A financial services firm operating in the United States is updating its security governance controls to maintain compliance with Sarbanes-Oxley Act (SOX) Section 404 requirements. The security manager must implement controls that verify the integrity and accuracy of internal financial reporting data stored within enterprise systems. Which of the following actions best fulfills this specific regulatory requirement?
- AReclassifying enterprise security policy documentation into non-binding operational guidelines for system administrators.
- Establishing mandatory segregation of duties and enforcing immutable audit logging for all configuration changes affecting financial reporting systems.Cevap
- CDelegating data ownership authority and regulatory liability for financial databases to the third-party cloud infrastructure hosting provider.
- DDeploying network perimeter firewalls to patch application-level buffer overflow vulnerabilities in financial software.
Cevap
Establishing mandatory segregation of duties and enforcing immutable audit logging for all configuration changes affecting financial reporting systems.
The Sarbanes-Oxley Act (SOX) Section 404 mandates that organizations establish and maintain internal controls and financial reporting procedures. Implementing segregation of duties prevents any single individual from executing fraudulent transactions without oversight, while immutable audit logging ensures that configuration modifications to financial reporting systems can be independently verified by auditors.
Adım Adım Çözüm
Anahtar Kavram
Sarbanes-Oxley Act (SOX) Financial Compliance and Internal Controls