Bill 198

Tripwire simplifies compliance with Bill 198—the Canadian equivalent to SOX

Bill 198, the Canadian counterpart to the U.S. Sarbanes Oxley Act (SOX), was instituted to regulate the efficiency of financial reporting and operations in publicly held companies. In order to comply with Bill 198, companies must implement and evaluate internal controls over financial reporting, as well as provide documentation that demonstrates the effectiveness of the information security in place.


Tripwire provides internal controls over financial reporting enabling you to comply with change management principles of Bill 198.

Tripwire delivers a comprehensive solution by:

  • Providing continuous compliance with the requirements of Bill 198 along with comprehensive configuration assessment policies.
  • Tracking and auditing all change and suspicious events, and generating an audit trail of authorized and unauthorized change to help evaluate whether their controls are effective.
  • Automating the repair of configurations that intentionally or accidentally fall from secure and compliant states
  • Investigating the source of any unauthorized change to ensure the timely disclosure of management’s report on the effectiveness of the company’s controls and detecting (and reporting) any material weaknesses in them.

COBIT

COBIT addresses the three elements of the term “disclosure control and procedures requirements” and is a good starting point for companies that seek to comply with the internal control and disclosure control and procedures requirements of Bill 198. Tripwire Enterprise incorporates the COBIT framework through custom configuration assessment profiles used to help organizations maintain compliance with those parts of the standard.


Bill 198 Resources

    • Infosecurity Europe 2012 Wrap Up
      Infosec expert and ‘cynic’ Javvad Malik summarizes the most important aspects of Infosecurity Europe 2012. Some of the top trends and key takeaways: risk management and the rising role of the CISO....
    • Communicating the value of Information Security – Part 3
      In part 2 of this series, I talked about getting to know the "language" of your particular business. This week, I want to talk about how to leverage Enterprise Architects, if they are available. They can be...
    • The Growing Pains of the New CISO
      Recently we had an opportunity to interview Phil Cracknell (@PCracknell on Twitter) during Infosecurity Europe. Infosec expert and ‘cynic’ Javvad Malik asks Mr. Cracknell, Global Security and...

To read more blog posts, visit the State of Security Blog.

To browse more, visit the company news section.

Resource Library

Resource Library

Read, watch or listen to valuable information about Tripwire solutions, customer success stories, IT security and compliance best practices, and more.

Resource Library