Showing posts with label mitigation. Show all posts
Showing posts with label mitigation. Show all posts

Monday, October 5, 2009

Is SOX Gonna Hang You out to Dry?

The US Securities and Exchange Commission announced Friday that starting in nine months, it will require the smallest public companies to provide the auditor assessments of internal controls over financial reporting that are required by the Sarbanes-Oxley Act of 2002.

Under Section 404 of Sarbox, public companies and their independent auditors are each required to report to the public on the effectiveness of the companies' internal controls. Companies with a public float below $75 million have been given extra time to design, implement, and document their controls before their auditors must attest to the controls' effectiveness.

That extension will cease starting with the 10-K reports of companies with fiscal years ending on or after June 15, 2010. Formerly, that deadline was for fiscal years ending on or after December 15, 2009. The extension was granted so that the SEC's Office of Economic Analysis could complete a study of whether additional guidance provided to company managers and auditors in 2007 was effective in reducing the costs of compliance.

Because the study was published in September, less than three months before the December 15 deadline, the SEC decided that adding more time was "appropriate and reasonable so that small public companies and their auditors can better plan for the required auditor attestation," according to the SEC.

While the largest U.S. publicly traded companies are in their fifth year of complying with Section 404, smaller companies have yet to fully comply. It was only last year that nonaccelerated filers — defined by the SEC as those with a market capitalization of below $75 million — began filing management's assessments of internal controls with their 10-Ks. Now, such companies that have fiscal years ending June 15 of next year will have to get their auditors' signoff on their internal controls, also known as 404(b) reports, for the first time.

"Since there will be no further Commission extensions, it is important for all public companies and their auditors to act with deliberate speed to move toward full Section 404 compliance," SEC chairman Mary Schapiro said in a release.

The controversial Sarbox provision has long drawn the ire of companies — particularly small public issuers — because of its allegedly high cost of compliance. The act, passed following the wave of corporate accounting scandals that included Enron and WorldCom, requires the SEC to mandate that corporate internal-controls reports state management's responsibility for setting up and maintaining an adequate internal-controls structure and procedures for financial reporting. It also must contain an assessment of the effectiveness of the company's controls structure and procedures for financial reporting, as of the end of the company's most-recent fiscal year.

The part of Section 404 related to the SEC's current action requires a company's auditors to attest to and report on the internal-controls assessments made by the management of the companies the accountants audit.

While the reporting and auditor attestation grew out of the 2002 law passed by Congress, all U.S. public companies have been required to maintain internal-accounting controls since 1977.

Shared via AddThis

Friday, July 17, 2009

Chinese Hackers Exploit Microsoft Internet Explorer Weakness!

Symantec, Sunbelt Software and SANS' Internet Storm Center (ISC) increased their threat level warnings yesterday, after Microsoft announced that attackers were exploiting a bug in an ActiveX control used by Internet Explorer (IE) to display Excel spreadsheets.

There is no patch for the vulnerability, nor will Microsoft release one later today when it issues its July batch of patches.

Temporary Fixes
A temporary fix that sets the "kill bits" of the ActiveX control is available, but experts believe it's likely most users won't take advantage of the protection.

Threat Ranking
Symantec raised its ThreatCon ranking to the second of four steps. "We're seeing it exploited, but currently on a limited scale," said Ben Greenbaum, a senior researcher with Symantec security response.

Sunbelt Ranking raised
Sunbelt also bumped up its ranking, to high, the company noted today. "We just set the Sunbelt Threat Level to high since our researchers and at least two other major organizations have found in-the-wild exploit code," said Tom Kelchner, malware researcher with the Florida-based firm.

ISC at Condition Yellow
Meanwhile, the ISC went to condition Yellow after discovering numerous sites hosting attack code. The ISC reported both broad and targeted attacks using exploit code against the new zero-day. "[There was] a highly-targeted attack against an organization earlier today who received a Microsoft Office document with embedded HTML," said the ISC in a frequently-updated blog post. "This one was particularly nasty.... It was specifically crafted for the target, with the document being tailored with appropriate contact information and subject matter that were specific to the targeted recipient."

China sites Compromised
Broader attacks are originating from compromised sites in China, the ISC added. "A .cn domain [is] using a heavily obfuscated version of the exploit, which may become an attack kit (think MPACK), and is similar to recent DirectShow attacks," said the center.

Unpatched Microsoft Bug
Last week, Microsoft confirmed that hackers were exploiting an unpatched bug in an ActiveX control that's part of DirectShow, a component of the DirectX graphics platform within Windows.

McAfee confirm attack code targeting
McAfee echoed the ISC late on Monday, confirming that attack code targeting yesterday's ActiveX bug has been added to a Web exploit toolkit and is being distributed from hijacked Chinese sites. The toolkit also contained attack code for last week's DirectShow vulnerability. Some computers in Spain, the U.K. and Germany also showed evidence of compromises, McAfee researcher Haowei Ren said in an entry to the company's security blog.

Early Days
Symantec's Greenbaum added that while his company is seeing only a small number of attacks currently "It's not in the top 500 attacks," he said. This has the potential to get big, and big quickly. "It's the kind of attack that can be very easily hosted on a Web server, and meets all the criteria for large-scale attacks in the relatively near future," Greenbaum said.

The number and diversity of attacks will likely increase because working exploit code is publicly available, he said.

Microsoft Patch
Although Microsoft is working on a patch for the new vulnerability, it's unclear when it will be ready. Users will definitely not receive any automatic protection today, however.

"Unfortunately, the comprehensive update for this vulnerability is not quite ready for broad distribution," a company spokesman said yesterday afternoon. "We recommend that customers follow the automatic 'Fix It' workaround ... to help secure their environment against this vulnerability while we finish up development and testing of the comprehensive update."

Manually Steer Browser
Fix It requires users to manually steer their browser to Microsoft's support site and download, install and run the tool to disable the ActiveX control.

That means many users won't currently be protected. "Most users won't [manually] mitigate," agreed Greenbaum. The message is clear 'Don't be in this vulnerable group.'