Sarbanes-Oxley IT administration reduced from three days to two hours
Baltimore Aircoil is a worldwide manufacturer and marketer of heat transfer and ice thermal storage products that conserve resources and respect the environment. Typical customer projects require precise engineering and design, special materials, and custom manufacturing requirements. The company’s IT department needed a system to effectively track, capture and display information required by auditors regarding IT operations, problem and incident management, and change management. In Serena Mashup Composer, Baltimore Aircoil found a product to address IT audit requirements, as well as a highly flexible solution that could be applied to manufacturing, engineering, and customer service departments to improve collaboration, visibility, accountability, and communications. With Business Mashups, preparation for Sarbanes-Oxley (SOX) IT audits has been reduced from three days to two hours.
"Managing change is critical. Without Mashup Composer, we would not be able to meet Sarbanes-Oxley requirements.”
- DJ Griffin, manager of ITit, Baltimore Aaircoil
Baltimore Aircoil Success Story (pdf)»
Challenge
- Increasingly rigorous government audit requirements
- Lengthy process of retrieving IT data and reports for audits
- Inefficient IT employee provisioning process
- Need for collaborative, workflow-based system to improve visibility and communications
Solutions
- Serena Mashup Composer selected for its robust, highly-flexible solution for managing and orchestrating change—companywide system
Results
- Preparation for Sarbanes-Oxley IT audits reduced from three days to two hours
- Reduced risk via accurate, retrievable information and reporting
- Improved visibility for more effective IT decision-making and management
- IT able to spend more time serving internal clients and driving strategic projects
"All approvals are synchronized with Mashup Composer. The result is streamlined collaboration with no paperwork—all the development processes are automated and audited.”
- DJ Griffin, manager of ITit, Baltimore Aaircoil
CHALLENGE
Baltimore Aircoil’s parent company, Amsted Industries, fully supports the Sarbanes-Oxley Act. “Even though we’re a private company, Amsted wanted us to be fully SOX-compliant and pass our audits with-out issue. It was important to have best practice processes in place to maintain full transparency and operational excellence,” says DJ Griffin, manager of IT for Baltimore Aircoil. Griffin knew that Baltimore Aircoil did not have an adequate system to keep track all of the exhaustive information required by SOX with regards to IT operations, problem and incident management, and change management. “In our first audit, we had problems pulling all the information together for auditors. It was an extremely difficult process. We were using another application at the time, and it was taking half a day just to track down one piece of information.” The company needed a collaborative, workflow-based system to improve visibility and communications.
SOLUTION
Baltimore Aircoil took a strategic and long-range approach in its search for a solution. “When we looked at Serena
and other leading change management vendors on the market, Serena Mashup Composer was the clear champion in terms of flexibility,” says Griffin. “It was the best solution on the market for managing SOX audits.” In a company where change is constant across all departments and geographies, Baltimore Aircoil found that Business Mashups could not only solve IT’s problems, but could also solve workflow and collaboration issues within manufacturing, customer service, and engineering departments. “This was a solution that could benefit the whole company,” says Griffin.
Baltimore Aircoil is now using Business Mashups to monitor all IT operations including problem and incident management, change management, and employee provisioning. “It has been huge in helping us to get ready for audits as well as streamlining our processes for handling IT helpdesk calls, application changes, setting up new users, and a lot more,” says Griffin. Changes to software applications in a production environment now go through a series of requests and approvals managed by Mashup Composer, an efficient process that requires no paperwork. “We feel confident that with Mashup Composer, audits will be quicker because the user interface and reporting makes it easy for ‘outsiders’ to grasp. The information is crisp and clean, and the graphics remove communication
barriers. Auditors immediately understand what’s going on,” says Griffin.
With Mashup Composer, the company now also has an automated process for tracking employee provisioning, as required by SOX. Serena tracks requests and approvals for new IT employees who require access to internal systems. The solution tracks new accounts, password activity, timestamps as well as closed account activity when an employee is terminated or quits. “With Serena Business Mashups we have a collaborative, workflow-based solution, which is creating order out of chaos,” concludes Griffin.
RESULTS
With Serena Business Mashups, preparation for SOX IT audits has been reduced from three days to two hours. With quick access to information and reports, Baltimore Aircoil is nimbly meeting the scrutiny of auditors and confidently meeting SOX requirements while reducing company risk. As a result, IT is devoting more time to serving internal clients and driving strategic projects.
Applying Business Mashups to solve IT challenges has streamlined business processes while improving collaboration, productivity, and performance. With its unique flexibility, Business Mashups may be applied to engineering, customer service, and manufacturing departments in the future. “We have people coming to us all the time asking if Mashup Composer can do ‘this’ or ‘that’,” says Griffin. “Our answer is always ‘yes’. The beauty of Mashup Composer is its open flexibility to solve unique business challenges. You’re not locked in to one process.”
Baltimore Aircoil Success Story (pdf)»