• No standard including SOX, RFR/fact, sas 70, hipaa, pci, MA 201 etc. Provide guidance on implementation. At the end of the day you dbas know your systems and weaknesses better than auditors. That said there are no requirements on how to secure or configure databases to be compliant with sox.

    Regardint the point of this thread, if you want to self assess across compliance requirements check out appdetective or ask me, I've dabbled in db auditing departments at my firm