SSAE 16 | Description of the “System” | What you Need to Know
Posted by: Charles Denyer
Enter SSAE 16 and it's new requirement for service organizations to provide a description of its "system". As for out with the old...
Enter SSAE 16 and it's new requirement for service organizations to provide a description of its "system". As for out with the old...
SSAE 16, put forth by the Auditing Standards Board (ASB) of the American Institute of Certified Public Accountants (AICPA), requires that the service organization provide a
SSAE 16, put forth by the Auditing Standards Board (ASB) of the American Institute of Certified Public Accountants (AICPA), will force a large number of service organizations to fundamentally re-address many of the compliance issues that they...
ISAE 3402, put forth by the International Auditing and Assurance Standards Board (IAASB) of the International Federation of Accountants (IFAC), will play a large and ever-expanding role for reporting on controls at service organizations. ...
ISAE 3402: The International Standard on Assurance Engagements, “Assurance Reports on Controls at a Service Organization”, is the new global standard for assurance reporting on service organizations. What's interesting to note about...
PCI DSS Compliance will continue to be one of the most talked about regulatory compliance initiatives for 2010, without question. First and foremost, data breaches are still occurring, companies are still losing sensitive cardholder data, and lastly, PCI compliance is finally (yes finally) being...
Properly scoping a SAS 70 Type I or SAS 70 Type II audit is an extremely important component of the audit process itself. Why? Because as a service organization undergoing a SAS 70 audit, your goal is to have a report produced and issued to you...
Well, i'm sure by now millions of people have read the article in Newsweek about how Sarbanes-Oxley (SOX) could be brought down to it's knees and killed. Compliance auditors are getting cold...
The term PCI DSS auditors is technically incorrect, as one really should be looking for a Payment Card Industry Data Security Standard (PCI DSS) Qualified Security Assessor (QSA). So what really is a QSA? A QSA is an individual who has...
Looking for a PCI compliance Roadmap? As a Payment Card Industry Data Security Standards Qualified Security Assessor (PCI QSA), I'm often asked about the who, what, where, and why of PCI compliance. Most organizations (merchants and service providers) are...
