Quality, Expert-Derived Cybersecurity Documentation To Keep Organizations Secure, Compliant & Resilient  |  Got Questions? +1-307-241-8740
ComplianceForge

Sarbanes-Oxley Act Of 2002 (SOX)

The Sarbanes-Oxley Act of 2002 (SOX) was passed due to the accounting scandals at Enron, WorldCom, Global Crossing, Tyco and Arthur Andersen, that resulted in billions of dollars in corporate and investor losses. These huge losses negatively impacted the financial markets and general investor trust. SOX mandates a wide-sweeping accounting framework for all public companies doing business in the United States.

SOX itself is organized into eleven sections, but sections 302, 404, 401, 409, 802 and 906 are the most important in terms of compliance. More specifically, SOX established new accountability standards for corporate boards and auditors, established a Public Company Accounting Oversight Board (PCAOB) under the Security and Exchange Commission (SEC), and specified civil and criminal penalties for noncompliance.

SOX Compliance
If applicable, a company must establish a financial accounting framework that can generate financial reports that are readily verifiable with traceable source data. This source data must remain intact and cannot undergo undocumented revisions. In addition, any revisions to financial or accounting software must be fully documented as to what was changed, why, by whom and when.
Common Questions

Frequently-Asked Questions

Here are answers to common questions about SOX and cybersecurity:

When was the Sarbanes-Oxley Act passed?
The Sarbanes-Oxley Act of 2002 was signed into law on July 30, 2002, as Public Law 107-204. Congress passed it after accounting failures at Enron, WorldCom and other public companies damaged investor confidence. The law created the Public Company Accounting Oversight Board (PCAOB) under SEC oversight, set new accountability standards for corporate officers and auditors, and added criminal penalties for destroying or falsifying records and for knowing or willful false certifications by executives.
What is SOX Section 404?
Section 404 of the Sarbanes-Oxley Act requires a public company's annual report to include management's report on internal control over financial reporting, with management's assessment of its effectiveness as of the end of the most recent fiscal year. Section 404(b) adds an attestation report from the company's registered public accounting firm. Under Section 404(c), added by the Dodd-Frank Act, companies that are neither accelerated filers nor large accelerated filers are exempt from the 404(b) auditor attestation.
What does SOX Section 302 require of executives?
Section 302 requires a company's principal executive and principal financial officers to certify each quarterly and annual report filed with the SEC. The certifications cover the accuracy of the report and the officers' responsibility for disclosure controls and procedures and for internal control over financial reporting, and they are filed as exhibits to the periodic reports. Section 906 separately creates criminal penalties for knowing or willful false certifications.
How does IT security affect SOX compliance?
IT security matters to SOX because internal control over financial reporting depends on the systems that process financial data. PCAOB Auditing Standard 2201 directs auditors to understand how IT affects a company's flow of transactions and to consider IT general controls and application controls that support financial reporting. Changes to financial or accounting software should be documented, including what changed, why, by whom and when. ComplianceForge's editable cybersecurity policies and IT controls support SOX Section 302 and 404 compliance.
How often is SOX compliance audited?
SOX compliance runs on an annual cycle with quarterly checkpoints. Management assesses internal control over financial reporting as of the end of each fiscal year for the annual report, and for accelerated and large accelerated filers the external auditor attests to that assessment as part of the annual audit. Executive certifications under Section 302 accompany every quarterly and annual report, so control issues can surface in any quarter.