SOX compliant—But not safe!
Michael L. Davis, Gordon E. Smith, Chris Schroeder · Journal of Corporate Accounting & Finance · 2006
The Sarbanes-Oxley Act (SOX) forced companies to evaluate their internal controls. And companies spent a lot of money on audits, trying to do that. Now many firms boast that they are “SOX compliant”— and therefore safe from hackers, data thieves, and fraudsters. But data security experts have found just the opposite: a continuing failure to secure operating systems and networks! © 2006 Wiley Periodicals, Inc.