APPENDIX G

image

Sarbanes-Oxley Security Compliance Requirements

I have included this admittedly very short appendix for the Sarbanes–Oxley Act (SOX) because it is widely cited for IT security compliance. The act is referred to in Chapter 8 and other places throughout the book.

As strange as it may seem, the Sarbanes-Oxley Act does not specify any details for web application security whatsoever. Two organizations, the Committee of Sponsoring Organizations of the Treadway Commission (COSO) and ISACA, stepped up to the plate and created some nontechnical guidelines to interpret IT security requirements for compliance with SOX. COSO has created guidelines, ...

Get The Manager’s Guide to Web Application Security: A Concise Guide to the Weaker Side of the Web now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.