Bill 198

Tripwire simplifies compliance with Bill 198—the Canadian equivalent to SOX

Bill 198, the Canadian counterpart to the U.S. Sarbanes Oxley Act (SOX), was instituted to regulate the efficiency of financial reporting and operations in publicly held companies. In order to comply with Bill 198, companies must implement and evaluate internal controls over financial reporting, as well as provide documentation that demonstrates the effectiveness of the information security in place.


Tripwire provides internal controls over financial reporting enabling you to comply with change management principles of Bill 198.

Tripwire delivers a comprehensive solution by:

  • Providing continuous compliance with the requirements of Bill 198 along with comprehensive configuration assessment policies.
  • Tracking and auditing all change and suspicious events, and generating an audit trail of authorized and unauthorized change to help evaluate whether their controls are effective.
  • Automating the repair of configurations that intentionally or accidentally fall from secure and compliant states
  • Investigating the source of any unauthorized change to ensure the timely disclosure of management’s report on the effectiveness of the company’s controls and detecting (and reporting) any material weaknesses in them.

COBIT

COBIT addresses the three elements of the term “disclosure control and procedures requirements” and is a good starting point for companies that seek to comply with the internal control and disclosure control and procedures requirements of Bill 198. Tripwire Enterprise incorporates the COBIT framework through custom configuration assessment profiles used to help organizations maintain compliance with those parts of the standard.


Bill 198 Resources

    • Happy New Year! Data Breach Roundup – January 2012
      It’s time for the January 2012 edition of the Data Breach Roundup! I’m trying out a cool new curation tool called Storify. Please let me know what you think of this format. Thanks! [View the story...
    • Infosec and too much to do
      One of the most common concerns I hear about from the enterprises I speak with all the time is that of having too much to do.  There’s never enough [time, money, people] to go around. So, what are they...
    • Safe, Dead or Lucky? (Knowing Good From Bad)
        There’s a saying among North American wildlife enthusiasts that goes something like, “Red touches yellow kills a fellow. Red touches black, friend of Jack.” It’s a pleasantly singsongy warning...

To read more blog posts, visit the State of Security Blog.

To browse more, visit the company news section.

Resource Library

Resource Library

Read, watch or listen to valuable information about Tripwire solutions, customer success stories, IT security and compliance best practices, and more.

Resource Library