Which of the following acts related to information security in the US establish that the
management of an organization is responsible for establishing and maintaining an adequate
internal control structure and procedures for financial reporting?
A.
USA Patriot Act 2001
B.
Sarbanes-Oxley 2002
C.
Gramm-Leach-Bliley Act (GLBA)
D.
California SB 1386
Explanation:
Reference:
http://www.sec.gov/rules/final/33-8238.htm(see background)
A
B, per ECSA text
B = See ECSA V8, M-01/P-49
establishing and maintaining an adequate internal control structure and procedures for financial reporting? Answer B