CISSP Security and Risk Management Practice Question
A financial institution is required to comply with SOX. Which of the following is a key focus area for IT under SOX?
⚠ Common exam trap
CISSP often tests the distinction between financial-reporting integrity regulations (SOX) and privacy/security regulations (GDPR, HIPAA, GLBA), so candidates who see 'encryption' or 'breach notification' and assume they are SOX requirements pick the wrong answer.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
IT general controls for financial systems
SOX Section 404 requires management to assess and auditors to attest to the effectiveness of internal controls over financial reporting (ICFR). IT general controls (ITGCs) — change management, access control, IT operations, and SDLC controls — are the primary mechanism by which IT supports that assertion for financial systems. Encryption, breach notification, and privacy are important but are not the defining IT compliance focus of SOX.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
IT general controls for financial systems
Why this is correct
The Sarbanes-Oxley Act (SOX) mandates that public companies establish and maintain internal controls over financial reporting. IT General Controls (ITGC) are foundational to this, ensuring the integrity, reliability, and security of the information systems that process financial data. These controls, encompassing areas like access management, change management, and operations, directly support the accuracy of financial statements, which is a core requirement of SOX Sections 302 and 404. Without robust ITGC, the reliability of financial data cannot be assured.
- ✗
Encryption of data at rest
Why it's wrong here
While encryption of data at rest is a critical security measure for protecting sensitive information from unauthorized access, it is not a primary or specific mandate of the Sarbanes-Oxley Act. SOX compliance primarily focuses on the accuracy and reliability of financial reporting and the internal controls supporting it, rather than general data protection strategies. Although encryption might be an underlying technical control supporting data integrity, it's not the direct objective or a specific requirement explicitly called out by SOX.
- ✗
Breach notification procedures
Why it's wrong here
Breach notification procedures, which dictate how organizations must inform affected parties following a data security incident, are primarily driven by data privacy regulations such as GDPR, CCPA, or various state-specific data breach laws. The Sarbanes-Oxley Act, conversely, is concerned with the accuracy and reliability of financial statements and the internal controls governing financial reporting. While a breach could indirectly impact financial systems, SOX does not directly mandate or focus on the procedures for notifying individuals about data breaches.
- ✗
Privacy of customer data
Why it's wrong here
The privacy of customer data, which involves the collection, use, storage, and disclosure of personally identifiable information (PII), is a central tenet of regulations like the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), or HIPAA for healthcare. The Sarbanes-Oxley Act, however, is specifically designed to protect investors by improving the accuracy and reliability of financial reporting and corporate disclosures. While financial institutions handle customer data, SOX does not directly regulate or focus on the privacy aspects of that data.
Go deeper
Related to this question
Learn chapter
Access Control Models and Mechanisms
Key term
Encryption
Encryption is the process of converting readable data into a secret code to prevent unauthorized access.
Key term
Compliance
Compliance is the process of ensuring that an organization follows laws, regulations, standards, and internal policies that apply to its operations and data handling.
About these practice questions
This CISSP question is part of Courseiva's 816-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.