9
Chapter 1:
The Business of Networking
Accordingly, network administrators for publicly traded companies will need
to work closely with their accounting departments to comply with the SOX 404
requirements on an ongoing basis. Doing so will include activities such as the
following:
Documentation of all user account creation, maintenance, and deactivation
activities, including appropriate sign-offs for new, changed, and terminated
users of in-scope systems
Creation of a change-control system for any system that the company modifies
from time to time, such as an accounting system for which the company uses
custom-developed reports or processing programs
Documentation of the security settings of the network
Documentation of the security settings and user account and password
management of the in-scope systems
Documentation of routine maintenance activities for in-scope systems
Collaboration with the accounting staff and the auditors to prove that all of the
controls that are in place are being followed, without exceptions
Creation and maintenance of systems (even manual procedural systems) to
detect unauthorized changes to any in-scope systems
Obviously, a book about networking cannot fully address all of the factors involved
in Sarbanes-Oxley compliance. You should, however, have a general idea of what it
is and what is involved. The accounting professionals charged with this important
requirement will have more detailed information about the exact steps required for
your company.
Chapter Summary
Many people I've met who work in some area of information technology, such as
networking, don't consider the business reasons for the network when they go about
their day-to-day jobs or when they propose improvements to the network. This
certainly isn't limited to the field of networking; many people who work in any area
of a company sometimes forget that the reason their function exists is to support the
objectives of the company in which they work. The most successful employees of any
company keep firmly in mind why they do what they do, before they consider how
best to do it. Some of the suggestions in this chapter should help you to approach
managing and improving a network successfully, by keeping in mind the benefits
the network brings to the company. Once you know what the company needs, you
can then propose the best solutions to solve problems that arise or make appropriate
improvements to the network.