Section 404 has been specifically discussed that outlines the internal control assessments required of the firms. Securities and Exchange Commission (SEC) also requires publicly traded companies to comply with Treadway Commission's Committee of Sponsoring Organizations (COSO). The case of Motorola IT governance model is taken to demonstrate how compliance with SOX can be ensured for data and IT security by organizations. The article observes that SEC fails to provide specific guidance on IT security; rather it leaves room for interpretation by firms. There is brief mentioning of SOX acts that outline compliance related issues such as Sections 302, 404, 409, and 802 of SOX 2002. The article concludes with an observation that firms with least effective IT security made decisions related to IT governance at the level of business unit managers. Most effective firms in terms of IT governance made IT decisions by engaging three main stakeholders i.e. top management, business unit managers, and IT specialists.

The book is written on the subject of 'insider attacks' related to abuse of information security in an organization. The book identifies and explains potential information technology (IT) system's vulnerability from insider sources of an organization such as employees,
