To be honest SOX doesn't mean a thing.
Until you have a security breach?

And as long as everything is documented and according to procedure it's ok. Unfortunately this doesn't mean it's secure in any way.
That is very true, and the problem is not only in regulations, I see it in certifications (BS, ISO etc.) and methodologies (CMM for example). So long as you have processes and procedures to support them, documentation, and you adhere to the processes and procedures, you will get the certification.

There is no concept of quality and effectiveness.