Earlier quoted context omitted.
SOX compliance has expanded in recent years to cover a gamut of Cybersecurity process and policy. Go look it up. I recently compiled all the documentation necessary for a client I am serving in order to pass. It includes handling of PII, access controls for code repositories and production environments, and tools for ensuring code quality like performing static analysis and mitigating DDOS attacks such as a decent WA…
Yes I have looked it up and you obviously have no clue what you're talking about. The law is the law, and regardless of what nonsense some random corporate trainer might have fed you, SOX compliance requirements haven't expanded in recent years. Go read the actual law instead of spreading misinformation. Some businesses do require their partners to have additional controls on PII handling. But that's purely a busines…
Former Twitter employee convicted of charges related to spying for Saudis
51–57 of 57 posts
Re: Former Twitter employee convicted of charges related to spying for Saudis
#52Earlier quoted context omitted.
Yes I have looked it up and you obviously have no clue what you're talking about. The law is the law, and regardless of what nonsense some random corporate trainer might have fed you, SOX compliance requirements haven't expanded in recent years. Go read the actual law instead of spreading misinformation. Some businesses do require their partners to have additional controls on PII handling. But that's purely a busines…
This is in the medical and recreational marijuana space which may have additional Reqs, but I am telling you exactly what the auditors themselves are asking for. I'm not talking out of my ass here.
Read the law. Seriously, it's posted online. You can just go look.
Re: Former Twitter employee convicted of charges related to spying for Saudis
#53Earlier quoted context omitted.
This is in the medical and recreational marijuana space which may have additional Reqs, but I am telling you exactly what the auditors themselves are asking for. I'm not talking out of my ass here.
You're talking out of your ass here. Your auditors may be checking various things for a variety of unrelated reasons, but it has nothing to do with SOX. Read the law. Seriously, it's posted online. You can just go look.
"SOX itself never mentions cybersecurity. However, in 2018, the SEC released a “Commission Statement and Guidance on Public Company Cybersecurity Disclosures (the Guidance).” (https://www.sec.gov/rules/interp/2018/33-10459.pdf) The SEC realized that increased technology use and data breach risk impact corporate financials. In fact, the Guidance lists several financial risks linked to cybersecurity:
Remediation costs Cybersecurity protection costs Lost revenue due to customer churn after an attack Litigation and legal risks, including regulatory fines Increased insurance premiums Reputation damage Damage to competitiveness, stock price, and long-term shareholder value In order to comply with SOX, public companies need to ensure that they establish appropriate controls and security monitoring programs that mitigate risk.
In 2020, the SEC released new guidance “Cybersecurity and Resiliency Observations” (Resiliency Guidance) (https://www.sec.gov/files/OCIE%20Cybersecurity%20and%20Resil...) through its Office of Compliance Inspections and Examinations (OCIE). This revised guidance offered greater specificity for organizations that need to file public financial reports."
Re: Former Twitter employee convicted of charges related to spying for Saudis
#54Earlier quoted context omitted.
You're talking out of your ass here. Your auditors may be checking various things for a variety of unrelated reasons, but it has nothing to do with SOX. Read the law. Seriously, it's posted online. You can just go look.
https://securityscorecard.com/blog/what-is-sox-compliance "SOX itself never mentions cybersecurity. However, in 2018, the SEC released a “Commission Statement and Guidance on Public Company Cybersecurity Disclosures (the Guidance).” ( https://www.sec.gov/rules/interp/2018/33-10459.pdf ) The SEC realized that increased technology use and data breach risk impact corporate financials. In fact, the Guidance lists several…
Re: Former Twitter employee convicted of charges related to spying for Saudis
#55Earlier quoted context omitted.
It's not a matter of Twitter giving guarantees about optional data. This is PII, which has to be protected legally. Internal controls at a company of the size of Twitter is no longer optional. You don't have to intend malice to be guilty of negligence. Equifax never gave guarantees of security and data safety either, but it's understood that they should be responsible.
Wrong. Under US federal law, Twitter has no legal obligation to protect PII. Internal controls for user data are optional. https://pro.bloomberglaw.com/brief/data-privacy-laws-in-the-... To be clear, I am not thrilled with this situation. But even if social networks were legally required to protect PII they would still suffer occasional breaches by advanced persistent threats and state intelligence agencies. Don't po…
Twitter is an international company with international users, and the law protects the users of that country/legislation.
Under GDPR, and other international laws, PII is legally protected.
Even if you're an American company, you can't disregard laws of other countries if they're going to be using your product.
Re: Former Twitter employee convicted of charges related to spying for Saudis
#56Earlier quoted context omitted.
While you may be correct about criminal law, I'm certain this would impact their SOX compliance ( https://en.wikipedia.org/wiki/Sarbanes%E2%80%93Oxley_Act ) and would put their ability to participate and operate in US securities markets in serious jeopardy.
Wrong again. That law only covers financial controls. It doesn't address user data.
Re: Former Twitter employee convicted of charges related to spying for Saudis
#57Earlier quoted context omitted.
https://securityscorecard.com/blog/what-is-sox-compliance "SOX itself never mentions cybersecurity. However, in 2018, the SEC released a “Commission Statement and Guidance on Public Company Cybersecurity Disclosures (the Guidance).” ( https://www.sec.gov/rules/interp/2018/33-10459.pdf ) The SEC realized that increased technology use and data breach risk impact corporate financials. In fact, the Guidance lists several…
You’ve linked to guidelines that do not have the force of law behind them.