ZenGRC

Sarbanes-Oxley Act of 2002 IT Primer: Everything You Should Know

The Sarbanes-Oxley Act of 2002, enacted in response to major corporate scandals, established stringent regulations including the creation of the PCAOB, enhanced corporate governance and financial disclosure requirements, and imposed severe criminal penalties to ensure accountability of publicly traded companies, with specific compliance provisions such as Section 302 focusing on disclosure controls and personal accountability of corporate officers.

The Sarbanes-Oxley Act of 2002 (SOX), named after Paul Sarbanes and Michael Oxley, is a law that implements regulations on publicly traded companies. In 2002, the US Congress passed SOX after a series of public scandals by large corporations such as Enron, Tyco International, and WorldCom that led to a stock market plummet. The legislation was intended to quell public fears of corporate misconduct and require greater accountability by management and Boards of Directors when reporting financial data. However, Sarbanes-Oxley turned into a larger and more complex piece of legislation than originally planned.

The Major Provisions of Sarbanes-Oxley

The Sarbanes-Oxley Act of 2002 presented five main provisions:

  1. 1.Creation of the Public Company Accounting Oversight Board (PCAOB) and restrictions on public accounting firm auditors, including independence standards.
  2. 2.Establishment of corporate governance requirements and audit committee safeguards.
  3. 3.Addition of disclosure requirements for financial reports and press releases.
  4. 4.Establishment of criminal penalties for public companies and CEOs/CFOs in the event of falsely certifying financial reports.
  5. 5.Establishment of criminal penalties of 20 to 25 years for obstruction of justice and securities fraud.

Sarbanes-Oxley Compliance

Sarbanes-Oxley compliance requirements fall into several different areas, focusing on corporate responsibility and governance. Within those, specific issues for information security also exist. Many feel overwhelmed by SOX compliance, but the reality lies in focusing on what pertains to an individual organization.

SOX Section 302

Section 302 focuses on Disclosure Control and Procedures. SOX 302 disclosures are traditionally unaudited but reviewed by independent auditors. These quarterly reports discuss all the processes and controls in place for public disclosures and focus on the personal accountability of signing officers. Key points include:

  1. 1.The signing officer has reviewed the report.
  2. 2.Based on the officer’s knowledge, the report does not contain any untrue statement of a material fact or omit to state a material fact necessary to make the statements not misleading.
  3. 3.The financial statements and other financial information included in the report fairly present the financial condition and results of operations.

In summary, executive officers personally take responsibility for the truthfulness and completeness of the documents they sign.

SOX Section 401

SOX 401 focuses on financial disclosures being prepared in accordance with specified accounting standards and requires reporting of off-balance sheet disclosures. These reports relate to annual and quarterly public financial reporting and are formally audited by a public accounting firm.

SOX Section 404

Section 404 focuses on the scope and adequacy of internal controls and procedures for financial reporting. This section is where most organizations struggle and spend the majority of their SOX compliance efforts. The SEC outlines steps for evaluating and documenting internal controls:

  • Assess reporting risks, both internal and external.
  • Evaluate entity-level controls and their precision.
  • Determine if multiple controls address the same risk and which is most efficient.
  • Assess whether controls are automated or manual and the associated risks.
  • Identify only those controls that adequately address financial reporting risks.

Next, determine whether the controls work and the risk if they fail. The greater the risk, the greater the evidence needed to support effective controls. Report conclusions on overall effectiveness and deficiencies. If a material weakness is found, controls cannot be considered effective. A material weakness is defined as one or more control deficiencies that create a reasonable possibility of a material misstatement in financial statements.

SOX Section 409

SOX 409 is referred to as the “Real Time Issuer Disclosures” section. Issuers are required to disclose to the public, on an urgent basis, information on material changes in their financial condition or operations. Disclosures should be easy to understand and supported by trend and qualitative information. For information security, a security breach would be considered a material change.

SOX Section 806

SOX 806 focuses on whistleblower protections. Employees who provide information about violations are protected by the U.S. Department of Labor. If a company retaliates against such an employee, the Department of Justice can criminally charge the responsible parties.

SOX Section 906

SOX 906 enforces corporate responsibility for filing financial reports. CEOs and CFOs must submit standard documents with their periodic SEC financial statement reports. Unlike SOX 302 certifications, SOX 906 certifications are more straightforward.

Sarbanes-Oxley and Information Security

For information security professionals, the overlap of SOX 302 and SOX 404 creates the most risk in terms of SOX compliance. Section 302 discusses personal certification of financial reporting controls by the CEO and CFO, while Section 404 focuses on internal controls. Neither section specifically defines "control," leaving it open to interpretation, including those related to information systems.

Sarbanes-Oxley created the PCAOB to guide auditors through best practices, but the standards provide little insight into IT controls. The PCAOB selected the Committee of Sponsoring Organizations (COSO) framework to create guidelines for structuring internal controls. Although not specifically required by legislation, the PCAOB’s adoption of COSO makes it a safe choice.

The COSO framework addresses areas such as information security controls, control environment, risk assessment, control activities, information and communication, and monitoring.

Many organizations also turn to the Control Objectives for Information and related Technology (COBIT) framework. COBIT organizes 34 IT processes into categories of planning and organization, acquisition and implementation, delivery and support, and monitoring. By ensuring an organization has a security policy, security standards, access and authentication procedures, network security details, monitoring, segregation of duties, and physical security, a company can put together an appropriate Sarbanes-Oxley compliance program.

A major challenge for IT security departments is appropriate access. While SOX security requirements may appear more lax than other regulations like PCI DSS or ISO 27001, they often form the foundation of best practices. One specific requirement involves monitoring user access to data, requiring mature procedures for user provisioning, de-provisioning, and granting privileged access. SOX requires auditors and IT personnel to regularly review access rights, and senior management must sign off on those reviews, leading to more mature access control procedures.

Regular access reviews not only lead to SOX compliance but also help ensure organizational security. In this way, Sarbanes-Oxley compliance helps protect companies from malicious intrusion.

While Sarbanes-Oxley was a significant change to corporate culture in 2002, its ongoing legacy helps establish financial reporting trust and information security best practices.