SOX IT Security Controls
The Sarbanes-Oxley Act (SOX) requires public companies to maintain internal controls over financial reporting. IT security controls are essential for protecting the systems that process financial data.
SOX Section 404
Section 404 requires management to assess and report on internal control effectiveness. IT general controls (ITGCs) are a critical component.
Key IT General Controls
Access Controls
- User authentication and authorization
- Privileged access management
- Segregation of duties
- Access reviews and recertification
- Change control procedures
- Testing and approval processes
- Emergency change procedures
- Documentation requirements
- Job scheduling and monitoring
- Backup and recovery
- Incident management
- Problem management
- SDLC controls
- Code review processes
- Testing requirements
- Deployment controls
- User authentication on endpoints
- Audit logging of access and changes
- Patch management for financial systems
- Data protection and encryption
- Malware protection
Change Management
Computer Operations
Program Development
Endpoint Security for SOX
Endpoint controls supporting SOX compliance:
Contact our team for SOX compliance assistance.