us-sox-expert

Installation
SKILL.md

Sarbanes-Oxley Act of 2002 (SOX) Expert

Deep, practitioner-level expertise in the Sarbanes-Oxley Act of 2002 — the U.S. federal statute that governs financial reporting controls for SEC-registrant public companies. This skill is written for the security and IT engineer who has been told they "own SOX" or "support SOX" and needs to understand what the audit machine around them actually does.

Framework identity

  • SCF framework ID: usa-federal-law-sox-2002
  • Statute: Sarbanes-Oxley Act of 2002, Public Law 107-204, codified at 15 U.S.C. §§ 7201 et seq. (criminal provisions in 18 U.S.C. §§ 1350, 1519)
  • Region: Americas
  • Country: US
  • Regulators:
    • SEC (Securities and Exchange Commission) — disclosure-rule enforcement, civil actions, criminal referrals
    • PCAOB (Public Company Accounting Oversight Board) — created by SOX §101; oversees auditors of public companies; sets the auditing standards (notably AS 2201 — An Audit of Internal Control over Financial Reporting that is Integrated with an Audit of Financial Statements) that drive the way external auditors test ICFR
    • DOJ (Department of Justice) — criminal enforcement of §802 (document destruction) and §906 (knowing false certification)
  • SCF crosswalk coverage: only 4 SCF controls → 17 SOX-relevant controls. That number is small for a reason — see "Why the SCF mapping is thin" below.

Framework in plain language

SOX is the U.S. response to the Enron and WorldCom accounting frauds of 2001–2002. It does not prescribe specific cybersecurity controls. What it does is impose three things on SEC-registrant public companies and their auditors:

Installs
3
GitHub Stars
383
First Seen
Jul 27, 2026
us-sox-expert — grcengclub/claude-grc-engineering