Sarbanes-Oxley (SOX)
acronymnetworking
The 2002 United States law on corporate financial reporting that made internal controls, including access control, a matter of legal liability for company officers.
It is a finance law and it reshaped security purchasing, which is why it belongs in a technical glossary. By making executives answerable for the integrity of financial systems, it turned identity governance, change control and audit logging from good practice into obligations someone signs for. Static analysis and identity governance both became enterprise categories in its wake. The pattern is the one this catalogue keeps recording: compliance creates markets faster than threats do, and it moves the buying decision from the people who operate a control to the people who have to certify it.
Also known as: sox, sarbanes oxley, sarbanes-oxley act