SOX IT Security Controls

The Sarbanes-Oxley Act (SOX) requires public companies to maintain internal controls over financial reporting. IT security controls are essential for protecting the systems that process financial data.

SOX Section 404

Section 404 requires management to assess and report on internal control effectiveness. IT general controls (ITGCs) are a critical component.

Key IT General Controls

Access Controls

  • User authentication and authorization
  • Privileged access management
  • Segregation of duties
  • Access reviews and recertification
  • Change Management

  • Change control procedures
  • Testing and approval processes
  • Emergency change procedures
  • Documentation requirements
  • Computer Operations

  • Job scheduling and monitoring
  • Backup and recovery
  • Incident management
  • Problem management
  • Program Development

  • SDLC controls
  • Code review processes
  • Testing requirements
  • Deployment controls
  • Endpoint Security for SOX

    Endpoint controls supporting SOX compliance:

  • User authentication on endpoints
  • Audit logging of access and changes
  • Patch management for financial systems
  • Data protection and encryption
  • Malware protection

Contact our team for SOX compliance assistance.