Section 2.5. Summary Section 2.6. Solutions Fast Track Section 2.7. Frequently Asked Questions Chapter 3. The Cost of Compliance Section 3.1. Overview Section 3.2. Why Comply? Section 3.3. Tools and Applications Section 3.4. The Human Factor Section 3.5. Walk the Walk Section 3.6. BuiltRight Construction Company Section 3.7. Summary Section 3.8. Solutions Fast Track Section 3.9. Frequently Asked Questions Chapter 4. Why Open Source? Section 4.1. The Open Source Model Section 4.2. Closed Source Application Development Section 4.3. Open Source Application Development Section 4.4. The Business Case for Open Source Section 4.5. Assessing Your Infrastructure Section 4.6. Case Studies: Introduction to the Sample Companies This document was created by an unregistered ChmMagic, please go to http://www.bisenter.com to register it. Thanks. Section 4.7. Summary Section 4.8. Solutions Fast Track Section 4.9. Frequently Asked Questions Chapter 5. Domain I: Planning and Organization Section 5.1. Overview Section 5.2. The Work Starts Here Section 5.3. What Work? Section 5.4. What Do Planning and Organization Mean? Section 5.5. Working the List Section 5.6. NuStuff Electronics Inc. Section 5.7. FastTrack CD Section 5.8. Policy Management Section 5.9. Summary Section 5.10. Solutions Fast Track Section 5.11. Frequently Asked Questions Chapter 6. Domain II: Acquisition and Implementation Section 6.1. Overview Section 6.2. Evaluating In-House Expertise Section 6.3. Automation Is the Name of the Game Section 6.4. What Do Acquisition and Implementation Mean? Section 6.5. Working the List Section 6.6. FastTrack CD Section 6.7. Summary Section 6.8. Solutions Fast Track Section 6.9. Frequently Asked Questions Chapter 7. Domain III: Delivery and Support Section 7.1. Overview Section 7.2. What Do Delivery and Support Mean? Section 7.3. Working the List Section 7.4. Performance, Capacity, and SLAs Section 7.5. System and Application Security Section 7.6. Configuration and Data Management Section 7.7. FastTrack CD Section 7.8. Summary Section 7.9. Solutions Fast Track Section 7.10. Frequently Asked Questions Chapter 8. Domain IV: Monitoring Section 8.1. Overview Section 8.2. What Does Monitoring Mean? Section 8.3. Working the List Section 8.4. Monitoring in Practice Section 8.5. FastTrack CD Section 8.6. Rolling Your Own Workflows Section 8.7. Summary Section 8.8. Solutions Fast Track Section 8.9. Frequently Asked Questions Chapter 9. Putting It All Together Section 9.1. Overview Section 9.2. OrganizationRepositioning Section 9.3. Policies, Processes, and Service Level Agreements (SLAs) Section 9.4. Control Matrices, Test Plan, and Components Section 9.5. Return on Investment (ROI) This document was created by an unregistered ChmMagic, please go to http://www.bisenter.com to register it. Thanks. Section 9.6. Summary Section 9.7. Solutions Fast Track Section 9.8. Frequently Asked Questions Appendix A. COBIT Control Objectives Section A.1. Planning and Organization Section A.2. Acquisition and Implementation Section A.3. Delivery and Support Section A.4. Monitoring Appendix B. KNOPPIX Live CD Parameters Section B.1. Cheat Codes Section B.2. Kernels Appendix C. The GNU General Public License Section C.1. Version 2, June 1991 Section C.2. Terms and Conditions for Copying, Distribution and Modification Appendix D. CD Contents at a Glance Section D.1. Main Toolbar Section D.2. BuiltRight Construction Site Index Section D.3. NuStuff Electronics Site Index Index This document was created by an unregistered ChmMagic, please go to http://www.bisenter.com to register it. Thanks . Syngress Publishing, Inc., the author(s), and any person or firm involved in the writing, editing, or production (collectively "Makers") of this book ("the Work") do not guarantee or warrant the results to be obtained from the Work. There is no guarantee of any kind, expressed or implied, regarding the Work or its contents. The Work is sold AS IS and WITHOUT WARRANTY. You may have other legal rights, which vary from state to state. In no event will Makers be liable to you for damages, including any loss of profits, lost savings, or other incidental or consequential damages arising out from the Work or its contents. Because some states do not allow the exclusion or limitation of liability for consequential or incidental damages, the above limitation may not apply to you. You should always use reasonable care, including backup and other appropriate precautions, when working with computers, networks, data, and files. Syngress Media®, Syngress®, "Career Advancement Through Skill Enhancement®," "Ask the Author UPDATE®," and "Hack Proofing®," are registered trademarks of Syngress Publishing, Inc. "Syngress:The Definition of a Serious Security Library"™, "Mission Critical™," and "The Only Way to Stop a Hacker is to Think Like One™" are trademarks of Syngress Publishing, Inc. Brands and product names mentioned in this book are trademarks or service marks of their respective companies. This book includes excerpts from COBIT 3rd Edition, which is used by permission of the IT Governance Institute. ©1996, 1998, 2000 IT Governance Institute (ITGI). All rights reserved. COBIT is a registered trademark of the Information Systems Audit and Control Association and the IT Governance Institute. KEY SERIAL NUMBER 001 HJIRTCV764 002 PO9873D5FG 003 829KM8NJH2 004 GHJ87DRPL4 005 CVPLQ6WQ23 006 VBP965T5T5 007 HJJJ863WD3E 008 2987GVTWMK 009 629MP5SDJT 010 IMWQ295T6T PUBLISHED BY Syngress Publishing, Inc. 800 Hingham Street Rockland, MA 02370 This document was created by an unregistered ChmMagic, please go to http://www.bisenter.com to register it. Thanks. Sarbanes-Oxley IT Compliance Using COBIT and Open Source Tools Copyright © 2005 by Syngress Publishing, Inc. All rights reserved. Printed in the United States of America. Except as permitted under the Copyright Act of 1976, no part of this publication may be reproduced or distributed in any form or by any means, or stored in a database or retrieval system, without the prior written permission of the publisher, with the exception that the program listings may be entered, stored, and executed in a computer system, but they may not be reproduced for publication. Printed in the United States of America 1 2 3 4 5 6 7 8 9 0 ISBN: 1-59749-036-9 Table Publisher: Andrew Williams Page Layout and Art: Patricia Lupien Acquisitions Editor: Gary Byrne Copy Editors: Beth Roberts and Judy Eby Cover Designer: Michael Kavish Indexer: J.