The information content of Sarbanes-Oxley in predicting security breaches

被引:8
|
作者
Westland, J. Christopher [1 ]
机构
[1] Univ Illinois, Chicago, IL 60680 USA
关键词
Sarbanes-Oxley; Security breaches; Internal control; Auditing; Computer security; Information systems breaches; Computer fraud; Privacy breach; INTERNAL CONTROL DEFICIENCIES; ACT; CONDENSATION; ERRORS; COST; LAW;
D O I
10.1016/j.cose.2019.101687
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
How effective is compliance with the Sarbanes-Oxley Act (SOX) in identifying and eliminating firm threats from information systems breaches? We investigated publicly reported security breaches of internal controls in corporate systems to determine whether SOX assessments are information bearing with respect to breaches which can lead to materially significant losses and misstatements. The results of our tests varied significantly between breach types. SOX Section 404 adverse decisions on effectiveness of controls occurred in 100% of credit card data breaches and around 33% of insider breaches. SOX 404 audits provided a contrarian "effective" control decision on 88% of situations where there was a control breach concerning a portable device. This suggests that employees are subverting particularly strict internal controls by using portable devices that can be carried outside the physical boundaries of the firm. We found that management and SOX 404 auditors do not general agree on the underlying internal control situation at any time. Instead the SOX 404 auditors were likely to discover material weaknesses and "educate" management and internal audit teams about the importance of these control weaknesses. SOX attestations were poor at identifying control weaknesses from unintended disclosures, physical losses, hacking and malware, stationary devices, and situations where the cause of the breach was unknown. Hazard and occupancy structural models were constructed to extrapolate to a larger population. Results showed that both SOX 302 and 404 audits provided information germane to the frequency of breaches, with SOX 404 being three times as informative as section 302 reports. The hazard model found an expected 2.88% reduction in breaches when SOX 302 controls were effective. Management's "material weakness' attestations provided no information in this structural model, whereas there would be around a 1% increase in breach occurrence when there exist significant deficiencies. SOX 404 attestations were the most informative; a negative SOX 404 attestation is projected to increase the frequency of breaches by around 8.5%. We concluded that the strength of internal controls attested in SOX reports is likely to be a significant factor in the occurrence of a security breach in a specific period. (C) 2019 Elsevier Ltd. All rights reserved.
引用
收藏
页数:20
相关论文
共 50 条
  • [41] Are Investors Confused by Restatements after Sarbanes-Oxley?
    Burks, Jeffrey J.
    [J]. ACCOUNTING REVIEW, 2011, 86 (02): : 507 - 539
  • [42] Sarbanes-Oxley and corporate risk-taking
    Bargeron, Leonce L.
    Lehn, Kenneth M.
    Zutter, Chad J.
    [J]. JOURNAL OF ACCOUNTING & ECONOMICS, 2010, 49 (1-2): : 34 - 52
  • [43] The impact of Sarbanes-Oxley on internal control remediation
    Chan, Kam
    Kleinman, Gary
    Lee, Picheng
    [J]. INTERNATIONAL JOURNAL OF ACCOUNTING AND INFORMATION MANAGEMENT, 2009, 17 (01) : 53 - +
  • [44] Sarbanes-Oxley: Will You Need a Forensic Accountant?
    Christensen, Jo Ann
    Byington, J. Ralph
    Blalock, Tonya J.
    [J]. JOURNAL OF CORPORATE ACCOUNTING AND FINANCE, 2005, 16 (03): : 69 - 75
  • [45] Halliburton executive blasts Sarbanes-Oxley Act
    Fletcher, S
    [J]. OIL & GAS JOURNAL, 2003, 101 (23) : 26 - 27
  • [46] Economic consequences of the Sarbanes-Oxley Act of 2002
    Zhang, Ivy Xiying
    [J]. JOURNAL OF ACCOUNTING & ECONOMICS, 2007, 44 (1-2): : 74 - 115
  • [47] The Sarbanes-Oxley Act Records management implications
    Stephens, David O.
    [J]. RECORDS MANAGEMENT JOURNAL, 2005, 15 (02) : 98 - +
  • [48] The propensity to save: The effect of Sarbanes-Oxley act
    James, Hui Liang
    Lirely, Roger
    [J]. REVIEW OF FINANCIAL ECONOMICS, 2022, 40 (01) : 77 - 96
  • [49] Accounting and the Global Economy after Sarbanes-Oxley
    Smith, David B.
    [J]. SERVICE BUSINESS, 2009, 3 (02) : 209 - 209
  • [50] The Sarbanes-Oxley act from a legislative viewpoint
    Kecskes, Andras
    [J]. THEORY AND PRACTICE OF LEGISLATION, 2016, 4 (01): : 27 - 43