A financial institution is required to comply with SOX. Which of the following is a key focus area for IT under SOX?
The Sarbanes-Oxley Act (SOX) mandates that public companies establish and maintain internal controls over financial reporting. IT General Controls (ITGC) are foundational to this, ensuring the integrity, reliability, and security of the information systems that process financial data. These controls, encompassing areas like access management, change management, and operations, directly support the accuracy of financial statements, which is a core requirement of SOX Sections 302 and 404. Without robust ITGC, the reliability of financial data cannot be assured.
Why this answer
SOX Section 404 requires management to assess and auditors to attest to the effectiveness of internal controls over financial reporting (ICFR). IT general controls (ITGCs) — change management, access control, IT operations, and SDLC controls — are the primary mechanism by which IT supports that assertion for financial systems. Encryption, breach notification, and privacy are important but are not the defining IT compliance focus of SOX.
Exam trap
CISSP often tests the distinction between financial-reporting integrity regulations (SOX) and privacy/security regulations (GDPR, HIPAA, GLBA), so candidates who see 'encryption' or 'breach notification' and assume they are SOX requirements pick the wrong answer.
How to eliminate wrong answers
Option B is wrong because encryption of data at rest is a security control that may support SOX compliance but is not the key IT focus area SOX mandates; SOX does not prescribe specific cryptographic controls. Option C is wrong because breach notification procedures are driven by state breach laws, HIPAA, and GDPR-style regulations, not SOX, which addresses financial reporting integrity. Option D is wrong because privacy of customer data is the domain of privacy regulations (GDPR, CCPA, GLBA privacy provisions), whereas SOX targets the accuracy and reliability of financial disclosures.