How are CMMI and SOX (SarBox / Sarbanes-Oxley) Related?
They’re not. Well… at least not in the way that many people think they might be. See, many people think that because the Sarbanes-Oxley Act of 2002 (which we’ll just call SarBox) frequently involves business process and IT infrastructure and related systems, that it involves CMMI. But, in actually, the connection to CMMI is rather weak and always is a function of the organization’s intentional effort to connect the two. SarBox is about public company corporate governance. It is a US law that aims to eliminate the excuse by corporate leaders of public companies that they “didn’t know” some bit of information about their company that could result in mistakes (or outright lies) about accounting, work-in-process, inventory, earnings reports, valuations, sales/revenue forecasts, and so on. Its origin is in the several accounting scandals revealed in the late 1990’s and early 2000’s. The intersection of SarBox and CMMI is only in that companies working towards SarBox compliance are very of