SOA in a SOX compliant environment

I’m looking for examples / case studies where SOA has been implemented within the context of SOX specific governance architectures.

Does anyone have any references and/or examples from workplace where you’ve seen this first hand?

Re: SOA in a SOX compliant environment

SOA?? Whats SOA?? Is it a software or what?

Re: SOA in a SOX compliant environment

^ lol

Re: SOA in a SOX compliant environment

Faisal,

SOA is Services Oriented Architecture which basically refers to an approach to the transmission of data among various business processes irrespective of their underlying technology platforms. The services are often made interoperable using a common interface definition such as Web Services.

Re: SOA in a SOX compliant environment

Think I may be misunderstanding, but here’s such an article:

http://wistechnology.com/article.php?id=2914

I work for a software vendor in the SOX space, but we’ve stayed clear of SOA so far…

Re: SOA in a SOX compliant environment

UT, I have a pdf doc that shows emerging threats and their mitigations for SOA... I can send it to you... and then you can match up the relevant SOX components :D

Let me know if you want the doc.

Re: SOA in a SOX compliant environment

^ Kaleem, I just sent you a PM.

Thanks Picoico... I have that article already... and the subject matter that I'm interested in is related to what that article summarizes. I'm just interested in real-world examples or more elaborate best practices.

Re: SOA in a SOX compliant environment

For me SOA is Start of Authority (DNS). :)

Re: SOA in a SOX compliant environment

Umar,

Doucment sent to the e-mail address you provided. Let me know if it helps in your quest.

Re: SOA in a SOX compliant environment

I thought SOX was Sarbanes Oxley act. Let me read a bit more about SOA as it seems we have a similar information sharing architechure in our organization.

Re: SOA in a SOX compliant environment

I think the author of the linked article is being paranoid. The situation of SOX/SOA is similar to running anti-virus on a machine connected to internet. The risk is there if you don't take any action. A systematic, informed approach to implementation is required to achieve this. Our organization is using a similar approach since the SOX was enforced on the US listed companies in 2005.

Re: SOA in a SOX compliant environment

I have not read the article but it looks like a match by a quick glance.

http://msdn2.microsoft.com/en-us/library/bb266338.aspx