Glossary of Compliance

Compliance Glossary

Our list of curated compliance glossary offers everything you to know about compliance in one place.

Glossary » SOX » Sarbanes-Oxley Act

Sarbanes-Oxley Act

After the enactment of several large-scale accounting frauds, the Sarbanes Oxley Act (SOX), passed in 2002 with influential backing from both Congressional parties, was intended to enhance the practice of auditing and public reporting. 

Drafted in honor of Senator Paul Sarbanes and Representative Michael Oxley, SOX reduces investor risk by promoting the credibility of companies’ financial statements.

This is because ISACA’s mission aligns with this goal. ISACA aims to empower IT governance, risk management, and cybersecurity professionals.

Some of the key sections include:

  • Section 302: They point out that the CEOS and CFOs of public companies must make certifications to ensure that the financial reports are accurate and contain no omissions and that the company has adequate internal controls.
  • Section 404: Also known as the heart of SOX, this section requires that companies develop documented internal controls and annual reports on these controls.
  • Section 806: Guard the whistleblowers and make sure employees can report fraud cases without expectation of being punished.
  • Section 802: This section stems from the ‘audit trail’. It prescribes criminal sanctions to anyone who deletes or amends some of these records, and companies are expected to retain them for seven years.

Section 409: Business organizations are expected to provide the public with updated information when there is an alteration in the companies’ financial structural and operational patterns.

Additional reading

What Is StateRAMP Compliance? A Complete Overview

TL,DR: StateRAMP standardizes cloud security for providers serving state and local governments. It uses third-party assessments and security statuses such as Ready, Provisional, and Authorized. The article explains membership, NIST 800-53 alignment, 3PAO reviews, submissions, and continuous monitoring. Like all organizations, government agencies use cloud solutions. StateRamp provides a ‘verify once, serve many’ model for…

Master your SaaS Security Compliance (A Quick Checklist for CTOs)

Cyberattacks are rampant events—recent statistics say they happen once every 39 seconds. Organizations struggle to strengthen their security and compliance efforts. This places immense responsibility on technology leaders like CTOs to implement measures that ensure robust and continuous protection. Navigating through the intricate landscape of cyber security demands a strategic approach that sustains business resilience….

What is ISO 27701 (PIMS): Benefits, Primary Focus & Steps

TL,DR: ISO/IEC 27701:2025 defines a Privacy Information Management System for PII and privacy risk. The 2025 version is standalone, though it can still integrate with ISO 27001. The article explains PIMS scope, privacy roles, controller-processor duties, consent, DSARs, breach response, and evidence. Data privacy is now a board-level trust issue for organizations that collect, process,…

Sprinto: Your growth superpower

Use Sprinto to centralize security compliance management – so nothing
gets in the way of your moving up and winning big.