MetricStream adds full support for IT Controls and Automation of Application Control Testing in its SOx 404 Solution

Softarea51.com is your source for all the latest computer technology and software related press releases.
Browse our archive for more press releases!

Released on: 28, December 2005
, Author: Laurie Gibson
, Audience: Software related

Recommended: Click here to run a Free driver update scan »


With IT applications automating most business processes intodayÂ's environment, they enable a vast majority of the internal controls within theorganization. Hence, it is essential to integrate process-level controls for all keyprocesses into a single environment to enable risk-based internal controlassessment. Examples include:

Process-level application controls (such as orders are processed only within acustomerÂ's credit limits or all goods shipped are invoiced)

Process-level general IT controls (upgrade process for order management applicationis well defined and always followed or adequate security exists for the ordermanagement application)

Process-level manual controls (orders and cancellations are input correctly into theapplication or users are well trained on the sales order policies)

Process-level application controls typically address risks related to completeness,accuracy, validity, authorization and segregation of duties for process level data,while, process-level general IT controls address overall IT-related risks for thatapplication, including processes to ensure validation against intended purpose,change management processes and access control. With the new product release of itsSOx 404 suite in December 2005, MetricStream becomes the first compliance vendor toprovide such an integrated risk and controls environment to its customers.

In addition, with the new product release, MetricStream will also enable companiesto significantly reduce their cost of compliance by providing a framework thatdefines process-level manual and application controls within a single test,automates the testing of process level application controls, and reports the resultsfor the entire test  including manual and application controls, in an integratedmanner. MetricStream leverages the APIs within this framework to automate thetesting of controls implemented within either popular ERP systems such as SAP,Oracle and PeopleSoft, as well as legacy/homegrown systems. MetricStream nowprovides an out-of-the-box library containing more than 1500 tests for automatingthe testing of application level controls within popular ERP systems in generalledger, procure-to-pay, order-to-cash, inventory / cost Accounting, asset managementand payroll processes.

Finally, with the new product release, a customer will also be able to easily defineand assess overall IT controls  these are typically COBIT/ITIL/ISO17799 definitionsthat are reconciled for the COSO internal control model. Such controls are intendedto drive IT Governance and  tone at the topÂ'. They include:

Lifecycle: Acquiring and implementing new programs and systems, as well as changesin, and maintenance of, existing systems

Operations: Managing service levels for applications and infrastructure and forthird-party services

Access: Managing access-control to programs and data including security andauthorization

As a result, MetricStream now enables its customers to integrate and reconcileCOBIT, ITIL and ISO17799 definitions into the COSO framework and allows customers touse COSO as the default framework for assessing all internal controls, including ITrelated controls.

"Working with the Fortune 1000 companies, we immediately realized that most pureplay SOx 404 vendors stopped short of addressing process-level IT controls andoverall IT controls within their solution set, said Shellye Archambeau, CEO ofMetricStream.  MetricStream decided to incorporate full support of definition andtesting of process-level application controls, process-level general IT controls,overall IT controls, COBIT framework, as well as automated testing of process-levelapplication controls in its current release. As a result, in one swoop we addresseda gaping hole in most SOx 404 solutions in the marketplace."

"I am very impressed with how MetricStream continues to work closely with itscustomers to clearly identify and rapidly address the SOx 404 requirements for itscustomers, said Joel E. Marks, vice chairman and COO, Advanced Equities.  We lookforward to addressing the IT-related control capabilities from MetricStream in ourSOx compliance program."

Key modules in the MetricStream solution for Sarbanes-Oxley 404 include:

MetricStream Core SOx 404 suite

MetricStream Design: Enables the organization to document the control hierarchy,design assessment plans, and setup the compliance environment for all the businessunits within the organization.

MetricStream Assess: Enables the organization to schedule and perform assessments ofdesign effectiveness and operational effectiveness of the controls.

MetricStream Improve: Enables the organization to manage the remediation, exception,and disclosure processes, track their status, and ensure successful completion.

MetricStream Monitor: Provides visibility into the ongoing compliance efforts withinthe organization through role based dashboards and scorecards.

MetricStream Document Management: Provides a central repository for all documentsrequired for compliance with Section 404 including company's policies, procedures,process documentation and all other regulatory and legal information.

MetricStream Training: Enables the organization to make compliance a part of thecompany's culture by driving consistency through managing all aspects of employeetraining.

MetricStr eam Audit: Performs process-level self-assessments and provides support forinternal and external auditors.

With the new release, MetricStream Design now enables users to identify any controlas a process-level application control or a process-level general IT control or aprocess-level manual control. In addition, MetricStream Design now enables users tocapture general IT controls by defining IT as a separate function with variousprocesses such as acquisition, change management, service level monitoring,security, incident management etc and enabling customers to easily comply withCOBIT, ISO17799 and ITIL standards. MetricStream Assess now provides a frameworkthat automates the testing of process level application controls and reports theresults for the entire test  including manual and application controls, in anintegrated manner and also provides an out-of-the-box library containing more than1500 tests for automating the testing of application level controls in generalledger, procure-to-pay, order-to-cash, inventory / cost Accounting, asset managementand payroll processes.

About MetricStream MetricStream is a market leader in Enterprise-wide Quality and Compliance Managementfor global corporations. MetricStream solutions are used by leading corporations indiverse industries such as Automotive, Food, Pharmaceuticals, Manufacturing andElectronics to manage their quality processes, regulatory and industry-mandatedcompliance and corporate governance initiatives. Key MetricStream customers includePfizer, Hitachi Computer Products (America), TaylorMade-Adidas Golf, Cannon-ITTIndustries and Fairchild Semiconductor. MetricStream is headquartered in RedwoodShores, California and can be reached at http://www.metricstream.com


Source: Express-Press-Release.com
Related downloads


ASP.net control for Visual Studio 2005/2008 that allows full YouTube API and Video Playback directly in your ASP.net web applications. HD and Javascript events allow for creative and new designed experiences. Callback and Built in Help File Support

Testing Master is a load and stress testing tool that provides you with an easy to use, consistent and cost-effective way of testing web sites and intranet applications with web interface.

Ghost Installer is full featured deployment solution with extremely friendly and powerful user interface, compact installer core and unique setup customization features.

Complete and efficient solution that gives you full control over remote computer. Easy to deploy over network, accurate screen updates while low CPU load, low network traffic, high security, built-in messaging, task and file manager and more

Application Blocker Pro is both an internet parental control and a monitoring solution that will protect your child while surfing the internet. The application can block inappropriate web sites, application running before the action take place

Eventcorder is a visual, easy-to-use, macro recorder and player.
It makes use of the unique Clickview technology to ensure a reliable playback. It re-focuses the windows during the playback. It can play variable data. It supports XML format.

Eventcorder is a visual, easy-to-use, macro recorder and player.
Eventcorder suite is a set of applications and tools to create regression and gui testing sessions, simple and complex automation, self-running presentations, benchmarking.

Automate web tasks like uploading, downloading, online marketing, click links and test websites. Browsing, form filling and data extraction can be recorded into an Internet macro. Supports all websites, including Flash, Java and Silverlight applets.

Toolbox LT provides the most cost effective solution for extending your design and drafting capabilities with AutoCAD LT. Design in 3D (solids and surfaces), generate realistic shaded renders and load and run Lisp utilities and ARX applications.

Automated Testing Tool for Functional Testing,Performance Testing,Load Testing,Stress Testing,Web Services Testing,Server Performance Monitoring & Regression Testing to run tests from command line for all test types.
Softarea51.com RSS Feed

Get RSS updates on latest computer technology and software related press releases Subscribe to Latest Press Releases RSS feed    Subscribe



You are welcome to include these headlines in your own pages. If you want to find out how to parse this RSS file please read our tutorial How to parse RSS feeds with PHP.