Preview

The Sarbanes-Oxley Act

Best Essays
Open Document
Open Document
2729 Words
Grammar
Grammar
Plagiarism
Plagiarism
Writing
Writing
Score
Score
The Sarbanes-Oxley Act
Abstract
The purpose of this paper is to create a policy that will ensure Firion 's compliancy with governmental regulations concerning cyber security as well for the protection of the company and its customers.

Introduction
Firion is a “corporation which develops, produces, and markets specialized jackets used in waste disposal and other safety-related applications” (UMUC, 4). Like most modern companies, Firion utilizes technology for increased efficiency in production, networking among employees, and to store and maintain important data. For example, databases contain employee and customer information as well as sensitive information about the research concerning Firion’s new glove designs and coatings. It is of extreme importance
…show more content…
The Sarbanes-Oxley Act is organized into eleven titles and protects from errors in accounting to fraudulent practices. IT and financial departments are affected due IT departments the daunting task of having to produce and preserve a archive of corporate files in a way that is lucrative and that complies with the requirements set forth by the legislation. The Sarbanes-Oxley Act states that all records can only be saved for five years. SOX allow enough information about transactions that would allow one to identify where misstatements due to fraud or human error could occur. There is information and controls set forth to detect or prevent fraud ("What is sox," …show more content…
The missing of a formal acceptable use policy (AUP) did not give user or management a guideline on the day-to-day activities. The incident involving Laura requesting trial software without getting proper security review and authorization shows the lack of security awareness and proper request for exception procedure. According a report from Ernst & Young, over 75% of security breaches are caused by activities by internal users (H. M. P. S. & Wijayanayake, 2009). Misuse of computer resources in work place not only reduced productivities but also bring additional risk to company’s reputation. Activities like surfing the web and participating in social networking sites might bring questionable contents to the work place. These contents can be seen as a form of sexual harassment. The Melissa virus, founded in 1999, was originally planted in an alt.sex Usenet newsgroup message. The billions of dollars of productivity lost and the negative publicity can tarnish the image and the business of Firion. Without a formal review on software request, the IT security organization will not be able to design a security solution to cover the user base. This gap will allow both internal and external intruders to plant software or Trojan to disrupt services or stealing

You May Also Find These Documents Helpful

  • Better Essays

    Whitman, M., & Mattord, H. (2004). Information Security Policy. In Management of information security(Fourth ed., p. 154). Boston, Mass.: Thomson Course…

    • 2101 Words
    • 8 Pages
    Better Essays
  • Satisfactory Essays

    IT255 Project 1

    • 663 Words
    • 2 Pages

    At Richman Investments the personnel is accountable for the appropriate use of IT assets. Therefore, it is in the best interest of the organization to ensure employees handle security procedures with integrity. It is essential to create a strong AUP (Acceptable Use Policy) procedure and as part of the process, require employees sign an agreement to guarantee they understand and conform to implemented rules and regulations. In addition, the company will conduct security awareness training, annual security exercises, notices about securing information, and constant reminders security is everyone’s responsibility.…

    • 663 Words
    • 2 Pages
    Satisfactory Essays
  • Good Essays

    The Sarbanes-Oxley Act of 2002 is mandatory. All large and small organizations must comply with this act. The legislation came into existence in 2002 as a result of a number of corporate and accounting scandals and introduced major changes to the regulation of financial practice and corporate governance. The main architects of the acts were Senator Paul Sarbanes and Representative Michael Oxley. The SOX act protects the shareholders from forged representations in corporate financial statements. The financial information on which the investors rely should be truthful and its accuracy must be verified by an independent third party.…

    • 187 Words
    • 1 Page
    Good Essays
  • Satisfactory Essays

    Sarbanes-Oxley Act

    • 534 Words
    • 2 Pages

    The Sarbanes-Oxley Act of 2002, often abbreviated as SOX, is a legislative act passed by Congress in response to the Enron and WorldCom financial scandals. The primary purpose of SOX is to protect shareholders from errors or fraudulent reporting by the company they have invested in. The Sarbanes-Oxley act is enforced by the Securities and Exchange Commission, a department dedicated to ensuring compliance to SOX from all firms, and is also responsible for revising provisions of the act in order to keep it current and up to date.…

    • 534 Words
    • 2 Pages
    Satisfactory Essays
  • Better Essays

    Senator Paul Sarbanes and Representative Michael Oxley drafted the Sarbanes-Oxley Act or "SOX" in 2002 in order to curb the incidence of corporate fraud. The “Act” was signed into law on July 30th 2002 by President George W. Bush with the express purpose of restoring public confidence in the financial markets; and after enacting “the Act”, neither Sarbanes or Oxley would run for re-election in the 2006 elections (Jahmani & Dowling, 2008). The intent of the SOX Act was to protect investors, and any other stakeholders in a company, by improving the validity and reliability of corporate disclosures, such as financial statements and earnings reports, pursuant to existing securities laws and regulations governing publically traded companies (Kessel, 2011). The SOX Act holds corporate Chief…

    • 1488 Words
    • 6 Pages
    Better Essays
  • Satisfactory Essays

    The act enacted in response to financial problems to protect the public from accounting errors and fraud. The act does not specify how a business should store their records; rather, it defines which records are to be stored and for how long they’re going to be stored. The act affects the financial corporations and the IT department. All business records must be saved for more than five years. The consequences for not following the rules are fines, imprisonment, or both. There are several sections to the Sarbanes-Oxley Act that describes the establishment, registration, auditing, quality control, rules, investigations…

    • 382 Words
    • 2 Pages
    Satisfactory Essays
  • Satisfactory Essays

    Sarbanes-Oxley Act

    • 558 Words
    • 3 Pages

    The Sarbanes-Oxley Act of 2002 (often shortened to SOX) is legislation enacted in response to the highprofile Enron and WorldCom financial scandals to protect shareholders and the general public from accounting errors and fraudulent practices in the enterprise. The act is administered by the Securities and Exchange Commission (SEC), which sets deadlines for compliance and publishes rules on requirements. Sarbanes-Oxley is not a set of business practices and does not specify how a business should store records; rather, it defines which records are to be stored and for how long. The legislation not only affects the financial side of corporations, it also affects the IT departments whose job it is to store a corporation's electronic records. The Sarbanes-Oxley Act states that all business records, including electronic records and electronic messages, must be saved for "not less than five years." The consequences for non-compliance are fines, imprisonment, or both. IT departments are increasingly faced with the challenge of creating and maintaining a corporate records archive in a cost-effective fashion that satisfies the requirements put forth by the legislation. FAQ: What is the impact of Sarbanes-Oxley on IT operations? The following sections of Sarbanes-Oxley contain the three rules that affect the management of electronic records. The first rule deals with destruction, alteration, or falsification of records.…

    • 558 Words
    • 3 Pages
    Satisfactory Essays
  • Good Essays

    NT2580 Project part 1

    • 606 Words
    • 3 Pages

    Safety of data and information is a real important aspect of a company. Before we can create an outline for general security solutions we must first define what is needed. I recommend that we use a multi-layered security plan. There are a total of seven domains of an IT infrastructure including user domain, workstation domain, LAN domain, LAN-to-WAN domain, WAN domain, remote access domain, and system/application domain.…

    • 606 Words
    • 3 Pages
    Good Essays
  • Satisfactory Essays

    Sarbanes-Oxley Act

    • 504 Words
    • 3 Pages

    The Sarbanes-Oxley Act of 2002 is an act passed by U.S. Congress in 2002 to protect investors and the general public from the possibility of fraudulent accounting activities by corporations. The Sarbanes-Oxley Act authorized strict modifications to improve financial disclosures from corporations and to prevent accounting fraud. This law was passed after a couple of big the accounting scandals like Enron, Tyco, and WorldCom shook investor assurance in financial statements and required an overhaul of regulatory standards. The act is administered by the Securities and Exchange Commission, which sets deadlines for compliance and publishes rules on requirements. It is not a set of business practices and does not specify how a business should store records; rather it tells more which records are to be stored and for how long in case of hearings.…

    • 504 Words
    • 3 Pages
    Satisfactory Essays
  • Powerful Essays

    Sarbanes-Oxley

    • 1874 Words
    • 8 Pages

    The Sarbanes-Oxley Act of 2002 was created by sponsors U.S. Senator Paul Sarbanes(D-MD) and U.S. Representative Michael G. Oxley (R-OH) in response to very public corporate fraud and accounting scandals. In a seemingly short period of time, Enron, Tyco International, Adelphia, Peregrine Systems and WorldCom all collapsed. The majority of these scandals resulted from the inaccurate reporting of financial transactions. The financial statements of these organizations were so gravely misrepresented and misstated that once the organizations' records were presented fairly, it caused the total collapse of the company. As a result of these scandals, investors lost billions of dollars when the share prices collapsed, and the public lost confidence in the nation's securities markets and the auditor who were supposed to protect the public's interest.…

    • 1874 Words
    • 8 Pages
    Powerful Essays
  • Better Essays

    The Sarbanes-Oxley Act

    • 1327 Words
    • 6 Pages

    The Sarbanes-Oxley Act of 2002(SOX which is also known as the Public Company Accounting Reform and Investor Protection Act was enacted in July, 30, 2002 as a prompt response to the financial crimes scandals (Adelphia, Enron, WorldCom, Peregrime Systems , Arther Anderson and Tyco International). SOX establishes new, stricter standards for all US publicly traded companies. It does not apply to privately companies. The Act is administered by the Securities and Exchange Commission (SEC), which deals with compliance, rules and requirements. The Act also created a new agency, the Public Company Accounting Oversight Board, or PCAOB, which is in charge of overseeing, regulating, inspecting, and disciplining accounting firms in their roles as auditors of public companies. In my opinion, the benefits of the act cant be able to overcome the frustration and the cost of it.…

    • 1327 Words
    • 6 Pages
    Better Essays
  • Satisfactory Essays

    Tags: sec402, sec 402, Cyber Security, sec 402 Cyber Security, strayer university, sec 402 strayer, sec 402 complete class, sec402 entire, sec 402 complete, sec 402 case study 1, case study, assignment, complete class, sec 402 Case Study 1 - The Critical Need for Information Security, sec 402 Assignment 1 - Developing the Corporate Strategy for Information Security, sec 402 Case Study 2 - Developing the Forensics, Continuity, Incident Management, and Security Training, sec402 Assignment 2 - Implementing Network and Personnel Security Measures, The Rookie Chief Information Security Officer, sec402 term paper The Rookie Chief Information Security Officer, sec 402 mid, sec402 midterm exam, sec 402 final, sec402 final exam, testbank, quiz bank…

    • 265 Words
    • 1 Page
    Satisfactory Essays
  • Better Essays

    The Sarbanes-Oxley Act

    • 2083 Words
    • 9 Pages

    Chapter 5: the Sarbanes- Oxley act of 2002 involved the public anger that started when Enron, WorldCom, and other big companies scandals. This is when there was support for white collar crime when it came to accounting standards. Under the law of federal sentencing rules to make sure that white collar criminals are being punished. (Barnes, 2012). 1. For someone to alter or get rid of documents and there intensions to obstruct or effect the crime/case. 2. The CEO (chief executive officer) and the CFO (chief financial officer) must clarify that repots have been submitted to the SEC (securities and exchange commission.) it is a crime if the CEO and CFO make a report that is false. 3 CEO and CFO must reimburse the company for any raises and if…

    • 2083 Words
    • 9 Pages
    Better Essays
  • Powerful Essays

    Acceptable Use Policy

    • 1267 Words
    • 6 Pages

    Johnson , R., Merkow, M. (2011). Security Policies and Implementation Issues. Sudbury, MA: Jones & Bartlett.…

    • 1267 Words
    • 6 Pages
    Powerful Essays
  • Powerful Essays

    Human factors can influence policy choices for both domestic and international cybersecurity issues. What will be discussed in this paper is how human factors can affect four selected cybersecurity issues. The four-cybersecurity issues selected are zero-day exploits, meta-data collected and used by private and public sectors, vulnerability assessments for mobile devices in the BYOD environment, and threats to copy right and ownership of intellectual property. This paper will go into details on important security issues, recommended policy controls, and how or why human factors can influence each of the recommended policy controls for each of the four selected topics mentioned.…

    • 4860 Words
    • 14 Pages
    Powerful Essays