(no subject)
Jul. 19th, 2006 12:31 pmForgive me Boss-Man for I have sinned. I have transgressed against the Gods of SOX. I, in my role of Local Sys Admin, did disable a user's account when they quit rather than wait for the authorities on high to issue a summons to the Desk of Help. I, in my foolish pride, did put security of my local network above bureaucratic nonsense and therefore did disable said account 5 days earlier than it would have been had proper SOX protocols been followed. Verily, Boss-Man, what is my penance for my transgressions?
Any of the rest of you have to put up with all this pain-in-the-SOX nonsense?
Any of the rest of you have to put up with all this pain-in-the-SOX nonsense?
no subject
Date: 2006-07-19 05:43 pm (UTC)no subject
Date: 2006-07-19 05:46 pm (UTC)Now, beyond that, http://en.wikipedia.org/wiki/Sarbanes-Oxley_Act
no subject
Date: 2006-07-19 05:53 pm (UTC)no subject
Date: 2006-07-19 05:51 pm (UTC)no subject
Date: 2006-07-19 06:00 pm (UTC)no subject
Date: 2006-07-19 06:04 pm (UTC)no subject
Date: 2006-07-19 05:44 pm (UTC)no subject
Date: 2006-07-19 05:54 pm (UTC)FOrtuately, the company I'm at now IIRC does not need to comply with either law, but instead has an entirely different set of rules to ply by which are almost as bad.
no subject
Date: 2006-07-19 06:16 pm (UTC)no subject
Date: 2006-07-19 07:54 pm (UTC)no subject
Date: 2006-07-19 11:15 pm (UTC)Truly.
I just open this form here.... print it out, and begin filling in all of the data, printing out documents and emails and other electronic documents to paper to paper clip, staple and attach to this form, and fill out more of the data, repeating the process, and when I'm done...
... store it in a box at Iron Mountain with other documents from this wonderful project/product launch where no-one will see all of my hard effort in documenting, and the box will be destroyed seven years from now, or whenever I deem its time on earth as mass to be final, whereby it will be destroyed through whatever means Iron Mountain uses to destroy. In destroying the box, I hope it will go through the scientific process and become heat, thereby creating greenhouse gasses and destroying the ozone.
Oh, nuts, I forgot to document in the SOX-doc when the box at Iron Mountain should be destroyed. Should I've?
no subject
Date: 2006-07-20 08:11 am (UTC)Do not offer opinions in the note as to whether the company's security should be good or bad. Merely list the problems that the policy will cause. That way, when the crap hits the fan, you have your documentation saying that you noted the problem and reported it, but did not have the authority to fix it.
no subject
Date: 2006-07-20 12:26 pm (UTC)I used to get users calling me all the time, "It says this computer has been locked by so and so and that YOU can unlock it!" "No, it doesn't, it says an administrator can, and I'm not that kind of administrator. Reboot the computer." "ARE YOU SURE?" "YES." "OH MY GOD, I WAS ABLE TO LOGIN!" heh.
no subject
Date: 2006-07-20 04:29 pm (UTC)SOX imposes harsh penalties for even the smallest infractions. Under SOX, what you did puts the future of the company in severe jeopardy, and puts the executives at risk of facing serious criminal charges.
Furthermore, by taking matters into your own hands, you obfuscated the jackassery that is SOX.
Had you let the SOX process run its course, and your network had been hax0r3d as a result, that could have been added to the List of Reasons Why SOX is Bad for the Economy and Whatnot.
Instead, you hid the true cost of SOX from the world, while simultaneously griefing your senior management, risking your own job security, and risking the job security of everybody else at the company (on account of SOX violations generally causing large fines, reduced consumer confidence in your company, and negative analyst reports about your company). Is that really what you had in mind?