Curated for content, computing, and digital experience professionals

Month: January 2005 (Page 5 of 10)

Compliance, SOX, and Nonprofits

This morning I attended a workshop on the impact of Sarbanes-Oxley on
nonprofit organizations.  The combination of SOX and nonprofits intrigued
me.  Since Sarbanes-Oxley is all about public companies, with rules issued
by the SEC, my impression was that the connection between SOX and nonprofits was
zip.  It followed that the workshop was likely to be either very
interesting or very short.

It turned out to be very interesting.

Boiled down to essentials, there at least four ways in which the governance
and internal control concerns intersect with nonprofit organizations:

  • The "whistleblower protection" in section 1107 of
    Sarbanes-Oxley, which provides substantial penalties for any retaliation
    against employees or others who provide law enforcement officers with
    information about possible violation of Federal law, applies to nonprofits
    as well as to other kinds of entities.
  • The penalties for document destruction in section 802 of
    Sarbanes-Oxley also apply to nonprofits.
  • As SOX applies to more and more for-profit entities, parts of it are
    emerging as the expected standard of performance in the eyes of public and
    private funding sources.
      At the very least, nonprofits should expect
    that expectations regarding conflicts of interest, audits, and evidence of
    internal controls will increase and will follow the general outline of SOX
  • Some states are beginning to consider state regulations that impose parts
    of the COSO framework and other aspects of SOX on nonprofits. 
    California has already passed such legislation.  (For a summary of
    other state activity, take a look at this
    document
    from the National Council of Nonprofit Associations).

Practically speaking, my sense was that the most immediate impact on
nonprofits from a content management point of view was that, regardless of size,
these organizations need to document policies and procedures and ensure that
they are available and that they are used.  The focus of this effort
should, of course, be on staff and on board members, but should also extend to
volunteers who act as agents of the organization.  The policies and
procedures should include mechanisms for handling employee complaints and
document retention and destruction, in accord with SOX requirements.  They
should also, of course, deal with broader internal control issues such as
handling cash, soliciting and accounting for donations, making bank deposits,
and so on.

Government, Open Source, and XML

Writing for WindowsIT Pro, Paul Thurrott reports that the Commonwealth of Massachusetts has reached agreement with Microsoft on a license change to Microsoft Office that may have far-reaching consequences in several arenas of interest to Gilbane Report readers.

Microsoft has reached an agreement with Massachusetts that will result in the software giant easing its license restrictions for its Office 2003 document formats in return for the state dropping a previous requirement to only use document formats based on open standards. In early 2004, Massachusetts announced that it would require all state agencies to create and store information in document types based on open standards like HTML… The goal of the format requirement was to ensure that the state could read digital documents in perpetuity and not have to worry about document conversions down the road if they adopted a format that was later abandoned by its maker. However, under terms of its agreement with Microsoft, Massachusetts has revised its requirement to include so-called “open formats” such as the XML-based document types supported by Office 2003 applications such as Word and Excel.

Thurrott goes on to say that this compromise with Microsoft should be viewed as a blow to open source advocates, who would rather see governments adopt open standards for document archiving. Thurrott has a good point; I know from my own consulting that government archivists would love to have open, high-fidelity document formats to choose from. On the other hand, it is potentially good news that Microsoft will be loosening its licensing restrictions on the schemas that underlie the ubiquitous document formats.

Ernst & Young on Internal Controls

Last fall Ernst & Young published the results of a survey on trends in the implementation of internal controls,
focusing in particular on the progress that companies were making in meeting
Section 404 deadlines for Sarbanes-Oxley.  Since the publication date was
last October, this isn’t breaking news … but the existence of the survey was
news to me and I found it useful and interesting.  (You can get to the
Acrobat file by clicking here.)

The general message is (surprise!) that companies were finding that it was
taking much more effort than they expected and that they were not, in general,
sticking to the schedules they had put into place earlier.

But there are also findings that are a more surprising.  Here is an
example:  59% of the companies surveyed said that they were tracking their
testing and remediation work in an Access database or an Excel spreadsheet ( !!)
.  The implication is that these companies are not at all able to provide
real-time information about remediation across the organization.  Bummer.

Here is another one:  nearly 30% of the companies surveyed had not yet
selected a technology platform for 404 compliance implementation.  Since
these companies will have, in general, met their initial deadlines without
making a platform commitment, that suggests that there are a good number of
companies that have worked through the first round of 404 issues without making
a big technology buy.  These companies are in a good position to bring
clear expectations and requirements to their planning and purchasing.

2005 is the year that Section 404 internal controls become required for all
SEC filers, not just the accelerated filers. It is a pretty good bet that there
will be more companies coming to terms with the issues highlighted in the
E&Y survey.  It is worth a look if you haven’t seen it.

RedDot Solutions Launches LiveServer 2.2

RedDot Solutions announced the launch of the RedDot LiveServer 2.2, a personalization and integration platform offered specifically for the midmarket. The new RedDot LiveServer features improved functionality for personalization, search and integration. RedDot LiveServer 2.2 now features: improved personalized search with Verity K2 5.5 technology; official certification and registration as an SAP SAP2EE Application; faster integration of pre-existing Web applications; integrated Web applications can now be “content aware”; extended integration with directory services using LDAP; and a new editor toolbar and additional display functions. www.reddot.com

Altova Announces DiffDog 2005

Altova announced that a new dedicated differencing utility has been added to its product line. Altova DiffDog 2005 is a synchronization tool that facilitates the comparison and merging of files, folders, and directories for application developers and power users. DiffDog 2005 is available in both Standard and Professional editions. DiffDog 2005 Standard and Professional editions allow users to quickly compare source code files, HTML files, or any text-based files then merge changes with a click of the mouse. Both editions deliver comparison and merging options for all file directories as well. DiffDog 2005 Professional Edition also provides advanced XML-aware differencing and editing capabilities based on those popularized in Altova XMLSpy. DiffDog 2005 integrates with any version control system that supports external differencing applications. Intelligent syntax-coloring, line numbering, indentation guides, folding margins, and other innovative features are provided to assist in comparing source code and XML files. Special XML differencing capabilities in DiffDog 2005 Professional Edition include DTD/schema-based validation, well-formedness checking, intelligent entry helpers, optional entity resolution, and attention to attribute and child element ordering. Developers can compare XML files in either an advanced text view or enhanced grid view. Altova DiffDog 2005 is immediately available for purchase in both Standard and Professional Editions with (USD) prices for a single-user license starting at $69 and $129 respectively. www.altova.com

Cadmus Communications Upgrades RapidRights DRM Service for Macintosh Users

Cadmus Communications Corporation announced the release of a Macintosh client for its RapidRights digital rights management (DRM) software. The Mac client will run on Mac OS X v10.3 or higher and will use Preview, the built-in Mac Viewer for PDF. RapidRights allows publishers to deliver protected PDF files and is a DRM solution that does not require a separate download or plug-in to open the protected files. RapidRights is the electronic delivery component of Cadmus’ ArticleWorks, a comprehensive content delivery and digital rights management system with complete e-commerce functionality that enables publishers and other content providers to deliver content on demand in either printed or secure electronic formats. www.cadmus.com

Interwoven Introduces LiveSite Content Publishing Server

Interwoven, Inc. announced the introduction of the Interwoven LiveSite Content Publishing Server. Powered by new WYSIWYG (What You See Is What You Get) content publishing technology, LiveSite empowers business users to easily create and publish dynamic websites – including public sites, intranets and extranets – while still providing IT with the tools to maintain a high degree of control and security. In a related announcement, Interwoven also introduced the new Interwoven Intranet Solution based on LiveSite technology. Fully integrated with the Interwoven TeamSite Web Content Management Server, LiveSite leverages TeamSite’s workflow, version control, staging, rollback, and preview capabilities. Key product features of Interwoven LiveSite include: WYSIWYG Publishing, Component-Based Page Assembly, Point-and-Click Customization, In-Context Review and Edit, and Single-Point Deployment and Delegated Administration. Interwoven LiveSite is generally available now. www.interwoven.com

« Older posts Newer posts »

© 2024 The Gilbane Advisor

Theme by Anders NorenUp ↑