About Gene Kim

I've been researching high-performing technology organizations since 1999. I'm the multiple award-winning CTO, Tripwire founder, co-author of The DevOps Handbook, The Phoenix Project, and Visible Ops. I'm an DevOps Researcher, Theory of Constraints Jonah, a certified IS auditor and a rabid UX fan.

I am passionate about IT operations, security and compliance, and how IT organizations successfully transform from "good to great."

SEARCH BLOG
« Mobilizing The PCI Resistance, Part IV: When Bottom-Up SOX-404 Audits Go Bad. Really Bad. | Main | Mobilizing the PCI Resistance, Part II: First Let's Re-Examine The SOX-404 Problem... »
Wednesday
Jun162010

Mobilizing The PCI Resistance, Part III: Quantifying The Huge SOX-404 Problem...

Previously, I wrote in Part I about "Upset about the subjectivity and ambiguity in the PCI DSS compliance standards? My #BSides submission on the answer...", and in Part II, I wrote about the problems that management and auditors faced in 2005 and 2006 for the IT portions of SOX-404.

In Part III of this series, I will continue walking through the January 2006 GAIT summit slides, and show you the objective evidence that there was a real problem that needed to be solved, and our vision of what the solution was.


Jan 2006 GAIT discussion.jpg

The Damage Of Bottom-Up Auditing

Actually, let me rewind a bit.  I didn't realize it at the time, but in 2005, I heard a great presentation by Patrick Gunderman that hinted at the magnitude and scale of the SOX-404 IT audit problem. Back then a Senior Manager in the KPMG audit practice.  He showed a slide that blew me away.

KPMG Gunderman.jpg

gunderman IT findings 1.jpg

In the slide above, KPMG found that "The estimated percentage of deficiencies identified show IT controls accounting for the most (34 percent), followed distantly by revenue (13 percent), procure to pay (10 percent), and fixed assets (10 percent)."

What this means is that auditors were spending time digging around IT infrastructure, and finding lots of deficiencies.  Then for each one, management would either have to remediate, or argue with the auditors that it wasn't worth fixing, because an IT control failure would not result in an undetected material error.  Now, if the Enron and Worldcom failures were caused by rogue DBAs, then maybe this level of scrutiny was warranted.  But, something definitely doesn't seem right...

It’s estimated that as much as $3 billion was spent in the first year of SOX-404 to fix IT controls to remediate these findings. Ultimately, most of these findings were found not to be direct risks to accurate financial reports and did not result in a material weakness.  This is because they followed a bottom up versus a top-down, risk-based approach.

At the January 2006 GAIT Summit, we had publicly traded companies present how this problem was affecting them and their need for a better way.  Universally, they talked about the huge IT audit effort and fees associated with SOX-404 that was totally disproportionate to the risk.

These companies included (in no particular order), Goldman Sachs, Marathon Oil, Microsoft, Hewlett Packard, Chevron Phillips Chemical, Business Objects and so forth.

One of the most compelling data points was presented by Fawn Weaver at Intel.

fawn weaver intel IT audit effort.jpg

This slide shows how 50% of the SOX-404 compliance effort was IT-related, which was generating almost 80% of the findings.  Yet, none of those findings represented a real risk to an undetected material error.  (So again, why was all that work performed?  It shouldn't have been.)

In my next post, I will write about how bottom-up auditing happens and our vision behind GAIT.  Next, I will write about the politics of GAIT, and how we assembled the constituencies, what was in it for them, and how I learned to use one of the most valuable tools in my career.

All of this helps (at least, in my mind) inform the PCI problem statement, as well as the strategy of how we can solve it.

References (135)

References allow you to track sources for this article, as well as articles that were written in response to this article.
  • Response
    The most hard task facing volunteer arrangements is to mobilize the neighborhood also its resources for important endure. Accompanying economic tensions causing numerous non profits to diminish their budgets, it is flush extra crucial than already to consume the resources interior your community to guarantee the continued fame of your company. ...
  • Response
    Response: Neundenker
  • Response
    Response: Neundenker
  • Response
    Response: Zhou Hua
    Mobilizing The PCI Resistance, Part III: Quantifying The Huge SOX-404 Problem... - RealGeneKim Blog - Home page of RealGeneKim (Gene Kim): Tripwire founder and CTO, Visible Ops co-author, and more...
  • Response
    Mobilizing The PCI Resistance, Part III: Quantifying The Huge SOX-404 Problem... - RealGeneKim Blog - Home page of RealGeneKim (Gene Kim): Tripwire founder and CTO, Visible Ops co-author, and more...
  • Response
    Response: Anthony Alles
    Mobilizing The PCI Resistance, Part III: Quantifying The Huge SOX-404 Problem... - RealGeneKim Blog - Home page of RealGeneKim (Gene Kim): Tripwire founder and CTO, Visible Ops co-author, and more...
  • Response
    means of one hour in the fall so that you can gain another amount of daylight over the early on night time.
  • Response
    Response: veterans day 2014
    Tax withheld finance calculator. Toggle remaining... Contains the payee furnished some type of Tax File Sum (TFN)? Guaranteed; Simply no... Contains the payee mentioned your current Tax Free Endurance
  • Response
    Response: time change 2014
    Brightness Retaining Occasion – also known as "Summer Time", "DST" or perhaps "Daylight Individual benefits Time" – can be a method of creating outstanding usage of your current sunny days to weeks on the inside days to weeks.
  • Response
    A lot like your hard earned money Act in response 2013 okayed by way of Federal government linked with people, that over the web duty finance calculator can be applied tax charges having country.
  • Response
    Response: xbox live codes
    The third part is awesome!
  • Response
    Response: Lazaro Weeber
  • Response
    Response: superiorpaper
    Excellent resource for my job. Really your new superiorpaper tips are usually inspired personally, it is a extremely impressive essay paper writing, I proud it so much intended for giving your valuable thoughts and very well wished far more threads this superb essay writing threads.
  • Response
    Response: superiorpaper
    Excellent resource for my job. Really your new superiorpaper tips are usually inspired personally, it is a extremely impressive essay paper writing, I proud it so much intended for giving your valuable thoughts and very well wished far more threads this superb essay writing threads.
  • Response
    Response: taxes
    How avoid 1 taxslayer 49 regarding taxi calculation.
  • Response
  • Response
    The handy remote control includes a special code that's from the garage door opener once it really is programmed.
  • Response
  • Response
  • Response
    Response: iOS 11 features
    iOS 11
  • Response
    Fifa 18 release date
  • Response
    Response: Palem Seven
  • Response
    Response: Free online notes
  • Response
    Response: Click Here
  • Response
    Response: Free Infos Online
  • Response
  • Response
  • Response
  • Response
  • Response
    Response: video me pair kodi
  • Response
    Response: Paper Writing Help
  • Response
  • Response
  • Response
    Response: Garage Door Part
  • Response
  • Response
  • Response
  • Response
  • Response
  • Response
  • Response
    Response: Garage Door-Parts
  • Response
  • Response
  • Response
    Response: SEO
  • Response
    Response: niaga hoster
  • Response
  • Response
    Your post is well detailed and well understood. Of a truth, there are many of the points mentioned above am coming across for the first time but I clearly understand it. I hope someday you'll continue posting.
  • Response
  • Response
    Response: law essays
  • Response
  • Response
  • Response
  • Response
    Response: Dissertation help
    Thanks for posting.
  • Response
  • Response
  • Response
    good
  • Response
  • Response
  • Response
    Response: Essay Help Online
  • Response
    Response: Term paper site
  • Response
  • Response
  • Response
  • Response
  • Response
  • Response
  • Response
    Great interesting blog and here are different artists are talking with one and others
  • Response
  • Response
  • Response
    Response: sharepoint design
    sharepoint design
  • Response
    If you are looking 12v submersible pump.
  • Response
    Response: Cable Tv
  • Response
    Response: Mass Texting
  • Response
    Response: Text Blast
  • Response
    Response: Online cricket id
  • Response
    Response: online betting id
  • Response
    Response: Max Net Homes
  • Response
  • Response
  • Response
  • Response
  • Response
  • Response
  • Response
  • Response
    Behti Hawa Sa Tha Woh Lyrics from 3 Idiots is Hindi song sung by Shaan, Shantanu Moitra and music is given by Shantanu Moitra. Behti Hawa Sa Tha Woh song lyrics are written by Swanand Kirkire.
  • Response
    Response: Microsoft project
    Celoxis is the Best Alternative to Microsoft Project. Microsoft Project has a number of problems. It is too complex for most teams, lacks collaboration and integrates only with other Microsoft Solutions.
  • Response
  • Response
    Response: criminal appeals
  • Response
    American Lifeguard Events
  • Response
    Response: Lifeguard class
  • Response
  • Response
  • Response
    At Digital Monk, we offer a full spectrum of Digital Marketing & SEO services in Calgary which can be customized to fit your needs.
  • Response
    Boost your IT Project Management with Celoxis. Effortlessly track task assignments, expenses, and progress in application development.
  • Response
  • Response
    Tuskr integrates with all the popular issue tracking, time tracking, and messaging applications. Using our API and webhooks you can build your own integrations easily.
  • Response
    Response: Logo Design
  • Response
  • Response
  • Response
    Response: Web Development
  • Response
    American Lifeguard Association
  • Response
    Response: water land
  • Response
  • Response
  • Response
  • Response
    Response: Order pizza online
  • Response
  • Response
    Mobilizing The PCI Resistance, Part III: Quantifying The Huge SOX-404 Problem... - RealGeneKim Blog - Home page of RealGeneKim (Gene Kim): Tripwire founder and CTO, Visible Ops co-author, and more...
  • Response
    Response: What is rice
    Mobilizing The PCI Resistance, Part III: Quantifying The Huge SOX-404 Problem... - RealGeneKim Blog - Home page of RealGeneKim (Gene Kim): Tripwire founder and CTO, Visible Ops co-author, and more...
  • Response
    Response: Related Site
    Mobilizing The PCI Resistance, Part III: Quantifying The Huge SOX-404 Problem... - RealGeneKim Blog - Home page of RealGeneKim (Gene Kim): Tripwire founder and CTO, Visible Ops co-author, and more...
  • Response
    Response: nasal spray
    Mobilizing The PCI Resistance, Part III: Quantifying The Huge SOX-404 Problem... - RealGeneKim Blog - Home page of RealGeneKim (Gene Kim): Tripwire founder and CTO, Visible Ops co-author, and more...
  • Response
    Mobilizing The PCI Resistance, Part III: Quantifying The Huge SOX-404 Problem... - RealGeneKim Blog - Home page of RealGeneKim (Gene Kim): Tripwire founder and CTO, Visible Ops co-author, and more...
  • Response
    Response: What is rice
    Mobilizing The PCI Resistance, Part III: Quantifying The Huge SOX-404 Problem... - RealGeneKim Blog - Home page of RealGeneKim (Gene Kim): Tripwire founder and CTO, Visible Ops co-author, and more...
  • Response
    Response: explanation
    Mobilizing The PCI Resistance, Part III: Quantifying The Huge SOX-404 Problem... - RealGeneKim Blog - Home page of RealGeneKim (Gene Kim): Tripwire founder and CTO, Visible Ops co-author, and more...
  • Response
    Response: next page
    Mobilizing The PCI Resistance, Part III: Quantifying The Huge SOX-404 Problem... - RealGeneKim Blog - Home page of RealGeneKim (Gene Kim): Tripwire founder and CTO, Visible Ops co-author, and more...
  • Response
    Response: What is rice
    Mobilizing The PCI Resistance, Part III: Quantifying The Huge SOX-404 Problem... - RealGeneKim Blog - Home page of RealGeneKim (Gene Kim): Tripwire founder and CTO, Visible Ops co-author, and more...
  • Response
    Response: Read Even more
    Mobilizing The PCI Resistance, Part III: Quantifying The Huge SOX-404 Problem... - RealGeneKim Blog - Home page of RealGeneKim (Gene Kim): Tripwire founder and CTO, Visible Ops co-author, and more...
  • Response
    Mobilizing The PCI Resistance, Part III: Quantifying The Huge SOX-404 Problem... - RealGeneKim Blog - Home page of RealGeneKim (Gene Kim): Tripwire founder and CTO, Visible Ops co-author, and more...
  • Response
    Mobilizing The PCI Resistance, Part III: Quantifying The Huge SOX-404 Problem... - RealGeneKim Blog - Home page of RealGeneKim (Gene Kim): Tripwire founder and CTO, Visible Ops co-author, and more...
  • Response
    Response: What is rice
    Mobilizing The PCI Resistance, Part III: Quantifying The Huge SOX-404 Problem... - RealGeneKim Blog - Home page of RealGeneKim (Gene Kim): Tripwire founder and CTO, Visible Ops co-author, and more...
  • Response
    Mobilizing The PCI Resistance, Part III: Quantifying The Huge SOX-404 Problem... - RealGeneKim Blog - Home page of RealGeneKim (Gene Kim): Tripwire founder and CTO, Visible Ops co-author, and more...
  • Response
    Mobilizing The PCI Resistance, Part III: Quantifying The Huge SOX-404 Problem... - RealGeneKim Blog - Home page of RealGeneKim (Gene Kim): Tripwire founder and CTO, Visible Ops co-author, and more...
  • Response
    Response: a knockout post
    Mobilizing The PCI Resistance, Part III: Quantifying The Huge SOX-404 Problem... - RealGeneKim Blog - Home page of RealGeneKim (Gene Kim): Tripwire founder and CTO, Visible Ops co-author, and more...
  • Response
    Response: Going On this site
    Mobilizing The PCI Resistance, Part III: Quantifying The Huge SOX-404 Problem... - RealGeneKim Blog - Home page of RealGeneKim (Gene Kim): Tripwire founder and CTO, Visible Ops co-author, and more...
  • Response
    Response: linktr.ee
    Mobilizing The PCI Resistance, Part III: Quantifying The Huge SOX-404 Problem... - RealGeneKim Blog - Home page of RealGeneKim (Gene Kim): Tripwire founder and CTO, Visible Ops co-author, and more...
  • Response
    Response: What is rice
    Mobilizing The PCI Resistance, Part III: Quantifying The Huge SOX-404 Problem... - RealGeneKim Blog - Home page of RealGeneKim (Gene Kim): Tripwire founder and CTO, Visible Ops co-author, and more...
  • Response
    Response: What is rice
    Mobilizing The PCI Resistance, Part III: Quantifying The Huge SOX-404 Problem... - RealGeneKim Blog - Home page of RealGeneKim (Gene Kim): Tripwire founder and CTO, Visible Ops co-author, and more...
  • Response
    Mobilizing The PCI Resistance, Part III: Quantifying The Huge SOX-404 Problem... - RealGeneKim Blog - Home page of RealGeneKim (Gene Kim): Tripwire founder and CTO, Visible Ops co-author, and more...
  • Response
    Response: Be5 Health
    Mobilizing The PCI Resistance, Part III: Quantifying The Huge SOX-404 Problem... - RealGeneKim Blog - Home page of RealGeneKim (Gene Kim): Tripwire founder and CTO, Visible Ops co-author, and more...
  • Response
    Response: Learn Additional
    Mobilizing The PCI Resistance, Part III: Quantifying The Huge SOX-404 Problem... - RealGeneKim Blog - Home page of RealGeneKim (Gene Kim): Tripwire founder and CTO, Visible Ops co-author, and more...
  • Response
    Mobilizing The PCI Resistance, Part III: Quantifying The Huge SOX-404 Problem... - RealGeneKim Blog - Home page of RealGeneKim (Gene Kim): Tripwire founder and CTO, Visible Ops co-author, and more...
  • Response
    Response: What is rice
    Mobilizing The PCI Resistance, Part III: Quantifying The Huge SOX-404 Problem... - RealGeneKim Blog - Home page of RealGeneKim (Gene Kim): Tripwire founder and CTO, Visible Ops co-author, and more...
  • Response
    Mobilizing The PCI Resistance, Part III: Quantifying The Huge SOX-404 Problem... - RealGeneKim Blog - Home page of RealGeneKim (Gene Kim): Tripwire founder and CTO, Visible Ops co-author, and more...
  • Response
    Response: navigate here
    Mobilizing The PCI Resistance, Part III: Quantifying The Huge SOX-404 Problem... - RealGeneKim Blog - Home page of RealGeneKim (Gene Kim): Tripwire founder and CTO, Visible Ops co-author, and more...
  • Response
    Response: this site
    Mobilizing The PCI Resistance, Part III: Quantifying The Huge SOX-404 Problem... - RealGeneKim Blog - Home page of RealGeneKim (Gene Kim): Tripwire founder and CTO, Visible Ops co-author, and more...

Reader Comments

There are no comments for this journal entry. To create a new comment, use the form below.

PostPost a New Comment

Enter your information below to add a new comment.

My response is on my own website »
Author Email (optional):
Author URL (optional):
Post:
 
Some HTML allowed: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <code> <em> <i> <strike> <strong>