 




<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Regulatory Compliance, Governance and Security &#187; managed services sas 70</title>
	<atom:link href="http://itknowledgeexchange.techtarget.com/compliance-governance/tag/managed-services-sas-70/feed/" rel="self" type="application/rss+xml" />
	<link>http://itknowledgeexchange.techtarget.com/compliance-governance</link>
	<description></description>
	<lastBuildDate>Thu, 10 Mar 2011 15:04:50 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	
		<item>
		<title>SAS 70 Compliance &#124; Tips on Scoping a SAS 70 Audit</title>
		<link>http://itknowledgeexchange.techtarget.com/compliance-governance/sas-70-compliance-tips-on-scoping-a-sas-70-audit/</link>
		<comments>http://itknowledgeexchange.techtarget.com/compliance-governance/sas-70-compliance-tips-on-scoping-a-sas-70-audit/#comments</comments>
		<pubDate>Fri, 20 Mar 2009 18:20:21 +0000</pubDate>
		<dc:creator>Charles Denyer</dc:creator>
				<category><![CDATA[audit]]></category>
		<category><![CDATA[charles denyer]]></category>
		<category><![CDATA[general controls audit]]></category>
		<category><![CDATA[managed services sas 70]]></category>
		<category><![CDATA[SAS 70]]></category>
		<category><![CDATA[sas 70 compliance]]></category>
		<category><![CDATA[sas 70 resource guide]]></category>
		<category><![CDATA[sas 70 type ii]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/compliance-governance/sas-70-compliance-tips-on-scoping-a-sas-70-audit/</guid>
		<description><![CDATA[SAS 70 compliance is commonplace for many of today&#8217;s businesses. Unfortunately, one of the missing ingredients in understanding SAS 70 compliance is the scope of the audit. That&#8217;s right. The who, what, when, where, and why of the actual SAS 70 audit process. Most service organizations undergoing a SAS 70 audit think that they are [...]]]></description>
				<content:encoded><![CDATA[<p><a href="http://www.sas70.us.com">SAS 70 compliance</a> is commonplace for many of today&#8217;s businesses. Unfortunately, one of the missing ingredients in understanding SAS 70 compliance is the scope of the audit. That&#8217;s right. The who, what, when, where, and why of the actual SAS 70 audit process. Most service organizations undergoing a SAS 70 audit think that they are all the same, that is, one SAS 70 report should &#8220;look and feel&#8221; like another report. This is incorrect, as different industries and companies alike have varying requirements on what needs to be covered for SAS 70 compliance.</p>
<p>Here are some things you need to know to help determine SAS 70 scope:</p>
<p>1. What is the test period (if a SAS 70 Type II audit is being conducted)<br />
2. Where are all the locations (physical offices, data centers) that will be included in the testing of the audit.<br />
3. What is the audit actually COVERING? That is, is it a general controls audit or are their certain business processes that are being included in the scope of the audit? (This is essentially one of the biggest scoping issues you need to understand and come to an agreement on). </p>
<p>To learn more about SAS 70 compliance and scoping, visit the official <a href="http://www.sas70.us.com">SAS 70 Resource Guide</a>.</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/compliance-governance/sas-70-compliance-tips-on-scoping-a-sas-70-audit/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SAS 70 Audits &amp; Data Centers &#124; Tips on Preparing for the Audit</title>
		<link>http://itknowledgeexchange.techtarget.com/compliance-governance/sas-70-audits-data-centers-tips-on-preparing-for-the-audit/</link>
		<comments>http://itknowledgeexchange.techtarget.com/compliance-governance/sas-70-audits-data-centers-tips-on-preparing-for-the-audit/#comments</comments>
		<pubDate>Fri, 16 Jan 2009 15:46:54 +0000</pubDate>
		<dc:creator>Charles Denyer</dc:creator>
				<category><![CDATA[change management sas 70]]></category>
		<category><![CDATA[co-locations]]></category>
		<category><![CDATA[environmental security]]></category>
		<category><![CDATA[incident management]]></category>
		<category><![CDATA[incident management sas 70]]></category>
		<category><![CDATA[managed services sas 70]]></category>
		<category><![CDATA[payment card industry]]></category>
		<category><![CDATA[PCI]]></category>
		<category><![CDATA[PCI DSS]]></category>
		<category><![CDATA[physical security]]></category>
		<category><![CDATA[SAS 70]]></category>
		<category><![CDATA[sas 70 data centers]]></category>
		<category><![CDATA[sas70]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/compliance-governance/?p=31</guid>
		<description><![CDATA[Today&#8217;s data centers and managed services providers are complex businesses, providing customers with a wide array of services. As such, SAS 70 audits have become the standard compliance audit for assessing internal controls for data centers and managed services. But buyer beware, not all SAS 70 audits are the same when being conducted on data [...]]]></description>
				<content:encoded><![CDATA[<p>Today&#8217;s data centers and managed services providers are complex businesses, providing customers with a wide array of services.  As such, <a href="http://www.sas70.us.com">SAS 70 audits</a> have become the standard compliance audit for assessing internal controls for data centers and managed services.  But buyer beware, not all SAS 70 audits are the same when being conducted on data centers and managed service providers. So, what&#8217;s the scope, you say? Well, generally speaking a good quality SAS 70 audit process and its subsequent report should include the following areas for considerations of controls:</p>
<p>1. Executive Management/Strategic Management Drivers<br />
2. Human Resources<br />
3. Quality Assurance Activities<br />
3. Client Contract Processes<br />
4. Technical Client Provisioning Processes and Activities<br />
5. Change Management<br />
6. Incident Management<br />
7. Logical Security<br />
8. Network Security<br />
9. Shipping and Receiving Management<br />
10. Physical Security<br />
11. Environmental Security</p>
<p>Any SAS 70 conducted on data centers, managed services providers and co-locations entities that encompass the following above referenced areas can be considered a quality audit and report, at least in terms of scope. It&#8217;s then up to the CPA firm conducting the audit to actually perform testing for these above referenced areas, but that&#8217;s a whole other topic of discussion for a later date.</p>
<p>To learn more about SAS 70 audits, visit the official <a href="http://www.sas70.us.com">SAS 70 Resource Guide</a>.<br />
To learn more about PCI DSS assessments, visit the <a href="http://www.pciassessment.org">Payment Card Industry (PCI) Resource Guide</a>.</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/compliance-governance/sas-70-audits-data-centers-tips-on-preparing-for-the-audit/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
