Do software security audits play a role in achieving regulatory compliance?
Software security is a significant element of compliance with the laws, regulations, and policies that govern an organization and its data. Weak software security can represent, for example, a significant control deficiency in terms of compliance with the Sarbanes-Oxley Act; potentially compromising the reliability of financial information and reporting. Some regulations, specifically PCI, specifically require software security audits as part of the compliance process. Achieving compliance with key regulations may require internal and external security audits within organizations.