Question

Difficulty: MediumRegulatory Compliance and Legal Requirements Management

A publicly traded healthcare technology firm in the United States is deploying an enterprise resource planning (ERP) system to process billing records and forecast quarterly corporate revenues. During an operational risk review, the audit committee emphasizes that the application must enforce strict separation of duties, tamper-evident audit logging, and verifiable internal controls specifically to prevent fraudulent reporting of financial statements. Which of the following regulatory frameworks or federal mandates primarily governs these financial data integrity requirements?

  1. Sarbanes-Oxley Act (SOX)Answer
  2. B
    Health Insurance Portability and Accountability Act (HIPAA)
  3. C
    Payment Card Industry Data Security Standard (PCI-DSS)
  4. D
    Federal Information Security Modernization Act (FISMA)

Answer

Sarbanes-Oxley Act (SOX)
The correct option is Sarbanes-Oxley Act (SOX). SOX regulates US publicly traded companies and mandates rigorous internal controls over financial data reporting, separation of duties, and audit logs to prevent corporate fraud and ensure accounting integrity.

Step-by-Step Solution

1
Analyze the organizational profile and core compliance requirements in the scenario.
The organization is a US publicly traded enterprise, and the target system controls focus on preventing fraudulent financial reporting and ensuring internal control over accounting statements.
Identifying the organizational entity type and regulatory scope narrows down the applicable legislation.
2
Differentiate between health data privacy, credit card transaction security, federal agency frameworks, and public company financial oversight.
SOX specifically targets internal controls surrounding corporate accounting and financial reporting, whereas HIPAA addresses PHI, PCI-DSS addresses credit cards, and FISMA addresses US federal agencies.
Legal mandates apply to specific operational domains and asset types.
3
Select the mandate governing financial auditing integrity.
Sarbanes-Oxley Act (SOX) is the correct regulation.
SOX Section 404 mandates management and auditors to establish and report on internal controls over financial reporting.

Key Concept

Sarbanes-Oxley Act (SOX) Statutory Scope and Internal Financial Controls
Rate this question