Wednesday, June 08, 2005

Role reversal: Audit uncovers gaps in SEC's IT controls

The shoe is on the other foot at the U.S. Securities and Exchange Commission after an audit of the agency's 2004 financial statements revealed that the chief enforcer of the Sarbanes-Oxley Act had "numerous" information security control weaknesses of its own.

The audit, which was conducted last summer by the Government Accountability Office and published on May 26, found that the SEC "had not consistently implemented effective electronic access controls" around user accounts and passwords, access rights and permissions, and network security.

See full Article.