 




<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>IT Governance, Risk, and Compliance &#187; Foreign Corrupt Practices Act</title>
	<atom:link href="http://itknowledgeexchange.techtarget.com/it-governance/tag/foreign-corrupt-practices-act/feed/" rel="self" type="application/rss+xml" />
	<link>http://itknowledgeexchange.techtarget.com/it-governance</link>
	<description></description>
	<lastBuildDate>Mon, 20 May 2013 00:56:50 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	
		<item>
		<title>Application Protection &#8211; Part IV</title>
		<link>http://itknowledgeexchange.techtarget.com/it-governance/application-protection-part-iv/</link>
		<comments>http://itknowledgeexchange.techtarget.com/it-governance/application-protection-part-iv/#comments</comments>
		<pubDate>Mon, 22 Jun 2009 20:41:36 +0000</pubDate>
		<dc:creator>Robert Davis</dc:creator>
				<category><![CDATA[Accounting]]></category>
		<category><![CDATA[Applications]]></category>
		<category><![CDATA[COE]]></category>
		<category><![CDATA[Council of Europe]]></category>
		<category><![CDATA[FCPA]]></category>
		<category><![CDATA[Financial]]></category>
		<category><![CDATA[Foreign Corrupt Practices Act]]></category>
		<category><![CDATA[Information Technology]]></category>
		<category><![CDATA[IT]]></category>
		<category><![CDATA[Laws and Regulations]]></category>
		<category><![CDATA[OAS]]></category>
		<category><![CDATA[OECD]]></category>
		<category><![CDATA[Organisation for Economic Co-operation and Development]]></category>
		<category><![CDATA[Organization of American States]]></category>
		<category><![CDATA[Sarbanes Oxley Act]]></category>
		<category><![CDATA[SOX]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/it-governance/?p=179</guid>
		<description><![CDATA[...the FCPA can affect an organization's internal control environment by indirectly imposing management's assurance of an adequate IT control environment with adequate information protection.]]></description>
				<content:encoded><![CDATA[<p>The FCPA impacts IT control requirements of U.S. publicly held enterprises. Section 78m (b), in particular, documents the legislative rules and compliance requirements of internal control evaluation reporting with regard to management&#8217;s assessment of internal controls. Section 78m (b) (2) through (5) applies to Securities Exchange Act of 1934 filers. Therefore, the FCPA can affect an organization&#8217;s internal control environment by indirectly imposing management&#8217;s <a href="http://diy.craigspress.com/BookStore/BookStoreBookDetails.aspx?bookid=48453">assurance</a> of an adequate IT control environment with adequate information protection. Based on the Public Company Accounting Oversight Board&#8217;s interpretation, the SOX IT control parameter, in effect, is the same as that of the FCPA. Therefore, U.S. Securities Exchange Act of 1934 filers may not be aware of FCPA legal requirements &#8212; yet, they should have been performing the necessary FCPA control self-assessments and remedial actions since 1977. Similarly, European Union, OAS, and OECD member countries should be engaging in control self-assessments and remediation of internal accounting controls as they relate to safeguarding information assets to ensure compliance with legal mandates.</p>
<p>&#8220;View Part I of the Application Protection series <a href="http://itknowledgeexchange.techtarget.com/it-governance/application-protection-part-i/">here</a>&#8221;</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/it-governance/application-protection-part-iv/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Application Protection &#8211; Part III</title>
		<link>http://itknowledgeexchange.techtarget.com/it-governance/application-protection-part-iii/</link>
		<comments>http://itknowledgeexchange.techtarget.com/it-governance/application-protection-part-iii/#comments</comments>
		<pubDate>Fri, 19 Jun 2009 13:09:53 +0000</pubDate>
		<dc:creator>Robert Davis</dc:creator>
				<category><![CDATA[Accounting]]></category>
		<category><![CDATA[Applications]]></category>
		<category><![CDATA[COE]]></category>
		<category><![CDATA[Council of Europe]]></category>
		<category><![CDATA[FCPA]]></category>
		<category><![CDATA[Financial]]></category>
		<category><![CDATA[Foreign Corrupt Practices Act]]></category>
		<category><![CDATA[Information Technology]]></category>
		<category><![CDATA[IT]]></category>
		<category><![CDATA[Laws and Regulations]]></category>
		<category><![CDATA[OAS]]></category>
		<category><![CDATA[OECD]]></category>
		<category><![CDATA[Organisation for Economic Co-operation and Development]]></category>
		<category><![CDATA[Organization of American States]]></category>
		<category><![CDATA[Sarbanes Oxley Act]]></category>
		<category><![CDATA[SOX]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/it-governance/?p=172</guid>
		<description><![CDATA[Technically, application safeguarding controls should be present during input, processing, and output.]]></description>
				<content:encoded><![CDATA[<p>FCPA control measures for an adequate system of internal accounting controls include maintaining appropriate segregation of duties, allowing only authorized transaction execution, controlling access to assets, and reconciling documented assets to actual assets regularly. Completeness, accuracy, authorization, and accessibility are considered key internal accounting information protection controls that fulfill FCPA legal requirements. These control measures most often interact with &#8212; or are deployed through &#8212; IT financial applications, thus justifying information security management&#8217;s involvement in assessing compliance with the FCPA. </p>
<p>To dispatch FCPA information reliability requirements, an information security manager should identify, understand, test, and document internal accounting security controls for information assets. Essentially, an information security manager should assume responsibility for assessing financial applications for FCPA safeguarding compliance. Technically, application safeguarding controls should be present during input, processing, and output. IT procedures are expected to provide information protection throughout the life cycle of earmarked FCPA financial application systems. Key internal accounting controls can be mapped to information security confidentiality, integrity, and availability control measures. For instance, information security application accuracy controls include input edit and validation routines that ensure information integrity.</p>
<p>&#8220;View Part I of the Application Protection series <a href="http://itknowledgeexchange.techtarget.com/it-governance/application-protection-part-i/">here</a>&#8220;</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/it-governance/application-protection-part-iii/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Application Protection &#8211; Part II</title>
		<link>http://itknowledgeexchange.techtarget.com/it-governance/application-protection-part-ii/</link>
		<comments>http://itknowledgeexchange.techtarget.com/it-governance/application-protection-part-ii/#comments</comments>
		<pubDate>Tue, 16 Jun 2009 19:06:50 +0000</pubDate>
		<dc:creator>Robert Davis</dc:creator>
				<category><![CDATA[Accounting]]></category>
		<category><![CDATA[Applications]]></category>
		<category><![CDATA[COE]]></category>
		<category><![CDATA[Council of Europe]]></category>
		<category><![CDATA[FCPA]]></category>
		<category><![CDATA[Financial]]></category>
		<category><![CDATA[Foreign Corrupt Practices Act]]></category>
		<category><![CDATA[Information Technology]]></category>
		<category><![CDATA[IT]]></category>
		<category><![CDATA[Laws and Regulations]]></category>
		<category><![CDATA[OAS]]></category>
		<category><![CDATA[OECD]]></category>
		<category><![CDATA[Organisation for Economic Co-operation and Development]]></category>
		<category><![CDATA[Organization of American States]]></category>
		<category><![CDATA[Sarbanes Oxley Act]]></category>
		<category><![CDATA[SOX]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/it-governance/?p=169</guid>
		<description><![CDATA[The FCPA codifies bribery of foreign officials as a criminal offense for U.S. publicly held companies...]]></description>
				<content:encoded><![CDATA[<p>The FCPA codifies bribery of foreign officials as a <a href="http://diy.craigspress.com/BookStore/BookStoreBookDetails.aspx?bookid=48453">criminal offense</a> for U.S. publicly held companies, requires accurate financial-transactions accounting, and amends the Securities Exchange Act of 1934. With regard to accounting, FCPA Section 78m (b) (2) documents managerial responsibility for generating and retaining financial information while presenting transactions accurately and fairly, as well as deploying a &#8220;system of internal accounting controls.&#8221; Furthermore, FCPA Section 78m (b) (5) has been interpreted as requiring U.S. businesses to create and sustain adequate internal accounting controls regardless of an organization&#8217;s cost-benefit analysis ratio. This section of the FCPA therefore decrees <a href="http://www.amazon.com/dp/0974302996?tag=authorsdencom&amp;camp=14573&amp;creative=327641&amp;linkCode=as1&amp;creativeASIN=0974302996&amp;adid=1S1Y52FHECCW6986Z57R&amp;">preventive and detective controls</a> to avoid financial statement fraud or misrepresentation.</p>
<p>&#8220;View Part I of the Application Protection series <a href="http://itknowledgeexchange.techtarget.com/it-governance/application-protection-part-i/">here</a>&#8220;</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/it-governance/application-protection-part-ii/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Application Protection &#8211; Part I</title>
		<link>http://itknowledgeexchange.techtarget.com/it-governance/application-protection-part-i/</link>
		<comments>http://itknowledgeexchange.techtarget.com/it-governance/application-protection-part-i/#comments</comments>
		<pubDate>Fri, 12 Jun 2009 18:36:47 +0000</pubDate>
		<dc:creator>Robert Davis</dc:creator>
				<category><![CDATA[Accounting]]></category>
		<category><![CDATA[Applications]]></category>
		<category><![CDATA[COE]]></category>
		<category><![CDATA[Council of Europe]]></category>
		<category><![CDATA[FCPA]]></category>
		<category><![CDATA[Financial]]></category>
		<category><![CDATA[Foreign Corrupt Practices Act]]></category>
		<category><![CDATA[Information Technology]]></category>
		<category><![CDATA[IT]]></category>
		<category><![CDATA[Laws and Regulations]]></category>
		<category><![CDATA[OAS]]></category>
		<category><![CDATA[OECD]]></category>
		<category><![CDATA[Organisation for Economic Co-operation and Development]]></category>
		<category><![CDATA[Organization of American States]]></category>
		<category><![CDATA[Sarbanes Oxley Act]]></category>
		<category><![CDATA[SOX]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/it-governance/?p=166</guid>
		<description><![CDATA[Legacy law or regulation replacement is a common occurrence within most governments when circumstances appear to discredit legal mandate enforcement.]]></description>
				<content:encoded><![CDATA[<p>Legacy law or regulation replacement is a common occurrence within most governments when circumstances appear to discredit legal mandate enforcement. However, the <a href="http://fl1.findlaw.com/news.findlaw.com/hdocs/docs/gwbush/sarbanesoxley072302.pdf">U.S. Sarbanes-Oxley Act (SOX) of 2002</a> does not supersede the <a href="http://www.usdoj.gov/criminal/fraud/docs/statute.html">U.S. Foreign Corrupt Practices Act (FCPA) of 1977</a>. In fact, though tagged legacy enterprise governance legislation by some officials, the FCPA has thrived as the basis for enactment of various internationally recognized legal edicts addressing internal accounting controls that indirectly impact information security management requirements. </p>
<p>Contextually, the FCPA applies to U.S. publicly held companies and was adopted in the 1990s by the Organization of American States (OAS), the Organisation for Economic Co-operation and Development (OECD), and the Council of Europe (COE). Concerning international relevance, the FCPA is a frame of reference for most current IT financial application security best practices. Specifically, details demonstrating this law&#8217;s influence are well documented in <a href="http://www.amazon.com/exec/obidos/ASIN/0974302996/authorsdencom">IT financial application assurance</a> and internal accounting control literature. </p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/it-governance/application-protection-part-i/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Legal Compliance Alignment &#8211; Part IV</title>
		<link>http://itknowledgeexchange.techtarget.com/it-governance/legal-compliance-alignment-part-iv/</link>
		<comments>http://itknowledgeexchange.techtarget.com/it-governance/legal-compliance-alignment-part-iv/#comments</comments>
		<pubDate>Mon, 23 Feb 2009 21:26:02 +0000</pubDate>
		<dc:creator>Robert Davis</dc:creator>
				<category><![CDATA[FCPA]]></category>
		<category><![CDATA[Foreign Corrupt Practices Act]]></category>
		<category><![CDATA[GLBA]]></category>
		<category><![CDATA[Gramm-Leach-Bliley Act]]></category>
		<category><![CDATA[Health Insurance Portability and Accountability Act]]></category>
		<category><![CDATA[HIPAA]]></category>
		<category><![CDATA[IAP]]></category>
		<category><![CDATA[Information Asset Protection]]></category>
		<category><![CDATA[Information Security Governance]]></category>
		<category><![CDATA[Information Security Management]]></category>
		<category><![CDATA[ISG]]></category>
		<category><![CDATA[ISM]]></category>
		<category><![CDATA[Sarbanes Oxley Act]]></category>
		<category><![CDATA[SOA]]></category>
		<category><![CDATA[SOX]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/it-governance/?p=78</guid>
		<description><![CDATA[When exploring links between national and international arenas, the information security manager will discover international developments decisively impact national laws.]]></description>
				<content:encoded><![CDATA[<p>When exploring links between national and international arenas, the information security manager will discover international developments decisively impact national laws. Specifically, regional coalitions have enacted IAP related edicts that subsequently were codified in national laws and regulations. Procedurally, most regional coalition IAP decrees are presented as directives to member nations for federal ratification. For this reason, with the assistance of legal counsel, it is strongly recommended that information security managers evaluate all relevant statutory and regulatory mandates; in whatever judicial divisions the entity operates. Beneficially, multiple legal compliance requirements assessments enable entity-centric standard practices for satisfying other expected behavior. Exercises in legal due care can also equip an entity to build a compliance culture where standardization is the norm, and conditionally produce an environment conducive to training employees in IAP. </p>
<p>Predicatively, laws will continue to be enacted and the regulatory environment will become more complex due to unacceptable conduct remediation. Consequently, entities will continue to be compelled to demonstrate compliance with legal mandates &#8211; especially laws governing data retention and privacy &#8211; that can differ by hemisphere, country, province, county, city, as well as industry. In this increasingly complex regulatory environment, most entities should balance their focus on compliance imperatives without diminishing anticipated response quality to governmental edicts.</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/it-governance/legal-compliance-alignment-part-iv/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Legal Compliance Alignment &#8211; Part III</title>
		<link>http://itknowledgeexchange.techtarget.com/it-governance/legal-compliance-alignment-part-iii/</link>
		<comments>http://itknowledgeexchange.techtarget.com/it-governance/legal-compliance-alignment-part-iii/#comments</comments>
		<pubDate>Thu, 19 Feb 2009 20:47:57 +0000</pubDate>
		<dc:creator>Robert Davis</dc:creator>
				<category><![CDATA[FCPA]]></category>
		<category><![CDATA[Foreign Corrupt Practices Act]]></category>
		<category><![CDATA[GLBA]]></category>
		<category><![CDATA[Gramm-Leach-Bliley Act]]></category>
		<category><![CDATA[Health Insurance Portability and Accountability Act]]></category>
		<category><![CDATA[HIPAA]]></category>
		<category><![CDATA[IAP]]></category>
		<category><![CDATA[Information Asset Protection]]></category>
		<category><![CDATA[Information Security Governance]]></category>
		<category><![CDATA[Information Security Management]]></category>
		<category><![CDATA[ISG]]></category>
		<category><![CDATA[ISM]]></category>
		<category><![CDATA[Sarbanes Oxley Act]]></category>
		<category><![CDATA[SOA]]></category>
		<category><![CDATA[SOX]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/it-governance/?p=71</guid>
		<description><![CDATA[There are numerous global, regional as well as national laws and regulations focusing on information assets protection (IAP) requiring professional consideration.]]></description>
				<content:encoded><![CDATA[<p>There are numerous global, regional as well as national laws and regulations focusing on <a href="http://www.theiia.org/bookstore/product/it-auditing-assuring-information-assets-protection-1381.cfm">information assets protection</a> (IAP) requiring professional consideration. In particular, at the global level, the World Intellectual Property Organization (WIPO) and World Trade Organization (WTO) have constructed legally binding derivative IAP agreements. While regionally, trans-border coalitions adopting or enacting IAP related laws include the Asia-Pacific Economic Co-operation (APEC), the Council of Europe (COE), the European Union (EU), the Organization of American States (OAS), and the Organization for Economic Cooperation and Development (OECD). Lastly, the Canadian Personal Information Protection and Electronic Documents Act (PIPEDA), the U.K. Data Protection Act, the U.S. Digital Millennium Copyright Act (DMCA), and the U.S. Federal Information Security Management Act (FISMA) are clear examples of IAP national legislation that may affect an entity&#8217;s control framework.</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/it-governance/legal-compliance-alignment-part-iii/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Legal Compliance Alignment &#8211; Part II</title>
		<link>http://itknowledgeexchange.techtarget.com/it-governance/legal-compliance-alignment-part-ii/</link>
		<comments>http://itknowledgeexchange.techtarget.com/it-governance/legal-compliance-alignment-part-ii/#comments</comments>
		<pubDate>Mon, 16 Feb 2009 20:00:15 +0000</pubDate>
		<dc:creator>Robert Davis</dc:creator>
				<category><![CDATA[FCPA]]></category>
		<category><![CDATA[Foreign Corrupt Practices Act]]></category>
		<category><![CDATA[GLBA]]></category>
		<category><![CDATA[Gramm-Leach-Bliley Act]]></category>
		<category><![CDATA[Health Insurance Portability and Accountability Act]]></category>
		<category><![CDATA[HIPAA]]></category>
		<category><![CDATA[IAP]]></category>
		<category><![CDATA[Information Asset Protection]]></category>
		<category><![CDATA[Information Security Governance]]></category>
		<category><![CDATA[Information Security Management]]></category>
		<category><![CDATA[ISG]]></category>
		<category><![CDATA[ISM]]></category>
		<category><![CDATA[Sarbanes Oxley Act]]></category>
		<category><![CDATA[SOA]]></category>
		<category><![CDATA[SOX]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/it-governance/?p=67</guid>
		<description><![CDATA[Simultaneous compliance with multiple laws and regulations can create unique challenges for most entities.]]></description>
				<content:encoded><![CDATA[<p>Simultaneous compliance with multiple laws and regulations can create unique challenges for most entities. Selectively, potential compliance hurdles include distinct internal management groups pursuing equivalent goals; diverse audit perspectives, priorities, and requirements; as well as confusion resulting from redundant controls. For instance, cross-compliance with the Foreign Corrupt Practices Act (FCPA), Sarbanes Oxley Act (SOX), Health Insurance Portability and Accountability Act (HIPAA), and Gramm-Leach-Bliley Act (GLBA) may generate muddled responses regarding the importance of certain security controls for a U.S. based &#8216;publicly held&#8217; corporation. To decrease potential negative effects of cross-compliance, management should seek <a href="http://www.amazon.com/Assuring-Legal-Compliance-Assurance-Services/dp/B001T0I7GO/ref=sr_1_10?ie=UTF8&amp;s=books&amp;qid=1234814708&amp;sr=1-10">assurance</a> that relevant statutory, regulatory, and contractual requirements are adequately defined and documented for each information system.</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/it-governance/legal-compliance-alignment-part-ii/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Legal Compliance Alignment &#8211; Part I</title>
		<link>http://itknowledgeexchange.techtarget.com/it-governance/legal-compliance-alignment-part-i/</link>
		<comments>http://itknowledgeexchange.techtarget.com/it-governance/legal-compliance-alignment-part-i/#comments</comments>
		<pubDate>Thu, 12 Feb 2009 22:22:20 +0000</pubDate>
		<dc:creator>Robert Davis</dc:creator>
				<category><![CDATA[FCPA]]></category>
		<category><![CDATA[Foreign Corrupt Practices Act]]></category>
		<category><![CDATA[GLBA]]></category>
		<category><![CDATA[Gramm-Leach-Bliley Act]]></category>
		<category><![CDATA[Health Insurance Portability and Accountability Act]]></category>
		<category><![CDATA[HIPAA]]></category>
		<category><![CDATA[IAP]]></category>
		<category><![CDATA[Information Asset Protection]]></category>
		<category><![CDATA[Information Security Governance]]></category>
		<category><![CDATA[Information Security Management]]></category>
		<category><![CDATA[ISG]]></category>
		<category><![CDATA[ISM]]></category>
		<category><![CDATA[Sarbanes Oxley Act]]></category>
		<category><![CDATA[SOA]]></category>
		<category><![CDATA[SOX]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/it-governance/?p=63</guid>
		<description><![CDATA[Aligning information security governance with legal compliance management allows an entity to enhance cultural ethics while concurrently reducing judicial risks.]]></description>
				<content:encoded><![CDATA[<p>Institutionalized information security governance defines the information assets safeguarding perimeter inside which an entity should operate. Whereas, legal compliance management ensures structural boundary segments are sturdy and the entity consistently fulfills its mission within externally imposed demarcation lines. Generally, determining an entity&#8217;s legal mandates exceeds the security function&#8217;s ambit. Nonetheless, overseeing the design, implementation and monitoring of applicable legal requirements is a security function imperative. Aligning <a href="http://www.pleier.com/itasecgovweb.htm">information security governance</a> with legal compliance management allows an entity to enhance cultural ethics while concurrently reducing judicial risks.</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/it-governance/legal-compliance-alignment-part-i/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
