Sarbanes-Oxley (SOX) regulates financial reporting and internal controls, PCI DSS provides payment card security standards, and BASEL II establishes banking capital requirements. All three directly pertain to banking information security. COBIT is an IT governance framework (not banking-specific), and Graham-Leach-Bliley is a US financial services law (less directly security-focused).