Because Sarbanes-Oxley doesn’t specify IT controls in detail, most auditors are using COBIT to evaluate SOX IT compliance. But COBIT itself provides only control objectives; it’s up to IT managers and ...