Home > Ask the Security Experts > Security Management Questions & Answers > Is the Sarbanes-Oxley Act being enforced?
Ask The Security Expert: Questions & Answers
EMAIL THIS

Is the Sarbanes-Oxley Act being enforced?

Mike Rothman EXPERT RESPONSE FROM: Mike Rothman

Pose a Question
Other Security Categories
Meet all Security Experts
Become an Expert for this site


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


>
QUESTION POSED ON: 27 February 2007
What happens when a company does not comply with the Sarbanes-Oxley Act? Have there been any criminal convictions? Is there data to show that the U.S. Securities and Exchange Commission (SEC) is actively pursuing companies who fail to comply?

>
EXPERT RESPONSE
To my knowledge, there have been no enforcement actions to date on a Sarbanes-Oxley violation. There are a couple of reasons for the lack of prosecutions. First, the federal government works slowly, unlike many fast-paced commercial businesses.

Also, the lack of definitive regulations has delayed much of the current enforcement; SOX requirements may be loosened in the near term. It seems, too, that the SEC is giving public companies the room to fix problems that are identified during examinations.

Implementing strong financial controls requires a change in process, culture and technology. This shift takes time, and the SEC hasn't gotten around to chasing folks yet.

To be clear, examinations are happening every day, and not many folks are "passing." In many cases, it has very little to do with security controls. The burden of financial controls and ensuring the integrity of financial reporting is stymieing many organizations, especially the small ones. "Passing" is also still somewhat subjective, meaning your grade may depend on your examiner and probably what side of the bed he/she woke up on that day. A lot of the industry has agreed on COBIT as an acceptable framework for Sarbanes-Oxley compliance.

Regulations are in place to make sure that organizations do the right thing. Whether SOX is enforced or not, it's probably a good idea for a company to have tight financial controls in place. An organization should also make efforts to protect customers' private data, regardless of HIPAA, GLBA or PCI.

More information:

  • In this webcast, learn the five steps that can lead to Sarbanes-Oxley compliance.
  • See how the SEC made it easier for small businesses to comply with Sarbanes-Oxley regulations.


  • Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


    RELATED CONTENT
    Security Management
    What's your advice for getting other business units to contribute to crafting an effective information security policy?
    How can organizations secure implanted microchips and RFID tags?
    Any recommendations for recruiting information security pros?
    I am concerned that a former employee will utilize corporate information in a malicious way.
    Is it necessary to grant a full administrative privileges to a security administrator?
    Recently I found my computer's serial number had been reported stolen. Will I face legal repercussions?
    What are the possible benefits of microchip implants and RFID tags for employees?
    Is it against HIPAA regulations to permanently store sensitive information?
    Two-tier distributed systems vs. three-tier distributed systems
    How to prevent software piracy

    Sarbanes-Oxley Act
    Security visualization helps make log files work
    The Little Black Book of Computer Security, 2nd Edition
    Information security book excerpts and reviews
    RSA attendees see data classification, rights management projects stumble
    Hannaford breach illustrates dangerous compliance mentality
    Does SOX provision email archiving?
    PCI compliance drives identity management spending, says IBM's GRC chief
    How to conduct an efficient and thorough employee access review.
    IBM to boost security spending, push PCI DSS program
    What types of software can help a company perform a security risk assessment?
    Sarbanes-Oxley Act Research

    Information Security Laws, Investigations and Ethics
    MIT case shows folly of suing security researchers
    TJX hacking ring charged in federal indictment
    IBM X-Force report critical of independent security researchers
    Valuable lesson emerges from DNS flaw handling
    Learn from NIST: Best practices in security program management
    Data breach laws have no effect on prevention, researchers say
    Botnet disruption raises ethical concerns among researchers
    Recently I found my computer's serial number had been reported stolen. Will I face legal repercussions?
    Disclosure Laws Fail as an Incentive to Secure Data
    Government and cybersecurity

    RELATED GLOSSARY TERMS
    Terms from Whatis.com − the technology online dictionary
    CALEA  (SearchSecurity.com)
    cyberstalking  (SearchSecurity.com)
    cypherpunk  (SearchSecurity.com)
    HSPD-7  (SearchSecurity.com)
    I-SPY Act  (SearchSecurity.com)
    Information Awareness Office  (SearchSecurity.com)
    intelligence community  (SearchSecurity.com)
    lawful interception  (SearchSecurity.com)
    lifestyle polygraph  (SearchSecurity.com)
    vulnerability disclosure  (SearchSecurity.com)

    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary



    Search and Browse the Expert Answer Center
    Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
    Browse our Expert Advice



    Find Security Solutions for Your Business
    Targeted Security Channel Tips for Resellers, Integrators and Consultants
    TechTarget Security Media
    Information Security View this month\\'s issue and subscribe today.
    Information Security Decisions Apply online for free conference admission.
    SearchSecurity.com
    HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




    All Rights Reserved, Copyright 2003 - 2008, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts