U.S. Law: Gramm-Leach-Bliley Act (GLBA) & Sarbanes–Oxley Act (SOX) Flashcards
What does SOX Act stand for?
Sarbanes-Oaxly Act
What is the organization responsible for establishing SOX standards and guidelines and conducting audits and imposing subsequent fines?
Security and Exchange Comission (SEC)
Who does SOX apply to?
all publically traded corporations in the U.S.
What is the goal of SOX?
create an environment of regulatory transparency where companies are required to disclose information about their financial status and implement controls to ensure the accuracy of that information; prevents fraudulent and poor practices
GLBA recognizes legal difference between what two entities?
customer and consumer
How is customer defined in GLBA?
customers have an ongoing relationsip with financial institution
How is consumer defined in GLBA?
only conduct isolated transactions with financial institution, such as caching a check at a bank or visiting bank’s website
What is the legal obligation of financial institutions towards consumers under GLBA?
financial institution needs to provide summary privacy notice that includes instructions for finding the full notice
What requirement for data breach reporting does the Sarbanes–Oxley Act place on organizations that must comply with it?
data breaches must be reported in annual and quarterly reports; also breaches must be reported to auditors
To whom must breaches be reported under Sarbanes–Oxley?
auditors as well as implementing methods to identify if breaches have occurred
Who is regulataed under GLBA?
financial institutions, that are significantly engaged in offering financial services
How does GLBA protect consumer’s privacy?
- better informing consumers about how their financial information is used
- by regulating the use of consumer information by financial institutions
How do financial institutions share their full privacy notices with all details with customers as their legal obligation under GLBA?
- when they first begin business relationship with a customer
- annualy with updated privacy notices
What are the three main sections of GLBA?
-
financial privacy rule
- regulates collection and disclosure of private financial info
-
safeguards rule
- stripulates that financial institutions must implement security programs to protect such information
-
pretexting provisions
- prohibit the practice of pretexting (accessing private info using false pretenses)
What is the section 802 of SOX Act?
it is a crime to destroy, change or hide documents to prevent their use in official legal processes