One of the most critical steps in defining the requirements for SOX compliance is determining the IT systems and services that must be secured and audited. There is a tendency for systems and activities required for compliance to "grow to the size of their environment." Organizations need to resist this tendency.