While perusing a draft of “IT Control Objectives for Sarbanes-Oxley, 2nd Edition,” I discovered several profound statements in the section on compliance and IT governance: “There is no such thing as a ...