<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Regulatory Compliance, Governance and Security &#187; Sarbanes-Oxley</title>
	<atom:link href="http://itknowledgeexchange.techtarget.com/compliance-governance/tag/sarbanes-oxley/feed/" rel="self" type="application/rss+xml" />
	<link>http://itknowledgeexchange.techtarget.com/compliance-governance</link>
	<description></description>
	<lastBuildDate>Thu, 10 Mar 2011 15:04:50 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	
		<item>
		<title>Could Sarbanes-Oxley (SOX) be Killed? &#124; An Auditor&#8217;s Viewpoint</title>
		<link>http://itknowledgeexchange.techtarget.com/compliance-governance/could-sarbanes-oxley-sox-be-killed-an-auditors-viewpoint/</link>
		<comments>http://itknowledgeexchange.techtarget.com/compliance-governance/could-sarbanes-oxley-sox-be-killed-an-auditors-viewpoint/#comments</comments>
		<pubDate>Fri, 11 Dec 2009 13:42:15 +0000</pubDate>
		<dc:creator>Charles Denyer</dc:creator>
				<category><![CDATA[charles denyer]]></category>
		<category><![CDATA[PCAOB]]></category>
		<category><![CDATA[Sarbanes-Oxley]]></category>
		<category><![CDATA[sarbox]]></category>
		<category><![CDATA[SAS 70]]></category>
		<category><![CDATA[SOX]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/compliance-governance/could-sarbanes-oxley-sox-be-killed-an-auditors-viewpoint/</guid>
		<description><![CDATA[Well, i&#8217;m sure by now millions of people have read the article in Newsweek about how Sarbanes-Oxley (SOX) could be brought down to it&#8217;s knees and killed. Compliance auditors are getting cold hands thinking of the unemployment line! Not so fast, read into the article some more and I would argue that the real issue [...]]]></description>
				<content:encoded><![CDATA[<p>Well, i&#8217;m sure by now millions of people have read the article in Newsweek about how<strong> <a href="http://www.businessweek.com/magazine/content/09_48/b4157040803359.htm">Sarbanes-Oxley (SOX) could be brought down to it&#8217;s knees and killed</a></strong>.</p>
<p>Compliance auditors are getting cold hands thinking of the unemployment line! Not so fast, read into the article some more and I would argue that the real issue being asserted within this article is the legal framework of how the PCAOB is structured, overseen, and how it appoints members to this organization. Sure, there are rumblings about the effectiveness of SOX, but the thought of taking away most of it&#8217;s original intent is not something too many politicians would angle for. Section 404 has been a success and so has the advent of SAS 70 audits on third party providers and service organizations. Think any of these provisions on attesting on outsourcing entities are going away; I highly doubt it. So, while we may see the PCAOB and SOX &#8220;watered down&#8221;, it&#8217;s doubtful key provisions would be killed all together. Could you imagine another Enron, Worldcom without any SOX provisions in place because they were killed? Again, highly doubtful. </p>
<p>What has gained so much traction from SOX are SAS 70 audits, and with or without SOX, SAS 55 requires SAS 70 audits for purposes of financial statement reporting. Additionally, companies will not just stop asking for SAS 70 audits even if key provisions for SOX have been amended. Why? Because they have become very familiar, comfortable, and interested in what controls third party providers have in place.</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/compliance-governance/could-sarbanes-oxley-sox-be-killed-an-auditors-viewpoint/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Sarbanes Oxley (SOX) and SAS 70 &#124; What Does the Future Hold?</title>
		<link>http://itknowledgeexchange.techtarget.com/compliance-governance/sarbanes-oxley-sox-and-sas-70-what-does-the-future-hold/</link>
		<comments>http://itknowledgeexchange.techtarget.com/compliance-governance/sarbanes-oxley-sox-and-sas-70-what-does-the-future-hold/#comments</comments>
		<pubDate>Mon, 27 Apr 2009 02:06:42 +0000</pubDate>
		<dc:creator>Charles Denyer</dc:creator>
				<category><![CDATA[charles denyer]]></category>
		<category><![CDATA[Compliance]]></category>
		<category><![CDATA[corporate governance]]></category>
		<category><![CDATA[PCI]]></category>
		<category><![CDATA[Sarbanes-Oxley]]></category>
		<category><![CDATA[SAS 70]]></category>
		<category><![CDATA[SOX]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/compliance-governance/sarbanes-oxley-sox-and-sas-70-what-does-the-future-hold/</guid>
		<description><![CDATA[Sarbanes Oxley and SAS 70 audits have had a monumental impact on corporate governance and compliance. So much so, they almost invented a huge part of the pie. As a SAS 70 auditor, i&#8217;m often asked what does the future hold for Sarbanes Oxley (SOX) compliance and also SAS 70. Well, my friends, let&#8217;s take [...]]]></description>
				<content:encoded><![CDATA[<p><strong><a href="http://www.sas70.us.com/white-papers/sox-and-sas70.php">Sarbanes Oxley and SAS 70</a></strong> audits have had a monumental impact on corporate governance and compliance. So much so, they almost invented a huge part of the pie. As a SAS 70 auditor, i&#8217;m often asked what does the future hold for Sarbanes Oxley (SOX) compliance and also SAS 70.</p>
<p>Well, my friends, let&#8217;s take a look at the crystal ball and let me give you my thoughts on SOX and SAS 70.</p>
<p>First and foremost, compliance is NOT going away. Sure, there have been growing pains with the cost and time associated with SOX compliance, but those costs are starting to become greatly streamlined as organizations are finding ways to be more efficient with SOX compliance.  In short, it&#8217;s here to stay, so consider it a part of life in the business world.  With the rash of fraud that occurred on Wall Street which almost toppled the capital markets overnight, there will no doubt be MORE compliance laws, regulations, and rules echoing out of the halls of congress. I would not be worried and thinking too much about SOX, but rather, what else is in the witches brew that could be cooked up on Capital Hill. Think i&#8217;m kiding? <strong><a href="http://www.pciassessment.org">PCI compliance</a></strong> recently became codified into law in MN with many other states following closely behind.</p>
<p>With SOX staying, you can rest assured that SAS 70 will be hanging around like a little brother. And why not, it&#8217;s been a hugely successful internal control auditing mechanism that has shed light on service organizations and how they conduct business. </p>
<p>Compliance is a way of life; as sure as death and taxes. The key is finding a way to meet compliance in a cost-effective and streamlined manner.</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/compliance-governance/sarbanes-oxley-sox-and-sas-70-what-does-the-future-hold/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SAS 70 Audits &#124; Understanding PRICING for SAS 70 Engagements</title>
		<link>http://itknowledgeexchange.techtarget.com/compliance-governance/sas-70-audits-understanding-pricing-for-sas-70-engagements/</link>
		<comments>http://itknowledgeexchange.techtarget.com/compliance-governance/sas-70-audits-understanding-pricing-for-sas-70-engagements/#comments</comments>
		<pubDate>Wed, 31 Dec 2008 23:30:00 +0000</pubDate>
		<dc:creator>Charles Denyer</dc:creator>
				<category><![CDATA[cpa firm]]></category>
		<category><![CDATA[Sarbanes-Oxley]]></category>
		<category><![CDATA[sas 70 audit]]></category>
		<category><![CDATA[sas 70 type i type ii]]></category>
		<category><![CDATA[sas70]]></category>
		<category><![CDATA[SOX]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/compliance-governance/?p=73</guid>
		<description><![CDATA[SAS 70 Type I and Type II audits have become common for many organizations providing critical outsourcing services to companies. Known as service organizations, they have all landed on the regulatory radar of having to be SAS 70 compliant, due in large part because of Sarbanes Oxley (SOX) or any other large number of federal [...]]]></description>
				<content:encoded><![CDATA[<p><strong><a href="http://www.sas70.us.com">SAS 70 </a></strong>Type I and Type II audits have become common for many organizations providing critical outsourcing services to companies. Known as service organizations, they have all landed on the regulatory radar of having to be SAS 70 compliant, due in large part because of Sarbanes Oxley (SOX) or any other large number of federal regulatory compliance mandates.. I’m often asked how much does a SAS 70 Type I or Type II audit cost. Well, that depends on a number of factors and circumstances that will be discussed today.</p>
<p>Issue #1: Choosing a Firm for the SAS 70 Audit</p>
<p>There are a number of providers available for SAS 70 audits, ranging from regional CPA firms to the nationally recognized big four firms. And as with anything in life, most organizations try to find the most value for their money, but remember, you get what you pay for. Small firms may be cost-effective, but they may lack the expertise and name recognition of other firms. The big four accounting firms will charge you a heavy premium audit fee, yet you get their name on the report, ultimately giving it a high level of recognition, simply based on who they are.</p>
<p>Remember, SAS 70 Type I and Type II audit prices have a wide range, so it’s probably a wise choice to pick in between, that is, a firm who is specialized, nationally known, not too large and bureaucratic, and provides you with a cost-effective, “fixed fee” that is fair, equitable, and you can live with.</p>
<p>Issue #2: Scoping the SAS 70 Audit</p>
<p>Numerous factors ultimately come into play for pricing considerations, but scoping is extremely important. It tells you and the CPA firm what will be tested, where it will be tested, and how long the test period will be, if a SAS 70 Type II audit is being performed. </p>
<p>To learn more about SAS 70 audits, <strong><a href="http://www.sas70.us.com">visit the official sas 70 resource guide</a>. </strong></p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/compliance-governance/sas-70-audits-understanding-pricing-for-sas-70-engagements/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SAS 70 and Regulatory Audits &#124; What is the Impact to our Economy?</title>
		<link>http://itknowledgeexchange.techtarget.com/compliance-governance/sas-70-and-regulatory-audits-what-is-the-impact-to-our-economy/</link>
		<comments>http://itknowledgeexchange.techtarget.com/compliance-governance/sas-70-and-regulatory-audits-what-is-the-impact-to-our-economy/#comments</comments>
		<pubDate>Wed, 31 Dec 2008 23:19:49 +0000</pubDate>
		<dc:creator>Charles Denyer</dc:creator>
				<category><![CDATA[glbay]]></category>
		<category><![CDATA[HIPAA]]></category>
		<category><![CDATA[impacts of audits to economy]]></category>
		<category><![CDATA[payment card industry]]></category>
		<category><![CDATA[PCI]]></category>
		<category><![CDATA[Sarbanes-Oxley]]></category>
		<category><![CDATA[SAS 70]]></category>
		<category><![CDATA[sas70]]></category>
		<category><![CDATA[section 404]]></category>
		<category><![CDATA[SOX]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/compliance-governance/?p=69</guid>
		<description><![CDATA[The impacts, in my opinion, are the following. Interestingly, the last decade has seen somewhat of a shift in auditing. That&#8217;s not to say there has been a decrease in this specialized service, quite to the contrary. The shift has occurred as financial statement auditing has begun to see somewhat of a flat line in [...]]]></description>
				<content:encoded><![CDATA[<p>The impacts, in my opinion, are the following.  Interestingly, the last decade has seen somewhat of a shift in auditing. That&#8217;s not to say there has been a decrease in this specialized service, quite to the contrary. The shift has occurred as financial statement auditing has begun to see somewhat of a flat line in growth, while highly specialized audits, such as Statement on Auditing Standards No. 70 (SAS 70) have been given the limelight. Regulatory legislation, such as the Sarbanes-Oxley Act of 2002, the Health Insurance Portability and Accountability Act (HIPAA), the <a href="http://www.sas70.us.com/white-papers/gramm-leach-privacy-rule.php">Gramm-Leach Bliley Act (GLBA)</a>, and numerous other federal and state laws have pushed audits, such as SAS 70, into the forefront. Additional audit or examination procedures that are non-financial in nature include the<a href="http://www.pciassessment.org"> Payment Card Industry (PCI) audits</a>, which are undertaken by entities that process credit card transactions, along with numerous ISO quality audits.</p>
<p>From a regulatory compliance perspective, impacts of audits to the economy have resulted in many service organizations having to become SAS 70 Type II compliant. It all starts with Section 404 of the <a href="http://www.sas70.us.com/white-papers/sox-and-sas70.php">Sarbanes-Oxley Act of 2002.</a> In simple terms, section 404 states that management must establish effective internal controls as it relates to financial reporting and must also gain assurances from outsourced third-party vendors (i.e., service organizations) whose controls can affect financial reporting. Though it may sound somewhat vague and blurred, it’s really quite straightforward. Take note of the following example to see the effect <a href="http://www.sas70.us.com/white-papers/sox-and-sas70.php">SAS 70 has on section 404</a> of publicly traded companies.</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/compliance-governance/sas-70-and-regulatory-audits-what-is-the-impact-to-our-economy/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SAS 70 Type II Audit Reports &#124; Why SAS 70 is Here to Stay</title>
		<link>http://itknowledgeexchange.techtarget.com/compliance-governance/sas-70-type-ii-audit-reports-why-sas-70-is-here-to-stay/</link>
		<comments>http://itknowledgeexchange.techtarget.com/compliance-governance/sas-70-type-ii-audit-reports-why-sas-70-is-here-to-stay/#comments</comments>
		<pubDate>Sun, 23 Nov 2008 19:46:09 +0000</pubDate>
		<dc:creator>Charles Denyer</dc:creator>
				<category><![CDATA[GLBA]]></category>
		<category><![CDATA[HIPAA]]></category>
		<category><![CDATA[regulatory compliance]]></category>
		<category><![CDATA[Sarbanes-Oxley]]></category>
		<category><![CDATA[SAS 70]]></category>
		<category><![CDATA[sas 70 audit report]]></category>
		<category><![CDATA[sas 70 control objectives]]></category>
		<category><![CDATA[sas 70 type ii]]></category>
		<category><![CDATA[sas70]]></category>
		<category><![CDATA[section 404 sox]]></category>
		<category><![CDATA[SOX]]></category>
		<category><![CDATA[What is SAS 70?]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/compliance-governance/sas-70-type-ii-audit-reports-why-sas-70-is-here-to-stay/</guid>
		<description><![CDATA[We live in a world of heightened regulatory compliance and corporate governance. From the passage of the 2002 Sarbanes-Oxley Act to numerous other pieces of legislation (HIPAA, GLBA, just to name a few), &#8220;comply, comply, comply&#8221; is the new mantra being pushed throughout organizations and at all levels. SAS 70 audits, originally introduced as the [...]]]></description>
				<content:encoded><![CDATA[<p>We live in a world of heightened regulatory compliance and corporate governance. From the passage of the 2002 Sarbanes-Oxley Act to numerous other pieces of legislation (HIPAA, GLBA, just to name a few), &#8220;comply, comply, comply&#8221; is the new mantra being pushed throughout organizations and at all levels. <strong><a href="http://www.sas70.us.com">SAS 70 audits</a></strong>, originally introduced as the 70th auditing standard in April of 1992, has stood the test of time as the main &#8220;go to&#8221; compliance audit for many of these regulatory requirements that have ushered from the halls of Congress.  </p>
<p>Okay, so, why is it here to stay? Well, for a number of reasons. First and foremost, it will always be used as an audit tool for evaluating service organization&#8217;s that could have a material impact to a company&#8217;s &#8220;information system&#8221;-This term, &#8220;information system&#8221; is used to describe the user organization&#8217;s &#8220;information system&#8221;, that is, what services are being performed by the service organization that are considered a part of the user organization&#8217;s &#8220;information system&#8221;. Transactions, procedures (be it manual or automated), supporting information, the capturing of events and conditions-are all considered traits and activities that relate to, have an effect, and impact the user organization&#8217;s &#8220;information system&#8221;.</p>
<p>Second, the SAS 70 auditing standard has been quite flexible, adapting to the needs of service organizations that must have their control environment examined.  Witness the numerous times the SAS 70 auditing standard has been amended over the last 16 years to keep &#8220;pace&#8221; with the changes of business.  </p>
<p>Third, the SAS 70 auditing standard has become very quickly recognized as the global de facto audit for internal controls on service organizations. In short, it has built up quite a following that is simply very hard to ignore.</p>
<p>To learn more about SAS 70 audits, visit the official <strong><a href="http://www.sas70.us.com">SAS 70 Resource Guide</a>.</strong></p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/compliance-governance/sas-70-type-ii-audit-reports-why-sas-70-is-here-to-stay/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SAS70 Reports &#124; Know the Difference Between Type I &amp; Type II</title>
		<link>http://itknowledgeexchange.techtarget.com/compliance-governance/sas70-reports-know-the-difference-between-type-i-type-ii/</link>
		<comments>http://itknowledgeexchange.techtarget.com/compliance-governance/sas70-reports-know-the-difference-between-type-i-type-ii/#comments</comments>
		<pubDate>Mon, 08 Sep 2008 16:04:13 +0000</pubDate>
		<dc:creator>Charles Denyer</dc:creator>
				<category><![CDATA[audits]]></category>
		<category><![CDATA[Compliance]]></category>
		<category><![CDATA[regulatory compliance]]></category>
		<category><![CDATA[Sarbanes-Oxley]]></category>
		<category><![CDATA[sas70]]></category>
		<category><![CDATA[sas70 sample reports]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/compliance-governance/sas70-reports-know-the-difference-between-type-i-type-ii/</guid>
		<description><![CDATA[If your company is needing to be SAS70 compliant, then a good start is to learn about what a SAS70 audit is and what the difference is between a SAS70 Type I &#38; SAS70 Type II audit report. In short, a SAS70 Type I is simply an audit that is a snapshot in time; an [...]]]></description>
				<content:encoded><![CDATA[<p>If your company is needing to be SAS70 compliant, then a good start is to learn about what a SAS70 audit is and what the difference is between a SAS70 Type I &amp; SAS70 Type II audit report.</p>
<p>In short, a <a href="http://www.sas70.us.com/services/sas70-typei-audit.php">SAS70 Type I</a> is simply an audit that is a snapshot in time; an audit for a particular day. For example, a Type I report would be given a date of August 31, 2008.  </p>
<p>A SAS70 Type II audit report is a report that will test the operating effectiveness of those controls over a time period, traditionally six (6) months. For example, a SAS70 Type II report would cover a period from January 1, 2008 to June 30, 2008.  </p>
<p>It is important to note that a SAS70 Type II is what the market is calling for, that is, it suffices for Sarbanes Oxley compliance and is looked upon as a much superior audit than a SAS70 Type I report.</p>
<p>A good example of learning more about SAS70 audits is to obtain a <a href="http://www.sas70.us.com/what-is/download-sample-sas70.php">SAS70 sample report,</a> whereby you can read and understand what the major components and parts are of a final report.</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/compliance-governance/sas70-reports-know-the-difference-between-type-i-type-ii/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SAS 70 &amp; Sarbanes Oxley (SOX) &#124;  What You Need to Know</title>
		<link>http://itknowledgeexchange.techtarget.com/compliance-governance/sas-70-sarbanes-oxley-sox-what-you-need-to-know/</link>
		<comments>http://itknowledgeexchange.techtarget.com/compliance-governance/sas-70-sarbanes-oxley-sox-what-you-need-to-know/#comments</comments>
		<pubDate>Tue, 26 Aug 2008 12:36:57 +0000</pubDate>
		<dc:creator>Charles Denyer</dc:creator>
				<category><![CDATA[regulatory compliance]]></category>
		<category><![CDATA[Sarbanes-Oxley]]></category>
		<category><![CDATA[SAS 70]]></category>
		<category><![CDATA[sas70]]></category>
		<category><![CDATA[sas70 sample reports]]></category>
		<category><![CDATA[section 404 sox]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/compliance-governance/sas-70-sarbanes-oxley-sox-what-you-need-to-know/</guid>
		<description><![CDATA[The relationship between Sarbanes-Oxley and SAS 70 begins with Section 404 of the 2002 Sarbanes Oxley Act (SOX). Because management must report annually on it’s effectiveness of internal controls, it then has a fiduciary responsibility and a requirement to inspect on controls considered critical to the organization as a whole, but more importantly, to it’s [...]]]></description>
				<content:encoded><![CDATA[<p>The relationship between Sarbanes-Oxley and SAS 70 begins with Section 404 of the 2002 Sarbanes Oxley Act (SOX). Because management must report annually on it’s effectiveness of internal controls, it then has a fiduciary responsibility and a requirement to inspect on controls considered critical to the organization as a whole, but more importantly, to it’s financial reporting process. Because a large number of publicly traded companies outsource a host of services, these outsourcing providers, known simply as &#8220;service organizations”, are considered an integral component for purposes of financial reporting. Therefore, a due-diligence process must be enacted to have their internal controls observed and certified. The Securities and Exchange Commission&#8217;s (SEC) Chief Accountant and the Division of Corporation Finance has stated that &#8220;In many situations, a registrant relies on a third party service provider to perform certain functions where the outsourced activity affects the initiation, authorization, recording, processing or reporting of transactions in the registrant&#8217;s financial statement. In assessing internal controls over financial reporting, management may rely on a Type 2 SAS 70 report.&#8221;  What&#8217;s just as important is that this relationship between SAS 70 and Section 404 of the SOX Act has kicked off a regulatory compliance push that quite frankly, there is no end in sight.</p>
<p>To learn more about SAS 70 audit or to <a href="http://www.sas70.us.com/what-is/download-sample-sas70.php">receive a sample SAS 70 Type II report</a>, visit the official <a href="http://www.sas70.us.com">SAS 70 Resource Guide</a>.</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/compliance-governance/sas-70-sarbanes-oxley-sox-what-you-need-to-know/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SAS 70 Audits &#124; Tips on Preparing Your Organization</title>
		<link>http://itknowledgeexchange.techtarget.com/compliance-governance/sas-70-audits-tips-on-preparing-your-organization/</link>
		<comments>http://itknowledgeexchange.techtarget.com/compliance-governance/sas-70-audits-tips-on-preparing-your-organization/#comments</comments>
		<pubDate>Tue, 26 Aug 2008 11:23:32 +0000</pubDate>
		<dc:creator>Charles Denyer</dc:creator>
				<category><![CDATA[regulatory compliance]]></category>
		<category><![CDATA[Sarbanes-Oxley]]></category>
		<category><![CDATA[SAS 70]]></category>
		<category><![CDATA[SAS 70 download]]></category>
		<category><![CDATA[SAS 70 readiness questionnaire]]></category>
		<category><![CDATA[sas70]]></category>
		<category><![CDATA[sas70 sample reports]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/compliance-governance/sas-70-audits-tips-on-preparing-your-organization/</guid>
		<description><![CDATA[SAS 70 audits are being performed on many service organizations in today&#8217;s growing regulatory compliance economy. From federal legislation, such as Sarbanes-Oxley to HIPAA, the SAS 70 auditing standard has been pushed to the forefront of the business arena. It&#8217;s becoming such a big requirement now that many request for proposals (RFP) are demanding that [...]]]></description>
				<content:encoded><![CDATA[<p>SAS 70 audits are being performed on many service organizations in today&#8217;s growing regulatory compliance economy. From federal legislation, such as <a href="http://www.sas70.us.com/white-papers/sox-and-sas70.php">Sarbanes-Oxley</a> to HIPAA, the SAS 70 auditing standard has been pushed to the forefront of the business arena. It&#8217;s becoming such a big requirement now that many request for proposals (RFP) are demanding that a service organization be SAS 70 compliant for even bidding on work or submitting a proposal.</p>
<p>So let&#8217;s erase some myths and misconceptions about the SAS 70 auditing standard. First and foremost, the audit can be done in an efficient, cost effective manner, provided you find a firm that has a good working knowledge of the SAS 70 auditing standard AND your industry. Put both of those variables together, and you should get a good fee from a quality auditor who truly knows what they are doing.</p>
<p>Secondly, you don&#8217;t have to do a SAS 70 Type I first if you need a SAS 70 Type II. Why waste thousands of dollars on a Type I when it&#8217;s not really what you needed?  Some CPA firms will try and sell you the full package, often including a Type I by stating its needed to begin the audit process. What you need to start with instead is a SAS 70 Readiness Assessment, which will get your organization up to speed and ready for the actual SAS 70 Type II audit.</p>
<p>Lastly, SAS 70 audits can be a reasonable financial proposition, if you use a firm with experience that has a working, scalable model, resulting in efficiency and cost-effectiveness. </p>
<p>If you want to learn more about SAS 70 audits, visit the <a href="http://www.sas70.us.com">official SAS 70 resource center</a> where you can receive <a href="http://www.sas70.us.com/what-is/download-sample-sas70.php">SAS 70 sample reports</a> for review.</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/compliance-governance/sas-70-audits-tips-on-preparing-your-organization/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SAS70 &amp; PCI Compliance &#124; Creating Audit Efficiencies</title>
		<link>http://itknowledgeexchange.techtarget.com/compliance-governance/sas70-pci-compliance-creating-audit-efficiencies/</link>
		<comments>http://itknowledgeexchange.techtarget.com/compliance-governance/sas70-pci-compliance-creating-audit-efficiencies/#comments</comments>
		<pubDate>Sun, 03 Aug 2008 14:49:44 +0000</pubDate>
		<dc:creator>Charles Denyer</dc:creator>
				<category><![CDATA[Auditing]]></category>
		<category><![CDATA[audits]]></category>
		<category><![CDATA[Compliance]]></category>
		<category><![CDATA[GLBA]]></category>
		<category><![CDATA[HIPAA]]></category>
		<category><![CDATA[payment card industry]]></category>
		<category><![CDATA[PCI]]></category>
		<category><![CDATA[qsa]]></category>
		<category><![CDATA[regulatory compliance]]></category>
		<category><![CDATA[Sarbanes-Oxley]]></category>
		<category><![CDATA[SAS 70]]></category>
		<category><![CDATA[sas70]]></category>
		<category><![CDATA[sas70 sample reports]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/compliance-governance/sas70-pci-compliance-creating-audit-efficiencies/</guid>
		<description><![CDATA[SAS70 audits have grown tremendously in the past five years, largely due in part to the explosive growth of federal regulatory compliance laws and legislation. Interestingly also, Payment Card Industry (PCI) compliance has also received much attention as of recent, particularly with the recent breaches of security in a number of well publicized cases. I&#8217;m [...]]]></description>
				<content:encoded><![CDATA[<p><strong><a href="http://www.sas70.us.com">SAS70 audits</a></strong> have grown tremendously in the past five years, largely due in part to the explosive growth of federal regulatory compliance laws and legislation.  Interestingly also, Payment Card Industry (PCI) compliance has also received much attention as of recent, particularly with the recent breaches of security in a number of well publicized cases.</p>
<p>I&#8217;m often asked by organizations that have to be SAS70 &amp; PCI compliant if these two audits can be a 2 for 1, that is, can I conduct SAS70 fieldwork and also hopefully piggyback off of that work to help augment a marginal part of the PCI compliance examination for QSA?  </p>
<p>There are synergies that can be created, allowing an experienced auditor to use his or her best judgment for creating these synergies.  If you look at the 12 core areas of the PCI compliance, you can extract elements from these very requirements that would most surely be included in a good, quality comprehensive SAS70 audit. I stress &#8220;good, quality&#8221; audit because the looseness of the SAS70 standard allows auditors to employ vastly different methodologies. </p>
<p>For example, PCI Requirement #9, &#8220;Restricting Physical Access to Cardholder Data&#8221; could be argued that this is very much in line with a common SAS70 control objective for &#8220;Physical Security&#8221;.  Remember this, there are only so many regulatory compliance and governance laws that can be pushed forward before they start to become overlapping and redundant to a certain degree.</p>
<p>If you can find a quality firm that does both SAS70 auditing and PCI QSA compliance, then it would be most beneficial to create these synergies for the audit. </p>
<p>One of the most valuable tools I recently created was a SAS70 &amp; PCI Gap analysis, showing you the overlapping features of both audits, allowing any firm to create these very efficiencies for these compliance examinations.</p>
<p>For more information on SAS70 audits, or to receive <strong><a href="http://www.sas70.us.com/what-is/download-sample-sas70.php">SAS70 sample reports</a></strong>, please visit the official <strong><a href="http://www.sas70.us.com/what-is/what-is-sas70.php">SAS70 resource center</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/compliance-governance/sas70-pci-compliance-creating-audit-efficiencies/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Data Centers &amp; SAS70 Audits &#124; How to Prepare for the Audit</title>
		<link>http://itknowledgeexchange.techtarget.com/compliance-governance/data-centers-sas70-audits-how-to-prepare-for-the-audit/</link>
		<comments>http://itknowledgeexchange.techtarget.com/compliance-governance/data-centers-sas70-audits-how-to-prepare-for-the-audit/#comments</comments>
		<pubDate>Fri, 25 Jul 2008 15:00:10 +0000</pubDate>
		<dc:creator>Charles Denyer</dc:creator>
				<category><![CDATA[Auditing]]></category>
		<category><![CDATA[Compliance]]></category>
		<category><![CDATA[Sarbanes-Oxley]]></category>
		<category><![CDATA[SAS 70]]></category>
		<category><![CDATA[SAS 70 download]]></category>
		<category><![CDATA[What is SAS 70?]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/compliance-governance/data-centers-sas70-audits-how-to-prepare-for-the-audit/</guid>
		<description><![CDATA[Data centers are increasingly being called upon to be SAS70 Type I or Type II compliant. It stems primarily from the rapid growth of compliance legislation, along with the advent of many industries, particularly Software as a Service (SaaS), that require services from data centers and co-location entities. Moreover, today&#8217;s data centers provide a wide [...]]]></description>
				<content:encoded><![CDATA[<p>Data centers are increasingly being called upon to be SAS70 Type I or Type II compliant. It stems primarily from the rapid growth of compliance legislation, along with the advent of many industries, particularly Software as a Service (SaaS), that require services from data centers and co-location entities.  Moreover, today&#8217;s data centers provide a wide array of services, and as such, client using these very services often have to adhere to regulatory compliance mandates also. Ultimately, this has a downstream effect that places data centers on the compliance radar, with SAS70 audits commonly being the default compliance tool used for evaluating their internal control structure.</p>
<p>Additionally, because no two SAS70 audits are truly identical, and because a SAS70 audit should be customized to reflect specific industry needs, it&#8217;s important to note what is considered as an acceptable baseline scope for SAS70 audits on data centers.  Thus, the areas of executive tone, human resources, incident management, change management, logical security, network security, physical security, environmental security, and computer operations form the basis of the audit for purposes of scope.  Please keep in mind, this a generally accepted scope, which can increase or decrease based primarily on what is driving the requirements for the audit itself.</p>
<p>To gain a greater understanding of your organization&#8217;s SAS70 needs, it would be helpful for you to learn about <strong><a href="http://www.sas70.us.com/what-is/what-is-sas70.php">what SAS70 is</a></strong> and also <strong><a href="http://www.sas70.us.com/what-is/download-sample-sas70.php">obtaining SAS70 sample reports</a></strong>, which are an excellent tool for learning more about this type of audit.</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/compliance-governance/data-centers-sas70-audits-how-to-prepare-for-the-audit/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
