108k views
3 votes
All of the following are frameworks for implementing Sarbanes-Oxley compliance EXCEPT:

a) COSO Framework
b) COBIT Framework
c) ITIL Framework
d) ISO 27001 Framework

1 Answer

5 votes

Final answer:

Among the given frameworks, the ITIL Framework is not specifically designed for implementing Sarbanes-Oxley compliance; it focuses more on IT service management best practices. The correct option is C.

Step-by-step explanation:

The Sarbanes-Oxley Act (SOX) is a United States federal law that sets new or expanded requirements for all U.S. public company boards, management, and public accounting firms. There are several frameworks that companies can use to comply with the SOX requirements, but not all frameworks are designed specifically for this purpose.

Among the options listed:

  • COSO Framework - The Committee of Sponsoring Organizations of the Treadway Commission (COSO) is a widely accepted framework for designing and evaluating the effectiveness of internal controls.
  • COBIT Framework - Control Objectives for Information and Related Technologies (COBIT) provides an extensive framework for governance and management of enterprise IT, which supports SOX compliance.
  • ITIL Framework - The Information Technology Infrastructure Library (ITIL) mainly focuses on the best practices in IT service management.
  • ISO 27001 Framework - An international standard for information security management systems (ISMS). While it can support principles of SOX, it is not specifically designed for SOX compliance.

Among the given options, the ITIL Framework is the one that is not specifically a framework for implementing Sarbanes-Oxley compliance.

User Swalex
by
7.0k points