-
1
-
-
0041957197
-
-
Addison-Wesley, New York, NY
-
Alberts, C. and Dorofee, A. (2002), Managing Information Security Risks: The OCTAVE Approach, Addison-Wesley, New York, NY.
-
(2002)
Managing Information Security Risks: The OCTAVE Approach
-
-
Alberts, C.1
Dorofee, A.2
-
4
-
-
33645608264
-
"SOA compliance: Will IT sabotage your efforts?"
-
Wiley Periodicals, Inc, published online in Wiley InterScience, available at: www.interscience.wiley.com
-
Cannon, D. and Growe, G. (2004), "SOA compliance: Will IT sabotage your efforts?", Wiley Periodicals, Inc, published online in Wiley InterScience, available at: www.interscience.wiley.com.
-
(2004)
-
-
Cannon, D.1
Growe, G.2
-
5
-
-
33645607057
-
"Sarbanes-Oxley: The IT dimension"
-
Chan, S. (2004), "Sarbanes-Oxley: The IT dimension", The Internal Auditor, Vol. 61 No. 1, pp. 31-3.
-
(2004)
The Internal Auditor
, vol.61
, Issue.1
, pp. 31-33
-
-
Chan, S.1
-
6
-
-
84870959483
-
"A Delphi examination of public sector ERP implementation issues"
-
Information System Management Research Centre, Faculty of Information Technology, Queensland University of Technology, Brisbane
-
Chang, S., Gable, G., Smythe, E. and Timbrell, G. (2000), "A Delphi examination of public sector ERP implementation issues", Proceedings of the Twenty First International Conference on Information Systems, Information System Management Research Centre, Faculty of Information Technology, Queensland University of Technology, Brisbane, pp. 494-500.
-
(2000)
Proceedings of the Twenty First International Conference on Information Systems
, pp. 494-500
-
-
Chang, S.1
Gable, G.2
Smythe, E.3
Timbrell, G.4
-
7
-
-
33645607311
-
"EXP research: Sarbanes-Oxley 2004: Are you ready to comply?"
-
CIO Insight/Gartner, available at: www.cioinsight.com
-
CIO Insight/Gartner (2004), "EXP research: Sarbanes-Oxley 2004: are you ready to comply?", available at: www.cioinsight.com.
-
(2004)
-
-
-
8
-
-
9144267776
-
"Sarbanes-Oxley: Pain or gain?"
-
Cobb, C.G. (2004), "Sarbanes-Oxley: Pain or gain?", Quality Progress, Vol. 37 No. 11, pp. 48-52.
-
(2004)
Quality Progress
, vol.37
, Issue.11
, pp. 48-52
-
-
Cobb, C.G.1
-
9
-
-
12344257332
-
"A comparison of internal controls: COBIT, SAC, COSO and SAS 55/78"
-
Colbert, J. and Bowen, P. (1996), "A comparison of internal controls: COBIT, SAC, COSO and SAS 55/78", IS Audit & Control Journal, Vol. 4, pp. 26-35.
-
(1996)
IS Audit & Control Journal
, vol.4
, pp. 26-35
-
-
Colbert, J.1
Bowen, P.2
-
10
-
-
33645592762
-
"FAQs, for COSO's enterprise risk management - Integrated framework"
-
COSO, available at: www.coso.org/Publications/ERM/erm_faq.htm
-
COSO (2005), "FAQs, for COSO's enterprise risk management - Integrated framework", available at: www.coso.org/Publications/ ERM/erm_faq.htm.
-
(2005)
-
-
-
11
-
-
10244236477
-
"Sarbanes-Oxley and IT governance: New guidance and IT control and compliance"
-
Winter
-
Damianides, M. (2005), "Sarbanes-Oxley and IT governance: New guidance and IT control and compliance", Information Systems Management, Winter.
-
(2005)
Information Systems Management
-
-
Damianides, M.1
-
12
-
-
33645593178
-
-
META Group, Stamford, CT, available at: www.metagroup.com
-
Decker, S. and Lepeak, S. (2003), Connecting to ERP for SOX 404 Assessments, META Group, Stamford, CT, available at: www.metagroup.com.
-
(2003)
Connecting to ERP for SOX 404 Assessments
-
-
Decker, S.1
Lepeak, S.2
-
13
-
-
33645586835
-
"Maximizing the value of ERP enabled processes"
-
Deloitte & Touche, 18 January
-
Deloitte & Touche (1999), "Maximizing the value of ERP enabled processes", The Review, 18 January.
-
(1999)
The Review
-
-
-
14
-
-
0003674946
-
-
Deloitte Consulting, Deloitte Consulting, Atlanta, GA
-
Deloitte Consulting (1999), ERP's Second Wave, Deloitte Consulting, Atlanta, GA.
-
(1999)
ERP's Second Wave
-
-
-
15
-
-
33645591692
-
"What will you do in Sarbanes-Oxley's second year?"
-
Dittmar, L. (2004), "What will you do in Sarbanes-Oxley's second year?", Financial Executive, Vol. 20 No. 8, pp. 17-18.
-
(2004)
Financial Executive
, vol.20
, Issue.8
, pp. 17-18
-
-
Dittmar, L.1
-
16
-
-
12344251332
-
"Adoption and usage patterns of COBIT: Results from a survey of COBIT purchasers"
-
Fedorowicz, J. and Ulric, J. (1998), "Adoption and usage patterns of COBIT: Results from a survey of COBIT purchasers", Information Systems Audit & Control Journal, Vol. 6, pp. 45-51.
-
(1998)
Information Systems Audit & Control Journal
, vol.6
, pp. 45-51
-
-
Fedorowicz, J.1
Ulric, J.2
-
17
-
-
33645584337
-
"Under the gun"
-
Garretson, C. (2003), "Under the gun", Network World, Vol. 20 No. 35, p. 38.
-
(2003)
Network World
, vol.20
, Issue.35
, pp. 38
-
-
Garretson, C.1
-
18
-
-
0003850551
-
"The IDEAL model: A practical guide for improvement"
-
Carnegie Melon Software Engineering Institute, available at: www.sei.cmu. edu/ideal/ideal.bridge.html
-
Gremba, J. and Myers, G. (2005), "The IDEAL model: A practical guide for improvement", Carnegie Melon Software Engineering Institute, available at: www.sei.cmu.edu/ideal/ideal.bridge.html.
-
(2005)
-
-
Gremba, J.1
Myers, G.2
-
19
-
-
12344329000
-
"Control and governance maturity survey: Establishing a reference benchmark and a self-assessment tool"
-
Guldentops, E., Van Grembergen, W. and De Haes, S. (2002), " Control and governance maturity survey: Establishing a reference benchmark and a self-assessment tool", Information Systems Control Journal, Vol. 6, pp. 32-5.
-
(2002)
Information Systems Control Journal
, vol.6
, pp. 32-35
-
-
Guldentops, E.1
Van Grembergen, W.2
De Haes, S.3
-
21
-
-
33645593177
-
-
Forrester Research, Cambridge, MA, available at: www.forrester.com
-
Hamerman, P., Markham, R., Orlov, L. and Teubner, C. (2005), Sarbanes-Oxley Solutions - Invest Now or Pay Later Hybrid Applications Emerge for Internal Controls Compliance, Forrester Research, Cambridge, MA, available at: www.forrester.com.
-
(2005)
Sarbanes-Oxley Solutions - Invest Now or Pay Later Hybrid Applications Emerge for Internal Controls Compliance
-
-
Hamerman, P.1
Markham, R.2
Orlov, L.3
Teubner, C.4
-
22
-
-
12344304439
-
"Revisiting ERP systems: Benefit realization"
-
paper presented at the 37th Hawaii International Conference on System Sciences, ACM, available at:
-
Hawking, P., Stein, A. and Foster, S. (2004), "Revisiting ERP systems: Benefit realization", paper presented at the 37th Hawaii International Conference on System Sciences, ACM, available at: http://csdl.computer.org/.
-
(2004)
-
-
Hawking, P.1
Stein, A.2
Foster, S.3
-
23
-
-
33645605030
-
"FEI CEO's 2005 top 10 financial reporting issues"
-
available at: www.fei.org
-
Heffes, E. (2005), "FEI CEO's 2005 top 10 financial reporting issues", Financial Executive, Vol. 21 No. 1, available at: www.fei.org.
-
(2005)
Financial Executive
, vol.21
, Issue.1
-
-
Heffes, E.1
-
24
-
-
33645590626
-
"About ISACA"
-
Information Systems Audit and Control Association, available at: www.isaca.org
-
Information Systems Audit and Control Association (2005), "About ISACA", available at: www.isaca.org.
-
(2005)
-
-
-
25
-
-
33645586285
-
"About ITGI"
-
IT Governance Institute, available at: www.itgi.org
-
IT Governance Institute (2005), "About ITGI", available at: www.itgi.org.
-
(2005)
-
-
-
26
-
-
27544464903
-
"IT governance and Sarbanes-Oxley: The latest sales pitch or real challenges for the IT function?"
-
IEEE, New York, NY
-
Kaarst-Brown, M. and Kelly, S. (2005), "IT governance and Sarbanes-Oxley: The latest sales pitch or real challenges for the IT function?", Proceedings of the 38th Hawaii International Conference on System Sciences - 2005, IEEE, New York, NY.
-
(2005)
Proceedings of the 38th Hawaii International Conference on System Sciences - 2005
-
-
Kaarst-Brown, M.1
Kelly, S.2
-
27
-
-
27544511562
-
"Enterprise architecting: Critical problems"
-
IEEE, New York, NY
-
Kaisler, S., Armour, F. and Valivullah, M. (2005), "Enterprise architecting: Critical problems", Proceedings of the 38th Hawaii International Conference on System Sciences, IEEE, New York, NY.
-
(2005)
Proceedings of the 38th Hawaii International Conference on System Sciences
-
-
Kaisler, S.1
Armour, F.2
Valivullah, M.3
-
28
-
-
33645603716
-
"Sarbanes-Oxley section 404: From practice to best practice"
-
Kola, V. (2004), "Sarbanes-Oxley section 404: From practice to best practice", Financial Executive, Vol. 20.
-
(2004)
Financial Executive
, vol.20
-
-
Kola, V.1
-
29
-
-
84886754293
-
"Outsourcing: Devising a game plan, what types of projects make good candidates for outsourcing"
-
Kolawa, A. (2004), "Outsourcing: Devising a game plan, what types of projects make good candidates for outsourcing", Queue, Vol. 2 No. 8, pp. 56-62.
-
(2004)
Queue
, vol.2
, Issue.8
, pp. 56-62
-
-
Kolawa, A.1
-
30
-
-
0033704202
-
"Ensuring e-business success by learning from ERP failures"
-
January-February
-
Krasner, H. (2000), "Ensuring e-business success by learning from ERP failures", IT Pro, January-February.
-
(2000)
IT Pro
-
-
Krasner, H.1
-
32
-
-
33645587088
-
"Sarbanes-Oxley Compliance Demands IS Involvement"
-
Gartner, available at: www.gartner.com/
-
Leskeia, L. and Logan, D. (2003), "Sarbanes-Oxley Compliance Demands IS Involvement", Gartner, available at: www.gartner.com/.
-
(2003)
-
-
Leskeia, L.1
Logan, D.2
-
33
-
-
24144459321
-
-
McGraw-Irwin, New York, NY
-
Louwers, T., Ramsey, R., Sinason, D. and Strawser, J. (2005), Auditing and Assurance Services, McGraw-Irwin, New York, NY.
-
(2005)
Auditing and Assurance Services
-
-
Louwers, T.1
Ramsey, R.2
Sinason, D.3
Strawser, J.4
-
34
-
-
14644394563
-
-
Pearson Prentice-Hall, Upper Saddle River, NJ
-
Luftman, J., Bullen, C., Liao, D., Nash, E. and Neumann, C. (2004), Managing the Information Technology Resource, Pearson Prentice-Hall, Upper Saddle River, NJ.
-
(2004)
Managing the Information Technology Resource
-
-
Luftman, J.1
Bullen, C.2
Liao, D.3
Nash, E.4
Neumann, C.5
-
35
-
-
33645593704
-
"Rules of the road"
-
Marlin, S. (2003), "Rules of the road", InformationWeek, No. 958, p. 40.
-
(2003)
InformationWeek
, Issue.958
, pp. 40
-
-
Marlin, S.1
-
36
-
-
2342631845
-
"Regulation and information security: Can Y2K lessons help us?"
-
IEEE, New York, NY
-
Mead, N.R. and Mcgraw, G. (2004), "Regulation and information security: Can Y2K lessons help us?", IEEE Security and Privacy, IEEE, New York, NY.
-
(2004)
IEEE Security and Privacy
-
-
Mead, N.R.1
Mcgraw, G.2
-
37
-
-
12344266312
-
"Internal audit and e-commerce controls"
-
Pathak, J. (2003), "Internal audit and e-commerce controls", Internal Auditing, Vol. 18 No. 2, pp. 30-4.
-
(2003)
Internal Auditing
, vol.18
, Issue.2
, pp. 30-34
-
-
Pathak, J.1
-
38
-
-
33645586567
-
"Sarbanes-Oxley security and risk controls: When is enough enough?"
-
Stamford, CT, META Group, available at: www.metagroup.com
-
Proctor, P. (2004), "Sarbanes-Oxley security and risk controls: When is enough enough?", Stamford, CT, Infusion: Security & Risk Strategies, META Group, available at: www.metagroup.com.
-
(2004)
Infusion: Security & Risk Strategies
-
-
Proctor, P.1
-
39
-
-
33645604642
-
"Center for enforcement tips, complaints and other information"
-
Public Company Accounting Oversight Board (PCAOB)available at: www.pcaobus.org/Enforcement/Tips/index.asp
-
Public Company Accounting Oversight Board (PCAOB) (2005), "Center for enforcement tips, complaints and other information", available at: www.pcaobus.org/Enforcement/Tips/index.asp.
-
(2005)
-
-
-
40
-
-
33645601712
-
"Sarbanes-Oxley act of 2002"
-
Public Company Accounting Oversight Board (PCAOB), Public Law 107-204, 107th Congress, available at: www.pcaobus.org
-
Public Company Accounting Oversight Board (PCAOB) (2002), "Sarbanes-Oxley act of 2002", Public Law 107-204, 107th Congress, available at: www.pcaobus.org.
-
(2002)
-
-
-
42
-
-
8344290645
-
"In their own words: CIO visions about the future of in-house IT organizations"
-
Reich, B.H. and Nelson, K. (2003), "In their own words: CIO visions about the future of in-house IT organizations", The Database for Advances in Information Systems, Vol. 34 No. 4.
-
(2003)
The Database for Advances in Information Systems
, vol.34
, Issue.4
-
-
Reich, B.H.1
Nelson, K.2
-
43
-
-
12344266612
-
"COBIT and its utilization: A framework from the literature"
-
Hoboken, NJ
-
Ridley, G., Young, J. and Carol, P. (2004), "COBIT and its utilization: A framework from the literature", Proceedings of the 37th Hawaii International Conference on System Sciences - 2004, Hoboken, NJ.
-
(2004)
Proceedings of the 37th Hawaii International Conference on System Sciences - 2004
-
-
Ridley, G.1
Young, J.2
Carol, P.3
-
45
-
-
33645606337
-
-
SAP, Home page, available at: www.sap.com
-
SAP (2005), Home page, available at: www.sap.com.
-
(2005)
-
-
-
46
-
-
33645592510
-
"Regulation S-K, 299.308, Item 308"
-
SEC, available at: www.sec.gov/divisions/corpfin/forms/regsk.htm#internal
-
SEC (2005), "Regulation S-K, 229.308, Item 308", available at: www.sec.gov/divisions/corpfin/forms/regsk.htm#internal
-
(2005)
-
-
-
47
-
-
84884825086
-
"Capability maturity model"
-
Software Engineering Institute, available at: www.sei.cmu.edu
-
Software Engineering Institute (2005), "Capability maturity models", available at: www.sei.cmu.edu.
-
(2005)
-
-
-
48
-
-
0034970801
-
"The impact of critical success factors across the stages of enterprise resource planning implementations"
-
IEEE, New York, NY
-
Somers, T.M. and Nelson, K. (2001), "The impact of critical success factors across the stages of enterprise resource planning implementations", Proceedings of the 34th Hawaii International Conference on System Sciences - 2001, IEEE, New York, NY.
-
(2001)
Proceedings of the 34th Hawaii International Conference on System Sciences - 2001
-
-
Somers, T.M.1
Nelson, K.2
-
49
-
-
33947310335
-
"Latest Standish group CHAOS report shows project success rates have improved by 50 percent"
-
(The) Standish Group, available at: www.standishgroup.com
-
(The) Standish Group (2003), "Latest Standish group CHAOS report shows project success rates have improved by 50 percent", available at: www.standishgroup.com.
-
(2003)
-
-
-
50
-
-
4243157449
-
"Financial services business process outsourcing"
-
Tas, J. and Sunder, S. (2004), "Financial services business process outsourcing", Communications of the ACM, Vol. 47 No. 5.
-
(2004)
Communications of the ACM
, vol.47
, Issue.5
-
-
Tas, J.1
Sunder, S.2
-
51
-
-
84993057084
-
"A preliminary survey of COBIT use EDP audit"
-
Tongren, J. and Warigon, S. (1997), "A preliminary survey of COBIT use EDP audit", Control and Security Newsletter, Vol. 25 No. 3, pp. 17-19.
-
(1997)
Control and Security Newsletter
, vol.25
, Issue.3
, pp. 17-19
-
-
Tongren, J.1
Warigon, S.2
-
52
-
-
33745945702
-
"Your risks and responsibilities; you may think the Sarbanes-Oxley legislation has nothing to do with you. You'd be wrong"
-
Worthen, B. (2003), "Your risks and responsibilities; you may think the Sarbanes-Oxley legislation has nothing to do with you. You'd be wrong", CIO, Vol. 16 No. 15, p. 1.
-
(2003)
CIO
, vol.16
, Issue.15
, pp. 1
-
-
Worthen, B.1
-
53
-
-
4243137230
-
"Grasping the complexity of IS development"
-
Xia, W. and Lee, G. (2004), "Grasping the complexity of IS development", Communications of the ACM, Vol. 47 No. 5, pp. 68-74.
-
(2004)
Communications of the ACM
, vol.47
, Issue.5
, pp. 68-74
-
-
Xia, W.1
Lee, G.2
-
54
-
-
33645607482
-
"CIO Insight Magazine and Gartner EXP release major study on Sarbanes Oxley compliance"
-
available at: www.ziffdavis.com
-
Ziff Davis (2004), "CIO Insight Magazine and Gartner EXP release major study on Sarbanes Oxley compliance", available at: www.ziffdavis.com.
-
(2004)
-
-
Ziff, D.1
-
55
-
-
33645606449
-
"Interview with Christopher Alberts, a senior member of the technical staff in the Networked Systems Survivability Program at the Software Engineering Institute"
-
available at: www.net-security.org (accessed 12 March)
-
Zorz, M. (2003), "Interview with Christopher Alberts, a senior member of the technical staff in the Networked Systems Survivability Program at the Software Engineering Institute", available at: www.net-security.org (accessed 12 March).
-
(2003)
-
-
Zorz, M.1
|