<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Regulatory Compliance, Governance and Security &#187; Compliance</title>
	<atom:link href="http://itknowledgeexchange.techtarget.com/compliance-governance/tag/compliance/feed/" rel="self" type="application/rss+xml" />
	<link>http://itknowledgeexchange.techtarget.com/compliance-governance</link>
	<description></description>
	<lastBuildDate>Thu, 10 Mar 2011 15:04:50 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	
		<item>
		<title>SAS 70 Audits for Data Centers &#124; It&#8217;s a &#8220;SaaS&#8221;y Environment</title>
		<link>http://itknowledgeexchange.techtarget.com/compliance-governance/sas-70-audits-for-data-centers-its-a-saasy-environment/</link>
		<comments>http://itknowledgeexchange.techtarget.com/compliance-governance/sas-70-audits-for-data-centers-its-a-saasy-environment/#comments</comments>
		<pubDate>Wed, 13 May 2009 19:44:21 +0000</pubDate>
		<dc:creator>Charles Denyer</dc:creator>
				<category><![CDATA[charles denyer]]></category>
		<category><![CDATA[colocation]]></category>
		<category><![CDATA[Compliance]]></category>
		<category><![CDATA[data centers]]></category>
		<category><![CDATA[managed services]]></category>
		<category><![CDATA[sas 70 and SaaS]]></category>
		<category><![CDATA[Software as a Service]]></category>
		<category><![CDATA[SOX]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/compliance-governance/sas-70-audits-for-data-centers-its-a-saasy-environment/</guid>
		<description><![CDATA[SAS 70 audits are being performed at a record pace these days on data centers, managed service providers and co-location entities. The big question is why? Well, there are many general answers that we all hear, such as &#8220;Oh, it&#8217;s just today&#8217;s compliance environment&#8221; or &#8220;SOX has really affected our business&#8221;. Sure, these are true [...]]]></description>
				<content:encoded><![CDATA[<p><a href="http://www.sas70.us.com">SAS 70</a> audits are being performed at a record pace these days on data centers, managed service providers and co-location entities. The big question is why?  Well, there are many general answers that we all hear, such as &#8220;Oh, it&#8217;s just today&#8217;s compliance environment&#8221; or &#8220;SOX has really affected our business&#8221;.</p>
<p>Sure, these are true statements, somewhat boiler plate, but they are true.</p>
<p>In reality, dig a little deeper and stretch a little further into the insight and analysis and you will find that a large number of entities are operating in a Software as a Service (SaaS) mode and function, which essentially has resulted in the explosive growth for many data centers.  These companies who have a SaaS business model are being hit quite hard by the SAS 70 compliance mantra from their clients and as such, the down stream effect is that data centers are now included in the scope of many SaaS entities. Amazing what 2 to 3 years can do to the I.T. industry. I say this because it was not that long ago (2005 or so) that a large number of Data Centers were not SAS 70 compliant&#8230;and i argue that a big reason for this change has been that SaaS entities occupy racks and racks of space now days. </p>
<p>So there is your<a href="http://www.sas70.us.com/faqs/advantages-sas70-relationshipwithsaas.php"> SAS 70 and SaaS</a> connection.</p>
<p>But hey, as a SAS 70 Auditor, it&#8217;s just my opinion. </p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/compliance-governance/sas-70-audits-for-data-centers-its-a-saasy-environment/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SAS 70 Audit and Compliance Tips for Data Centers</title>
		<link>http://itknowledgeexchange.techtarget.com/compliance-governance/sas-70-audit-and-compliance-tips-for-data-centers/</link>
		<comments>http://itknowledgeexchange.techtarget.com/compliance-governance/sas-70-audit-and-compliance-tips-for-data-centers/#comments</comments>
		<pubDate>Fri, 08 May 2009 11:47:25 +0000</pubDate>
		<dc:creator>Charles Denyer</dc:creator>
				<category><![CDATA[charles denyer]]></category>
		<category><![CDATA[co-location]]></category>
		<category><![CDATA[Compliance]]></category>
		<category><![CDATA[cpa firm]]></category>
		<category><![CDATA[data center]]></category>
		<category><![CDATA[data center physical security]]></category>
		<category><![CDATA[sas 70 audit]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/compliance-governance/sas-70-audit-and-compliance-tips-for-data-centers/</guid>
		<description><![CDATA[Learn more about SAS 70 audits for data centers by reviewing the step by step SAS 70 audit process. From beginning to end, a number of steps, activities, and deliverables must be undertaken for ensuring the audit is successful. From the initial SAS70 readiness questionnaire assessments to the delivery of the final audit report, both [...]]]></description>
				<content:encoded><![CDATA[<p>Learn more about <a href="http://www.slideshare.net/sas70pciauditor/sas-70">SAS 70 audits</a> for data centers by reviewing the step by step SAS 70 audit process. From beginning to end, a number of steps, activities, and deliverables must be undertaken for ensuring the audit is successful. From the initial SAS70 readiness questionnaire assessments to the delivery of the final audit report, both the CPA firm conducting the audit and the data center employees will be working together in a collaborative manner for the audit.</p>
<p>Follow this step by step process if you are a data center or co-location facility that will be performing a SAS 70 audit in the near future:</p>
<p>First and foremost, identify the scope of the SAS 70 audit. Though it sounds quite straightforward, every CPA firm approaches scope in a slightly different manner. When identifying scope, there are a number of items to keep in mind, such as the following: Does the scope of the audit satisfy your client&#8217;s demands? Does the scope of the audit conform to industry accepted standards for SAS 70 audits on data centers?</p>
<p>Once the scope has been identified, it&#8217;s critical to begin the planning process with the auditors. A series of planning meetings should include a discussion on the following items: </p>
<p>1.  SAS 70 readiness questionnaire assessment and when it will be done (if deemed necessary).</p>
<p>2.  Discussion of type of sampling that is conducted for the audit (this is important as auditors have varying views on the numbers and amounts done on audit sampling).</p>
<p>3.  Discussion that identifies key personnel involved in the audit from both sides. </p>
<p>4.  Discussion on what <strong><a href="http://www.sas70.us.com/industries/data-center-colocations.php">data center physical security controls</a></strong> will be included in the scope of the audit.</p>
<p>These are just some general parameters to get you going in the right direction.</p>
<p>If you want to learn more about SAS 70 audits, then <strong><a href="http://www.sas70.us.com">visit the official SAS 70 resource guide</a></strong>, where you can obtain SAS 70 sample reports for review. </p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/compliance-governance/sas-70-audit-and-compliance-tips-for-data-centers/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Sarbanes Oxley (SOX) and SAS 70 &#124; What Does the Future Hold?</title>
		<link>http://itknowledgeexchange.techtarget.com/compliance-governance/sarbanes-oxley-sox-and-sas-70-what-does-the-future-hold/</link>
		<comments>http://itknowledgeexchange.techtarget.com/compliance-governance/sarbanes-oxley-sox-and-sas-70-what-does-the-future-hold/#comments</comments>
		<pubDate>Mon, 27 Apr 2009 02:06:42 +0000</pubDate>
		<dc:creator>Charles Denyer</dc:creator>
				<category><![CDATA[charles denyer]]></category>
		<category><![CDATA[Compliance]]></category>
		<category><![CDATA[corporate governance]]></category>
		<category><![CDATA[PCI]]></category>
		<category><![CDATA[Sarbanes-Oxley]]></category>
		<category><![CDATA[SAS 70]]></category>
		<category><![CDATA[SOX]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/compliance-governance/sarbanes-oxley-sox-and-sas-70-what-does-the-future-hold/</guid>
		<description><![CDATA[Sarbanes Oxley and SAS 70 audits have had a monumental impact on corporate governance and compliance. So much so, they almost invented a huge part of the pie. As a SAS 70 auditor, i&#8217;m often asked what does the future hold for Sarbanes Oxley (SOX) compliance and also SAS 70. Well, my friends, let&#8217;s take [...]]]></description>
				<content:encoded><![CDATA[<p><strong><a href="http://www.sas70.us.com/white-papers/sox-and-sas70.php">Sarbanes Oxley and SAS 70</a></strong> audits have had a monumental impact on corporate governance and compliance. So much so, they almost invented a huge part of the pie. As a SAS 70 auditor, i&#8217;m often asked what does the future hold for Sarbanes Oxley (SOX) compliance and also SAS 70.</p>
<p>Well, my friends, let&#8217;s take a look at the crystal ball and let me give you my thoughts on SOX and SAS 70.</p>
<p>First and foremost, compliance is NOT going away. Sure, there have been growing pains with the cost and time associated with SOX compliance, but those costs are starting to become greatly streamlined as organizations are finding ways to be more efficient with SOX compliance.  In short, it&#8217;s here to stay, so consider it a part of life in the business world.  With the rash of fraud that occurred on Wall Street which almost toppled the capital markets overnight, there will no doubt be MORE compliance laws, regulations, and rules echoing out of the halls of congress. I would not be worried and thinking too much about SOX, but rather, what else is in the witches brew that could be cooked up on Capital Hill. Think i&#8217;m kiding? <strong><a href="http://www.pciassessment.org">PCI compliance</a></strong> recently became codified into law in MN with many other states following closely behind.</p>
<p>With SOX staying, you can rest assured that SAS 70 will be hanging around like a little brother. And why not, it&#8217;s been a hugely successful internal control auditing mechanism that has shed light on service organizations and how they conduct business. </p>
<p>Compliance is a way of life; as sure as death and taxes. The key is finding a way to meet compliance in a cost-effective and streamlined manner.</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/compliance-governance/sarbanes-oxley-sox-and-sas-70-what-does-the-future-hold/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SAS 70 Type II Audits &#124; An Auditor&#8217;s Expert Opinion on Pricing</title>
		<link>http://itknowledgeexchange.techtarget.com/compliance-governance/sas-70-type-ii-audits-an-auditors-expert-opinion-on-pricing/</link>
		<comments>http://itknowledgeexchange.techtarget.com/compliance-governance/sas-70-type-ii-audits-an-auditors-expert-opinion-on-pricing/#comments</comments>
		<pubDate>Sat, 29 Nov 2008 17:30:27 +0000</pubDate>
		<dc:creator>Charles Denyer</dc:creator>
				<category><![CDATA[Compliance]]></category>
		<category><![CDATA[SAS 70]]></category>
		<category><![CDATA[sas 70 audit report]]></category>
		<category><![CDATA[sas 70 control objectives]]></category>
		<category><![CDATA[SAS 70 readiness questionnaire]]></category>
		<category><![CDATA[SAS 70 Type I]]></category>
		<category><![CDATA[sas 70 type ii]]></category>
		<category><![CDATA[sas70]]></category>
		<category><![CDATA[sas70 pricing]]></category>
		<category><![CDATA[sas70 readiness assessment questionnaires]]></category>
		<category><![CDATA[sas70 sample reports]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/compliance-governance/sas-70-type-ii-audits-an-auditors-expert-opinion-on-pricing/</guid>
		<description><![CDATA[People often ask me what the price of a SAS 70 Type I or SAS 70 Type II audit is. My response? That depends, I say, on many, many factors. Here is what needs to be understood when considering pricing factors for SAS 70 Type I and Type II audits: 1. The CPA firm-Are you [...]]]></description>
				<content:encoded><![CDATA[<p>People often ask me what the price of a <a href="http://www.sas70.us.com">SAS 70</a> Type I or SAS 70 Type II audit is. My response? That depends, I say, on many, many factors.  Here is what needs to be understood when considering pricing factors for SAS 70 Type I and Type II audits:</p>
<p>1. The CPA firm-Are you looking for brand recognition or are you looking for a cost-effective provider which can simply help you &#8220;check the box&#8221; for SAS 70 compliance.</p>
<p>2. Scope-What is being examined and tested from a control perspective for SAS 70 audits? Are you looking for just a general controls audit or an audit that also includes specific business processes?</p>
<p>3. Testing period: For SAS 70 Type II audits, what is the testing period going to be? The longer the test period, the more the audit will cost as auditors have to pull larger samples, do more testing, etc.</p>
<p>4. Location of testing: How many physical areas does your organization have that will fall under the scope of the SAS 70 audit? Having more than one means that auditors will ultimately have to travel to numerous locations to conduct more testing. Again, more locations, more time, money, and expenses out of your pocket for the audit itself.</p>
<p>5. Are you confident you can obtain SAS 70 compliance without conducting a SAS 70 readiness assessment? If not and you need assistance identifying weaknesses and gaps within your control environment, then expect to spend more time, money, and resources on the front end of a SAS 70 audit for preparing in an adequate manner.</p>
<p>As you can see, there is no quick, easy, black and white answer to the cost of a SAS 70 Type I or Type II audit. </p>
<p>To learn more about statement of auditing standards no. 70, <a href="http://www.sas70.us.com">visit the official sas 70 resource guide</a>, where you can obtain a wealth of information on sas 70 audits. </p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/compliance-governance/sas-70-type-ii-audits-an-auditors-expert-opinion-on-pricing/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>PCI DSS &amp; SAS70 Audits &#124; If you need both, then read on&#8230;</title>
		<link>http://itknowledgeexchange.techtarget.com/compliance-governance/pci-dss-sas70-audits-if-you-need-both-then-read-on/</link>
		<comments>http://itknowledgeexchange.techtarget.com/compliance-governance/pci-dss-sas70-audits-if-you-need-both-then-read-on/#comments</comments>
		<pubDate>Fri, 26 Sep 2008 18:17:17 +0000</pubDate>
		<dc:creator>Charles Denyer</dc:creator>
				<category><![CDATA[audits]]></category>
		<category><![CDATA[Compliance]]></category>
		<category><![CDATA[PCI DSS]]></category>
		<category><![CDATA[pci dss qsa]]></category>
		<category><![CDATA[SAS 70]]></category>
		<category><![CDATA[sas70]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/compliance-governance/pci-dss-sas70-audits-if-you-need-both-then-read-on/</guid>
		<description><![CDATA[PCI DSS and SAS70 audits are two of the most common regulatory compliance initiatives currently facing many service organizations in today&#8217;s current business climate. Add to the mix of some unique similarities that both PCI DSS and SAS70 possess, and you can have some marginal to meaningful efficiencies of scale when one firm conducts both [...]]]></description>
				<content:encoded><![CDATA[<p>PCI DSS and SAS70 audits are two of the most common regulatory compliance initiatives currently facing many service organizations in today&#8217;s current business climate. Add to the mix of some unique similarities that both PCI DSS and SAS70 possess, and you can have some marginal to meaningful efficiencies of scale when one firm conducts both the PCI DSS assessment and the SAS70 audit.</p>
<p>Here&#8217;s how it works. When you look at the 12 core standards as put forth for PCI DSS, some of those functional areas can very well be part of a SAS70 audit, if scoped properly.  That&#8217;s not to say that a PCI DSS and a SAS70 audit are a one for one match-by no means are they at all, but some items are examined and tested for in both the PCI DSS assessment and the SAS70 audit.</p>
<p>In short, there are only a handful of firms that are currently conducting both PCI DSS and SAS70 compliance. If you can find one, and they are out there, and they are willing to work on both the PCI DSS assessment and the SAS70 audit for purposes of document collection, analysis, discovery, and a host of other activities, then you have found a WIN WIN.  Though the PCI DSS is much more technology driven than a SAS70 audit (and again for the thousandth time, a SAS70 is NOT an I.T. audit), there will be much learned from the PCI DSS assessment that will create great value and savings for purposes of the SAS70 audit.</p>
<p>If you want to learn more about this along with creating a Gap analysis, then contact <strong><a href="http://www.ndbcpa.com ">NDB, Accountants and Consultants</a></strong></p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/compliance-governance/pci-dss-sas70-audits-if-you-need-both-then-read-on/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SAS70 Reports &#124; Know the Difference Between Type I &amp; Type II</title>
		<link>http://itknowledgeexchange.techtarget.com/compliance-governance/sas70-reports-know-the-difference-between-type-i-type-ii/</link>
		<comments>http://itknowledgeexchange.techtarget.com/compliance-governance/sas70-reports-know-the-difference-between-type-i-type-ii/#comments</comments>
		<pubDate>Mon, 08 Sep 2008 16:04:13 +0000</pubDate>
		<dc:creator>Charles Denyer</dc:creator>
				<category><![CDATA[audits]]></category>
		<category><![CDATA[Compliance]]></category>
		<category><![CDATA[regulatory compliance]]></category>
		<category><![CDATA[Sarbanes-Oxley]]></category>
		<category><![CDATA[sas70]]></category>
		<category><![CDATA[sas70 sample reports]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/compliance-governance/sas70-reports-know-the-difference-between-type-i-type-ii/</guid>
		<description><![CDATA[If your company is needing to be SAS70 compliant, then a good start is to learn about what a SAS70 audit is and what the difference is between a SAS70 Type I &#38; SAS70 Type II audit report. In short, a SAS70 Type I is simply an audit that is a snapshot in time; an [...]]]></description>
				<content:encoded><![CDATA[<p>If your company is needing to be SAS70 compliant, then a good start is to learn about what a SAS70 audit is and what the difference is between a SAS70 Type I &amp; SAS70 Type II audit report.</p>
<p>In short, a <a href="http://www.sas70.us.com/services/sas70-typei-audit.php">SAS70 Type I</a> is simply an audit that is a snapshot in time; an audit for a particular day. For example, a Type I report would be given a date of August 31, 2008.  </p>
<p>A SAS70 Type II audit report is a report that will test the operating effectiveness of those controls over a time period, traditionally six (6) months. For example, a SAS70 Type II report would cover a period from January 1, 2008 to June 30, 2008.  </p>
<p>It is important to note that a SAS70 Type II is what the market is calling for, that is, it suffices for Sarbanes Oxley compliance and is looked upon as a much superior audit than a SAS70 Type I report.</p>
<p>A good example of learning more about SAS70 audits is to obtain a <a href="http://www.sas70.us.com/what-is/download-sample-sas70.php">SAS70 sample report,</a> whereby you can read and understand what the major components and parts are of a final report.</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/compliance-governance/sas70-reports-know-the-difference-between-type-i-type-ii/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SAS 70 Audits for Data Centers &amp; Managed Services</title>
		<link>http://itknowledgeexchange.techtarget.com/compliance-governance/sas-70-audits-for-data-centers-managed-services/</link>
		<comments>http://itknowledgeexchange.techtarget.com/compliance-governance/sas-70-audits-for-data-centers-managed-services/#comments</comments>
		<pubDate>Thu, 28 Aug 2008 13:07:49 +0000</pubDate>
		<dc:creator>Charles Denyer</dc:creator>
				<category><![CDATA[Compliance]]></category>
		<category><![CDATA[data centers]]></category>
		<category><![CDATA[DataCenter]]></category>
		<category><![CDATA[managed services]]></category>
		<category><![CDATA[SAS 70]]></category>
		<category><![CDATA[SAS 70 download]]></category>
		<category><![CDATA[SAS 70 readiness questionnaire]]></category>
		<category><![CDATA[sas70 sample reports]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/compliance-governance/sas-70-audits-for-data-centers-managed-services/</guid>
		<description><![CDATA[If you are a data center or manged services provider and need a SAS 70 audit, then here are some helpful tips and strategies for finding the right firm, getting a fair and equitable fee, and for ensuring you have the proper scope for the audit. Today&#8217;s data center are complex entities, providing customers with [...]]]></description>
				<content:encoded><![CDATA[<p>If you are a data center or manged services provider and need a SAS 70 audit, then here are some helpful tips and strategies for finding the right firm, getting a fair and equitable fee, and for ensuring you have the proper scope for the audit.</p>
<p>Today&#8217;s data center are complex entities, providing customers with a broad array of services, thus it&#8217;s important your SAS 70 report meets and exceeds the objectives of the audit for you and your customers.</p>
<p>1. First and foremost, find a CPA firm that specializes in not only SAS 70 audits, but one that has a strong understanding of the services offered by your organization. From ping, power, and pipe to highly complex managed services, it&#8217;s important to remember to keep all critical services within the scope of the audit.</p>
<p>2. Get a fixed fee for your audit. With the rising cost of expenses, such as gas, travel and other ancillary services ,getting a &#8220;fixed fee&#8221; for your SAS 70 audit ensures that costs are contained, and you have an exact idea of what you will be paying for the audit. SAS 70 audits that do not include expenses will ending costing data centers approximately an additional 20% or more over the original agreed fee. Hourly rates for auditing data centers should be considered a thing of the past-work hard to get a fixed. fee.</p>
<p>3. Scope the audit correctly by making sure the CPA firm conducting the SAS 70 audit includes the following areas for examination and testing:</p>
<ul>
<li>Executive Tone</li>
<li>Human Resources</li>
<li>Customer Contract Process</li>
<li>Customer Provisioning Process</li>
<li>Incident Management</li>
<li>Change Management</li>
<li>Logical Security</li>
<li>Network Security</li>
<li>Physical Security</li>
<li>Environmental Security</li>
<li>Computer Operations</li>
</ul>
<p>There also a number of <a href="http://www.sas70.us.com/industries/data-center-colocations.php">Data Center best practices</a> that should be in place for helping facilitate the overall success of the SAS 70 audit.</p>
<p>To learn more about SAS 70 audits or to receive a <a href="http://www.sas70.us.com/what-is/download-sample-sas70.php">SAS 70 sample report</a>, visit the official <a href="http://www.sas70.us.com">SAS 70 Resource Guide</a>.</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/compliance-governance/sas-70-audits-for-data-centers-managed-services/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SAS 70 Audits &amp; Software as a Service (SaaS) &#124; Helpful Audit Tips</title>
		<link>http://itknowledgeexchange.techtarget.com/compliance-governance/sas-70-audits-software-as-a-service-saas-helpful-audit-tips/</link>
		<comments>http://itknowledgeexchange.techtarget.com/compliance-governance/sas-70-audits-software-as-a-service-saas-helpful-audit-tips/#comments</comments>
		<pubDate>Tue, 26 Aug 2008 20:05:29 +0000</pubDate>
		<dc:creator>Charles Denyer</dc:creator>
				<category><![CDATA[Compliance]]></category>
		<category><![CDATA[regulatory compliance]]></category>
		<category><![CDATA[SaaS]]></category>
		<category><![CDATA[SAS 70]]></category>
		<category><![CDATA[sas70]]></category>
		<category><![CDATA[sas70 sample reports]]></category>
		<category><![CDATA[Software as a Service]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/compliance-governance/sas-70-audits-software-as-a-service-saas-helpful-audit-tips/</guid>
		<description><![CDATA[The Software as a Service (SaaS) industry and SAS 70 audits actually have quite a bit in common. First and foremost, both the SAS 70 auditing standard and the SaaS industry have seen explosive growth in the past five years, thanks in large part to regulatory compliance and the advent of technology. Second, from a [...]]]></description>
				<content:encoded><![CDATA[<p>The Software as a Service (SaaS) industry and SAS 70 audits actually have quite a bit in common. First and foremost, both the SAS 70 auditing standard and the SaaS industry have seen explosive growth in the past five years, thanks in large part to regulatory compliance and the advent of technology.  Second, from a compliance standpoint, SaaS providers are increasingly being required to be SAS 70 Type II compliant.  </p>
<p>The sheer nature of the SaaS industry has forced the SAS 70 auditing standard&#8217;s requirement onto many SaaS providers.  What&#8217;s more, what may have been perceived as a market edge, a compliance luxury, the SAS 70 audit is now a must have for SaaS providers, or lose potential clients and future prospects.</p>
<p>If you are an organization falling under the SaaS industry label, there are a few helpful things you can do to get ready for a SAS 70 audit:</p>
<p>1. Find a firm that truly understands the SaaS industry-it can be complicated due to the nature of the industry itself.<br />
2. Fina a firm that will give you a fixed fee for the audits. That&#8217;s right, no need to pay additional out of pocket expenses to the auditor. Most reputable firms are now moving towards the fixed fee mentality, so your checkbook should too.<br />
3. Make sure you define the scope early with the CPA firm doing the audit. The SaaS industry has many providers and outsourcing entities that could potentially be in scope for the audit of your company. From data centers to external, third party managed providers of security, you and the CPA firm need to nail down who and what is included in the scope. This will have a sizable impact on the time, fees, and man hours needed to complete the audit.</p>
<p>To learn more about SAS 70 audit, visit the official <a href="http://www.sas70.us.com">SAS 70 Resource guide</a> where you can <a href="http://www.sas70.us.com/what-is/download-sample-sas70.php">receive sample SAS 70 reports</a> for view.</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/compliance-governance/sas-70-audits-software-as-a-service-saas-helpful-audit-tips/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SAS70 Audits and PCI Assessments &#124; GAP Analysis</title>
		<link>http://itknowledgeexchange.techtarget.com/compliance-governance/sas70-audits-and-pci-assessments/</link>
		<comments>http://itknowledgeexchange.techtarget.com/compliance-governance/sas70-audits-and-pci-assessments/#comments</comments>
		<pubDate>Mon, 18 Aug 2008 15:30:41 +0000</pubDate>
		<dc:creator>Charles Denyer</dc:creator>
				<category><![CDATA[Compliance]]></category>
		<category><![CDATA[pci compliance]]></category>
		<category><![CDATA[pci dss qsa]]></category>
		<category><![CDATA[SAS 70]]></category>
		<category><![CDATA[sas70]]></category>
		<category><![CDATA[What is SAS 70?]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/compliance-governance/sas70-audits-and-pci-assessments/</guid>
		<description><![CDATA[Many organizations are now being required to be SAS70 and PCI DSS compliant. With that said, I am often asked where the synergies or overlaps are for a SAS70 audit, which can only be done by a CPA firm and a PCI DSS assessment, which can only be done by a qualified PCI QSA individual. [...]]]></description>
				<content:encoded><![CDATA[<p>Many organizations are now being required to be SAS70 and PCI DSS compliant. With that said, I am often asked where the synergies or overlaps are for a SAS70 audit, which can only be done by a CPA firm and a PCI DSS assessment, which can only be done by a qualified PCI QSA individual.</p>
<p>My answer to this is yes, IF and only IF, you obtain services from an individual or a firm who is both a CPA and one that is a qualified PCI QSA individual, AND that they produce both high quality SAS70 audits and PCI DSS assessments. The SAS70 auditing standard is rather loose, so its incumbent upon the firm issuing the SAS70 report to produce a report that is high quality. High quality means it is a report that covers all essential baseline elements considered for a SAS70 audit, which should include substantial testing for network security and logical access. If done correctly, you will see an overlap with other areas within the PCI DSS assessment. So, this is the yes answer.  If you engage in two different firms, one to do the SAS70 audit, the other to do the PCI DSS assessment, then you can have conflicting views on what each report should contain. In short, the synergies occur when you use a firm to do both the SAS70 and PCI assessment.</p>
<p>For more information on Payment Card Industry compliance, visit the <strong><a href="http://www.pcisecuritystandards.org">official PCI website</a></strong>.</p>
<p>For more information on SAS70 audits, visit the official <strong><a href="http://www.sas70.us.com">SAS70 Resource Guide website</a></strong>.</p>
<p><strong><em>I have also created a SAS70 and PCI DSS Gap analysis, which shows the overlapping areas</em></strong></p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/compliance-governance/sas70-audits-and-pci-assessments/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SAS70 &amp; PCI Compliance &#124; Creating Audit Efficiencies</title>
		<link>http://itknowledgeexchange.techtarget.com/compliance-governance/sas70-pci-compliance-creating-audit-efficiencies/</link>
		<comments>http://itknowledgeexchange.techtarget.com/compliance-governance/sas70-pci-compliance-creating-audit-efficiencies/#comments</comments>
		<pubDate>Sun, 03 Aug 2008 14:49:44 +0000</pubDate>
		<dc:creator>Charles Denyer</dc:creator>
				<category><![CDATA[Auditing]]></category>
		<category><![CDATA[audits]]></category>
		<category><![CDATA[Compliance]]></category>
		<category><![CDATA[GLBA]]></category>
		<category><![CDATA[HIPAA]]></category>
		<category><![CDATA[payment card industry]]></category>
		<category><![CDATA[PCI]]></category>
		<category><![CDATA[qsa]]></category>
		<category><![CDATA[regulatory compliance]]></category>
		<category><![CDATA[Sarbanes-Oxley]]></category>
		<category><![CDATA[SAS 70]]></category>
		<category><![CDATA[sas70]]></category>
		<category><![CDATA[sas70 sample reports]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/compliance-governance/sas70-pci-compliance-creating-audit-efficiencies/</guid>
		<description><![CDATA[SAS70 audits have grown tremendously in the past five years, largely due in part to the explosive growth of federal regulatory compliance laws and legislation. Interestingly also, Payment Card Industry (PCI) compliance has also received much attention as of recent, particularly with the recent breaches of security in a number of well publicized cases. I&#8217;m [...]]]></description>
				<content:encoded><![CDATA[<p><strong><a href="http://www.sas70.us.com">SAS70 audits</a></strong> have grown tremendously in the past five years, largely due in part to the explosive growth of federal regulatory compliance laws and legislation.  Interestingly also, Payment Card Industry (PCI) compliance has also received much attention as of recent, particularly with the recent breaches of security in a number of well publicized cases.</p>
<p>I&#8217;m often asked by organizations that have to be SAS70 &amp; PCI compliant if these two audits can be a 2 for 1, that is, can I conduct SAS70 fieldwork and also hopefully piggyback off of that work to help augment a marginal part of the PCI compliance examination for QSA?  </p>
<p>There are synergies that can be created, allowing an experienced auditor to use his or her best judgment for creating these synergies.  If you look at the 12 core areas of the PCI compliance, you can extract elements from these very requirements that would most surely be included in a good, quality comprehensive SAS70 audit. I stress &#8220;good, quality&#8221; audit because the looseness of the SAS70 standard allows auditors to employ vastly different methodologies. </p>
<p>For example, PCI Requirement #9, &#8220;Restricting Physical Access to Cardholder Data&#8221; could be argued that this is very much in line with a common SAS70 control objective for &#8220;Physical Security&#8221;.  Remember this, there are only so many regulatory compliance and governance laws that can be pushed forward before they start to become overlapping and redundant to a certain degree.</p>
<p>If you can find a quality firm that does both SAS70 auditing and PCI QSA compliance, then it would be most beneficial to create these synergies for the audit. </p>
<p>One of the most valuable tools I recently created was a SAS70 &amp; PCI Gap analysis, showing you the overlapping features of both audits, allowing any firm to create these very efficiencies for these compliance examinations.</p>
<p>For more information on SAS70 audits, or to receive <strong><a href="http://www.sas70.us.com/what-is/download-sample-sas70.php">SAS70 sample reports</a></strong>, please visit the official <strong><a href="http://www.sas70.us.com/what-is/what-is-sas70.php">SAS70 resource center</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/compliance-governance/sas70-pci-compliance-creating-audit-efficiencies/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
