Abstract
In 2002, the passage of Sarbanes-Oxley (SOX) was supposed to protect the public by changing the reporting requirements in financial statement audits. Management and auditors were to attest to the existence and effectiveness of internal controls over financial data, and that would supposedly “fix” the problem. Recent disclosures of business practices at two companies who were victims of cybercrimes—Target and JPMorgan Chase—bring to light a lack of proper internal controls over the financial data they collect. This paper discusses information security, internal controls, and SOX, as well as concerns of why current internal control policies are not effective in securing information. Lastly, it is important to note the most recent legislation enacted in an attempt to improve information security.
Recommended Citation
Land, Teresa K. PhD and Jones, Rita C. PhD
(2018)
"Information Security Breaches, Internal Controls and Related Legislation,"
Journal of Business, Industry, and Economics: Vol. 23, Article 4.
Available at:
https://roar.una.edu/jobie/vol23/iss1/4