9 used & new from $45.00

Have one to sell? Sell yours here
 
 
Sarbanes-Oxley Compliance Using COBIT and Open Source Tools
 
 
Tell the Publisher!
I’d like to read this book on Kindle

Don’t have a Kindle? Get your Kindle here.
 
  

Sarbanes-Oxley Compliance Using COBIT and Open Source Tools [ILLUSTRATED] (Paperback)

~ Christian Lahti (Author), Roderick Peterson (Author), Steve Lanza (Contributor)
Key Phrases: control matrices, test plan, server room, Solutions Fast Track, Working the List, Help Desk (more...)
3.8 out of 5 stars  See all reviews (17 customer reviews)


Available from these sellers.


1 new from $115.99 8 used from $45.00
There is a newer edition of this item:
Sarbanes-Oxley IT Compliance Using Open Source Tools, Second Edition Sarbanes-Oxley IT Compliance Using Open Source Tools, Second Edition
$55.95
In Stock.
What Do Customers Ultimately Buy After Viewing This Item?

Customers Who Bought This Item Also Bought

Manager's Guide to Compliance: Sarbanes-Oxley, COSO, ERM, COBIT, IFRS, BASEL II, OMB's A-123, ASX 10, OECD Principles, Turnbull Guidance, Best Practices, and Case Studies (Manager's Guide Series)

Manager's Guide to Compliance: Sarbanes-Oxley, COSO, ERM, COBIT, IFRS, BASEL II, OMB's A-123, ASX 10, OECD Principles, Turnbull Guidance, Best Practices, and Case Studies (Manager's Guide Series)

by Anthony Tarantino
4.4 out of 5 stars (5)  $55.25
Information Technology Control and Audit, Third Edition

Information Technology Control and Audit, Third Edition

by Sandra Allen-Senft
4.8 out of 5 stars (92)  $71.96
Sarbanes-Oxley For Dummies

Sarbanes-Oxley For Dummies

by Jill Gilbert Welytok
4.6 out of 5 stars (24)  $14.95
CISA Certified Information Systems Auditor Study Guide

CISA Certified Information Systems Auditor Study Guide

by David L. Cannon
3.9 out of 5 stars (36)  $37.79
Security Controls for Sarbanes-Oxley Section 404 IT Compliance: Authorization, Authentication, and Access

Security Controls for Sarbanes-Oxley Section 404 IT Compliance: Authorization, Authentication, and Access

by Dennis C. Brewer
$43.59
Explore similar items

Editorial Reviews

Product Description

This book illustrates the many Open Source cost savings opportunities available to companies seeking Sarbanes-Oxley compliance. It also provides examples of the Open Source infrastructure components that can and should be made compliant. In addition, the book clearly documents which Open Source tools you should consider using in the journey towards compliance. Although many books and reference material have been authored on the financial and business side of Sox compliance, very little material is available that directly address the information technology considerations, even less so on how Open Source fits into that discussion.

Each chapter begins with an analysis of the business and technical ramifications of Sarbanes-Oxley as regards to topics covered before moving into the detailed instructions on the use of the various Open Source applications and tools relating to the compliance objectives.

The bootable CD contains fully configured demonstrations of Open Source tools.

* Shows companies how to use Open Source tools to achieve SOX compliance, which dramatically lowers the cost of using proprietary, commercial applications
* Contains a bootable-Linux CD containing countless applications, forms, and checklists to assist companies in achieving SOX compliance
* Only SOX compliance book specifically detailing steps to achieve SOX compliance for IT Professionals


From the Back Cover

This book illustrates the many Open Source cost savings opportunities available to companies seeking Sarbanes-Oxley compliance. It also provides examples of the Open Source infrastructure components that can and should be made compliant. In addition, the book clearly documents which Open Source tools you should consider using in the journey towards compliance. Although many books and reference material have been authored on the financial and business side of Sox compliance, very little material is available that directly address the information technology considerations, even less so on how Open Source fits into that discussion.

Each chapter begins with an analysis of the business and technical ramifications of Sarbanes-Oxley as regards to topics covered before moving into the detailed instructions on the use of the various Open Source applications and tools relating to the compliance objectives. The bootable CD contains fully configured demonstrations of Open Source tools.

Product Details

  • Paperback: 356 pages
  • Publisher: Syngress; 1 edition (August 1, 2005)
  • Language: English
  • ISBN-10: 1597490369
  • ISBN-13: 978-1597490368
  • Product Dimensions: 8.9 x 7 x 1.1 inches
  • Shipping Weight: 1.4 pounds
  • Average Customer Review: 3.8 out of 5 stars  See all reviews (17 customer reviews)
  • Amazon.com Sales Rank: #912,160 in Books (See Bestsellers in Books)

Inside This Book (learn more)

Tags Customers Associate with This Product

 (What's this?)
Click on a tag to find related items, discussions, and people.
 
(2)

Your tags: Add your first tag
 

Sell a Digital Version of This Book in the Kindle Store

If you are a publisher or author and hold the digital rights to a book, you can sell a digital version of it in our Kindle Store. Learn more

 

Customer Reviews

17 Reviews
5 star:
 (8)
4 star:
 (4)
3 star:
 (2)
2 star:    (0)
1 star:
 (3)
 
 
 
 
 
Average Customer Review
3.8 out of 5 stars (17 customer reviews)
 
 
 
 
Share your thoughts with other customers:
Most Helpful Customer Reviews

 
15 of 15 people found the following review helpful:
3.0 out of 5 stars Two books in one, October 21, 2005
By Stephen Northcutt (Kauai, HI USA) - See all my reviews
(REAL NAME)   
This is the hardest review I have ever written. The book has enormous potential. The concepts behind the book can probably save organizations a lot of money. The book is a primer to COBIT, which is the model most people use to implement Sarbanes-Oxley. It is also a book about open source tools that may be able to support a COBIT framework.

As a pointer to tools and ideas, you cannot beat this book. However, if you are not already a part of the Linux open source world, I don't think this book can get you there. I had trouble with the CD and had to use a Knoppix cheat code to get it to boot. In addition, the examples on the CD are not populated with enough data to let you play with the tools.

The bottom line, I think this has all the earmarks to become a really important book in the auditing and compliance world in its next edition. I have purchased a copy for every one of my students in my management class and I am flying the authors out to demonstrate the tools to my class. I honestly don't think you can afford to miss this book if you have responsibility for Sarbanes-Oxley or GLBA for that matter. However, you are going to have to find a Linux geek to actually put any of this into practice.
Comment Comment | Permalink | Was this review helpful to you? Yes No (Report this)



 
8 of 8 people found the following review helpful:
4.0 out of 5 stars Very helpful introduction to SOX compliance through COBIT, March 13, 2006
I read Sarbanes-Oxley IT Compliance Using COBIT and Open Source Tools (SOICUCAOST) to learn more about compliance issues. I am a security engineer who thankfully has not had to suffer through a SOX audit. I am glad I read SOICUCAOST, however. The book is clear, well-written, and makes innovative use of a live CD. While the book is not the answer to SOX compliance (no book is), small-to-medium-sized businesses will find SOICUCAOST a valuable guide.

I found SOICUCAOST's advice to be surprisingly candid. This is no "SOX is awesome" book. On p 276 we read "one could conclude that not only is there no realistic way to calculate ROI for SOX compliance, but if there were, there would be no positive ROI for SOX. The value of SOX compliance is qualitative and not quantitative. If there is no way to justify SOX compliance, how do I answer questions about how my company's compliance activities affect the bottom line? By shifting the ROI from SOX and the cost savings to open source and cost avoidance... a decision point of whether to comply with SOX or not does not exist." That is only one dose of brutal honesty -- there are many others in this book.

I thought the XFLD-based live CD was an innovative touch. Assuming one can get it to work (I had no trouble), it is a slick way to use a portal for two fictitious companies created to demonstrate ways to achieve IT-related SOX compliance. Not every component works, but using the live CD gets the reader to think he or she may be doing SOX activities instead of reading a book about it.

As far as specific open source tools goes, I don't think it's realistic to be able to use tools based on the information in this book. Syngress published an entire book on Nagios, an entire book on host-based integrity monitoring, an entire book on Snort, and so on. I would have preferred to see SOICUCAOST spend more time on presenting options with advantages and disadvantages for each. I also though the idea of running Snort from a live CD as a production sensor (Ch 6) to be very ill-conceived.

Regarding the reviews -- I am surprised to see they are all over the map. I think Christopher Byrne makes a few good points, but his criticism doesn't warrant a one-star review. Author Roderick Peterson should not have written a five-star "rebuttal". Authors write books, not reviews of their own books. That's poor form and it manipulates Amazon's star ratings.

Overall, I think SOICUCAOST is helpful for any SMB staring at SOX compliance. It certainly provides plenty of sound guidance, solid frameworks, and examples (on the live CD). The book is well-written and organized. I think some of the material could have been formatted for easier reading; Syngress has a tendency to use fonts that are way too large and thereby distracting. Still, I recommend anyone involved with IT-related SOX issues and/or COBIT give SOICUCAOST a try.
Comment Comment | Permalink | Was this review helpful to you? Yes No (Report this)



 
5 of 5 people found the following review helpful:
5.0 out of 5 stars ARE YOU IN COMPLIANCE??, July 22, 2006
Are you a CFO, CIO, CEO, VP, Director of IT, IT Operations Manager, and/or IT Consultant? If you are, then this book is for you! Authors Christian Lahti, Roderick Peterson, and Steve Lanza, have done an outstanding job of writing a practical book that gives you the reader, an understanding of how open source technology and tools might be applied to your individual requirements.

Lahti, Peterson, and Lanza, begin by discussing why the Sarbanes-Oxley (SOX) experience promises to be quite different in terms of depth, cost, and resources. Then, the authors discuss how Congress enacted the Sarbanes-Oxley Act of 2002 in an effort to prevent financial scandals such as those that occurred at Enron and MCI. Next, they explore the need for SOX compliance and the possible consequences of noncompliance--lawsuits, negative publicity for the company, and fines for executive management. The authors then investigate the entire open source phenomenon and the fundamental differences between it and nonfree software. They continue by covering the difference between SOX and COBIT. Then, the authors discuss automation and why it should be a key component of any small to medium-sized company's SOX compliance activities. Next, they cover the COBIT Delivery and Support Delivery and Support Domain and why it is important, not only to SOX compliance activities, but also from an IT Department repositioning perspective. The authors then discuss Deming's continuous quality improvement process, specifically how it was predicted on a closed-loop process. Finally, they show you how to reposition an IT Department, by utilizing COBIT for SOX.

In this most excellent book, you will find a lot of applicable content--basically as much as the authors could muster by way of open source technologies and how they fit into the SOX sphere of influence. More importantly, this book illustrates the many Open Source cost-saving opportunities that public companies can deploy in their IT organizations to meet the mandatory compliance requirements of SOX.
Comment Comment | Permalink | Was this review helpful to you? Yes No (Report this)


Share your thoughts with other customers: Create your own review
 
 
 
Most Recent Customer Reviews

3.0 out of 5 stars Could be better organized
The book does a fair job in describing the requirements of SOX.
However, it often only scratches the surface of SOX compliance, while spending a lot of time on seemingly... Read more
Published 2 months ago by I. Sfiligoi

4.0 out of 5 stars Open Source Compliance Using CobiT
This book is a winner. It is clever, and fresh, and offers some really great concepts and ideas for companies needing to, or wanting to (yes there is such a thing), comply with... Read more
Published on October 9, 2007 by Kenny McNees, CPA, CISSP, CISA...

1.0 out of 5 stars A waste of money.
If you are preparing for the CISA,do not waste your money on this book. Put your money towards the ISACA's study materials. Read more
Published on January 5, 2007 by FrugalMan

4.0 out of 5 stars Nice Resource on Sarbanes-Oxley Compliance
If you are a company or IT person that is responsible for keeping your company compliant with the Sarbanes-Oxley act of 2002, you owe it to yourself to pick up this book. Read more
Published on August 11, 2006 by Daniel McKinnon

5.0 out of 5 stars Great resource, very helpful in ensuring complying with SOX
Compliance with the Sarbanes-Oxley Act is a legal requirement for publicly traded companies. The problem with the Act is that it requires things like adequate internal control... Read more
Published on April 19, 2006 by Harold McFarland

5.0 out of 5 stars Great Book, Great Advice!!!!!
My company has been working hard to mitigate and resolve SOX audit concerns/items. Being the technical leader of our open systems environment I am very involved in how this will... Read more
Published on January 2, 2006 by UNIX/Linux Junkie

5.0 out of 5 stars Thank you Mr. Peterson
As a Program Manager on goverment contracts, being audited for many different areas is a way of life and always painful. Read more
Published on November 17, 2005 by Program Manager

5.0 out of 5 stars Been There .... Done it
This is a phenomenal book that I ever read. I am a Systems Admin working in IT and implementing SOX policies in our company. Before I read this book, I have no clue about SOX. Read more
Published on November 8, 2005 by Book Reader

5.0 out of 5 stars Authors' Rebuttal
As the authors of this book, we'd like to respond to Christopher Byrne's review of our book. We appreciate Christopher's time and attention paid to our book, but would like to... Read more
Published on October 27, 2005 by Roderick Peterson

4.0 out of 5 stars Sarbanes-Oxley IT Cmmpliance Using COBIT and Open Source Tools
This book strikes a perfect balance between the theory and application
necessary for any IT Organization to effectively start to address their
Sarbanes-Oxley... Read more
Published on October 20, 2005 by D. S

Only search this product's reviews



Customer Discussions

This product's forum
Discussion Replies Latest Post
No discussions yet

Ask questions, Share opinions, Gain insight
Start a new discussion
Topic:
First post:
Prompts for sign-in
 

Search Customer Discussions
Search all Amazon discussions
   



So You'd Like to...


Create a guide

Product Information from the Amapedia Community

Beta (What's this?)


Look for Similar Items by Category


Look for Similar Items by Subject

 

Feedback

If you need help or have a question for Customer Service, contact us.
 Would you like to update product info or give feedback on images?
Is there any other feedback you would like to provide?

Your comments can help make our site better for everyone.



Your Recent History

 (What's this?)

After viewing product detail pages or search results, look here to find an easy way to navigate back to pages you are interested in.