Skip to content
Data Science & information systems International Journal of Advances in Data and Information Systems
Open access E-ISSN 2721-3056 Acceptance rate: 28%

Evaluating Access Management Effectiveness for SOX-Driven IT General Controls Using NIST SP 800-53

Authors

DOI:

https://doi.org/10.59395/ijadis.v7i2.1507

Keywords:

Access Management, IT General Controls, Sarbanes–Oxley Compliance, NIST SP 800-53, Fintech Security Governance

Abstract

Access control failures including delayed account deactivation, unauthorized privilege escalation, and gaps in privileged session oversight represent a primary risk pathway to financial reporting integrity failures and SOX-reportable material weaknesses, making effective access management one of the most consequential components of IT General Controls (ITGC) in fintech organizations operating within SOX-oriented governance frameworks. Despite formal compliance efforts, access management controls are often implemented in a procedural manner that may not fully reflect their operational effectiveness. This study evaluates the effectiveness of access management controls in a fintech organization using NIST Special Publication 800-53 Revision 5 as a technical evaluation framework. The research adopts a qualitative evaluative case study approach, combining document review, system observation, and semi-structured interviews to assess selected access management controls. A structured control mapping and gap analysis process is applied to compare existing practices against NIST-defined control requirements, followed by a risk-based interpretation of identified gaps. The results indicate that while foundational access management mechanisms are in place, several controls are only partially effective due to reliance on manual processes, delayed account deactivation, limited privileged access monitoring, and periodic log reviews. These gaps reduce the consistency and timeliness of access enforcement and weaken overall ITGC effectiveness. This study contributes a practical and technically grounded evaluation model that bridges SOX-driven internal control expectations with standardized security controls. The findings provide actionable insights for organizations seeking to strengthen access management governance and improve control effectiveness in regulated digital environments.

519 132

Downloads

Download data is not yet available.

References

[1] P. Weill and J. W. Ross, IT Governance on One Page, SSRN Electronic Journal, 2004, doi: 10.2139/ssrn.664612. DOI: https://doi.org/10.2139/ssrn.664612

[2] S. Mithas, A. Tafti, I. Bardhan, and J. M. Goh, Information Technology and Firm Profitability: Mechanisms and Empirical Evidence, MIS Quarterly, vol. 36, no. 1, pp. 205224, Oct. 2012, doi: 10.2307/41410414. DOI: https://doi.org/10.2307/41410414

[3] G. P. Lander, The SarbanesOxley Act of 2002, Journal of Investment Compliance, vol. 3, no. 1, pp. 4453, Jan. 2002, doi: 10.1108/joic.2002.3.1.44. DOI: https://doi.org/10.1108/15285810210812619

[4] H. ASHBAUGHSKAIFE, D. W. COLLINS, W. R. KINNEY JR, and R. LAFOND, The Effect of SOX Internal Control Deficiencies on Firm Risk and Cost of Equity, Journal of Accounting Research, vol. 47, no. 1, pp. 143, Mar. 2009, doi: 10.1111/j.1475-679X.2008.00315.x. DOI: https://doi.org/10.1111/j.1475-679X.2008.00315.x

[5] P. P. Gupta, H. Sami, and H. Zhou, Do companies with effective internal controls over financial reporting benefit from SarbanesOxley sections 302 and 404?, Journal of Accounting, Auditing and Finance, vol. 33, no. 2, pp. 200227, 2018, doi: 10.1177/0148558X16663091. DOI: https://doi.org/10.1177/0148558X16663091

[6] T. Mazza and S. Azzali, Information Technology Controls Quality and Audit Fees: Evidence From Italy, Journal of Accounting, Auditing & Finance, vol. 33, no. 1, pp. 123146, Jan. 2018, doi: 10.1177/0148558X15625582. DOI: https://doi.org/10.1177/0148558X15625582

[7] M. L. DEFOND and C. S. LENNOX, Do PCAOB Inspections Improve the Quality of Internal Control Audits?, Journal of Accounting Research, vol. 55, no. 3, pp. 591627, Jun. 2017, doi: 10.1111/1475-679X.12151. DOI: https://doi.org/10.1111/1475-679X.12151

[8] Committee of Sponsoring Organizations of the Treadway Commission (COSO), Internal ControlIntegrated Framework, 2013.

[9] B. Blakely, J. Kurtenbach, and L. Nowak, Exploring the information content of cyber breach reports and the relationship to internal controls, International Journal of Accounting Information Systems, vol. 46, no. July, p. 100568, Sep. 2022, doi: 10.1016/j.accinf.2022.100568. DOI: https://doi.org/10.1016/j.accinf.2022.100568

[10] J. C. Westland, The information content of Sarbanes-Oxley in predicting security breaches, Computers & Security, vol. 90, p. 101687, Mar. 2020, doi: 10.1016/j.cose.2019.101687. DOI: https://doi.org/10.1016/j.cose.2019.101687

[11] J. R. Cohen, J. R. Joe, J. C. Thibodeau, and G. Trompeter, Audit Partners Judgments and Challenges in the Audit of Internal Control over Financial Reporting, SSRN Electronic Journal, 2020, doi: 10.2139/ssrn.3551763. DOI: https://doi.org/10.2139/ssrn.3551763

[12] P. Foote and T. Neudenberger, Beyond Sarbanes-Oxley compliance, Computers and Security, vol. 24, no. 7, pp. 516518, 2005, doi: 10.1016/j.cose.2005.07.005. DOI: https://doi.org/10.1016/j.cose.2005.07.005

[13] M. Syafrizal, S. R. Selamat, and N. A. Zakaria, Analysis of Cybersecurity Standard and Framework Components, International Journal of Communication Networks and Information Security (IJCNIS), vol. 12, no. 3, pp. 417432, Apr. 2022, doi: 10.17762/ijcnis.v12i3.4817. DOI: https://doi.org/10.17762/ijcnis.v12i3.4817

[14] Joint Task Force NIST, Security and Privacy Controls for Information Systems and Organizations, Gaithersburg, MD, Sep. 2020. doi: 10.6028/NIST.SP.800-53r5. DOI: https://doi.org/10.6028/NIST.SP.800-53r5

[15] D. Mittal and M. Damle, An Appraisal in Internal Control Frameworks Implementation of COSO, ISO 27001 and NIST for Opportunities in Industry 5.0, in 2025 Seventh International Conference on Computational Intelligence andCommunication Technologies (CCICT), Apr. 2025, pp. 345352. doi: 10.1109/CCICT65753.2025.00061. DOI: https://doi.org/10.1109/CCICT65753.2025.00061

[16] R. V. Rose, NEW NIST REVISIONS WHAT DO THEY MEAN FOR REGULATORY COMPLIANCE?, EDPACS, vol. 59, no. 6, pp. 513, Jun. 2019, doi: 10.1080/07366981.2019.1642559. DOI: https://doi.org/10.1080/07366981.2019.1642559

[17] R. K. Yin, Case Study Research and Applications Sixth Edition, vol. 6. 2455 Teller Road, Thousand Oaks California 91320 United States: SAGE Publications, Inc., 2018. doi: 10.4135/9781412957397. DOI: https://doi.org/10.4135/9781412957397

[18] B. Tuttle and S. D. Vandervelde, An empirical examination of CobiT as an internal control framework for information technology, International Journal of Accounting Information Systems, vol. 8, no. 4, pp. 240263, Dec. 2007, doi: 10.1016/j.accinf.2007.09.001. DOI: https://doi.org/10.1016/j.accinf.2007.09.001

[19] H. Taherdoost, Validity and Reliability of the Research Instrument; How to Test the Validation of a Questionnaire/Survey in a Research, SSRN Electronic Journal, no. January 2016, 2016, doi: 10.2139/ssrn.3205040. DOI: https://doi.org/10.2139/ssrn.3205040

[20] U. J. Gelinas, R. B. Dull, and P. Wheeler, Accounting Information Systems. Cengage Learning, 2011. [Online]. Available: https://books.google.co.id/books?id=cdU8AAAAQBAJ

[21] R. S. Sandhu and P. Samarati, Access control: principle and practice, IEEE Communications Magazine, vol. 32, no. 9, pp. 4048, Sep. 1994, doi: 10.1109/35.312842. DOI: https://doi.org/10.1109/35.312842

[22] F. Cai, N. Zhu, J. He, P. Mu, W. Li, and Y. Yu, Survey of access control models and technologies for cloud computing, Cluster Computing, vol. 22, no. S3, pp. 61116122, May 2019, doi: 10.1007/s10586-018-1850-7. DOI: https://doi.org/10.1007/s10586-018-1850-7

[23] C. Li, G. Peters, V. Richardson, and M. Watson, The Consequences of Information Technology Control Weaknesses on Management Information Systems: The Case of Sarbanes-Oxley Internal Reports. 2010.

[24] D. F. Ferraiolo, J. F. Barkley, and D. R. Kuhn, A role-based access control model and reference implementation within a corporate intranet, ACM Transactions on Information and System Security, vol. 2, no. 1, pp. 3464, 1999, doi: 10.1145/300830.300834. DOI: https://doi.org/10.1145/300830.300834

[25] R. Sandhu, D. Ferraiolo, and R. Kuhn, The NIST model for role-based access control, in Proceedings of the fifth ACM workshop on Role-based access control, Jul. 2000, pp. 4763. doi: 10.1145/344287.344301. DOI: https://doi.org/10.1145/344287.344301

[26] S. Romanosky, Examining the costs and causes of cyber incidents, J. Cybersecur., vol. 2, pp. 121135, 2016, doi: 10.1093/cybsec/tyw001. DOI: https://doi.org/10.1093/cybsec/tyw001

[27] M. Benaroch, International Journal of Accounting Measuring the pervasiveness of IT general controls: A model and empirical validation, International Journal of Accounting Information Systems, vol. 56, no. June, p. 100752, Dec. 2025, doi: 10.1016/j.accinf.2025.100752. DOI: https://doi.org/10.1016/j.accinf.2025.100752

Downloads

Published

2026-08-04

How to Cite

[1]
I. Shofwan, M. H. . Hilman, and R. . Trimanadi, “Evaluating Access Management Effectiveness for SOX-Driven IT General Controls Using NIST SP 800-53”, International Journal of Advances in Data and Information Systems, vol. 7, no. 2, pp. 645–655, Aug. 2026, doi: 10.59395/ijadis.v7i2.1507.

Share



Plum Analytics


Similar Articles

11-20 of 85

You may also start an advanced similarity search for this article.