Jordan said:
Actually, that is exactly what I do as well. Unfortuantely, we are subject
to the SOX audits each year and they will rate us as "non-compliant" if we
do not change the passwords on all accounts every 90 days.
You misunderstand SOX. We were under that too until we were bought by a
different Parent Company that doesn't fall under SOX.
SOX does not demand a password change,...in fact SOX dictates next to
nothing about "specific" IT tasks. What they do is verify that you follow
proper IT Policy that that is established by *you*. So it is simply them
making sure that you do what you said you would do.
So the company needs to stablish a more specific password policy. Do not
say "We will change all passowrds...." because SOX will insist you change
all passwords,...you need to say "We will change all passwords *but*....."
and they will make sure that you do what you say and "Change all passwords
*but*...".
The primary thing SOX tries to accomplish is this:
1. Job Positions have specific duties and do not cross certain boundaries
with certain other jobs. This is primarily to prevent things like
Embesselment and other white-collar crime. For example a Sales person can
create a "order" but cannot approve the order,...while a Sales Manager can
approve an order but cannot create an order.
2. Business critical data is to be protected. But it does not dictate the
specific tasks of *how* it is protected. It is the responsibility of the
Company to "create" the tasks and the means to protect its data (without
shooting themselves in the foot),...and then the Auditiors make sure that
the compnay follows the "tasks and the means" that they said they would
follow. So the moral of that story is: "Don't make promises you can't
realistically keep". Think through the full ramifications of the policies
that the Company puts in place,...the auditors will expect you to follow
your policies.
So if the Company needs to "perfect" their policies,...then they need to get
their policies "perfected".
If you look up and actually read the SOX act you will find it to be very
short and that it says very little. I don't not believe the words "computer"
or "password" are even mentioned once.
--
Phillip Windell
www.wandtv.com
The views expressed, are my own and not those of my employer, or Microsoft,
or anyone else associated with me, including my cats.
-----------------------------------------------------