 




<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Regulatory Compliance, Governance and Security &#187; sas70</title>
	<atom:link href="http://itknowledgeexchange.techtarget.com/compliance-governance/tag/sas70/feed/" rel="self" type="application/rss+xml" />
	<link>http://itknowledgeexchange.techtarget.com/compliance-governance</link>
	<description></description>
	<lastBuildDate>Thu, 10 Mar 2011 15:04:50 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	
		<item>
		<title>GLBA, HIPAA, SAS 70, PCI DSS &#124; what is next for Compliance?</title>
		<link>http://itknowledgeexchange.techtarget.com/compliance-governance/glba-hipaa-sas-70-pci-dss-what-is-next-for-compliance/</link>
		<comments>http://itknowledgeexchange.techtarget.com/compliance-governance/glba-hipaa-sas-70-pci-dss-what-is-next-for-compliance/#comments</comments>
		<pubDate>Sun, 23 Aug 2009 16:39:46 +0000</pubDate>
		<dc:creator>Charles Denyer</dc:creator>
				<category><![CDATA[charles denyer]]></category>
		<category><![CDATA[GLBA]]></category>
		<category><![CDATA[HIPAA]]></category>
		<category><![CDATA[payment card industry data security standards]]></category>
		<category><![CDATA[PCI DSS]]></category>
		<category><![CDATA[SAS 70]]></category>
		<category><![CDATA[sas70]]></category>
		<category><![CDATA[The Minnesota Plastic Card Security Act]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/compliance-governance/glba-hipaa-sas-70-pci-dss-what-is-next-for-compliance/</guid>
		<description><![CDATA[The trend of late has been Payment Card Industry (PCI) Data Security Standards (DSS) compliance, along with a continued emphasis on the well known SAS 70 auditing standard. And occasionally, calls for GLBA and HIPAA compliance come calling also. As an auditor for many years, I’m often asked to look into the crystal ball of [...]]]></description>
				<content:encoded><![CDATA[<p>The trend of late has been <a href="http://www.pciassessment.org">Payment Card Industry (PCI) Data Security Standards (DSS)</a> compliance, along with a continued emphasis on the well known SAS 70 auditing standard. And occasionally, calls for GLBA and HIPAA compliance come calling also.  As an auditor for many years, I’m often asked to look into the crystal ball of compliance and give my prescient thoughts and answers.  </p>
<p>First and foremost, the requirements for <a href="http://www.sas70.us.com">SAS 70</a> Type II audit and PCI DSS assessment compliance will continue to grow larger; larger in scope regarding the actual requirements and larger in the number of companies having to comply.  Data breaches are occurring at a feverish pace, causing great unrest for all participants involved.  And add to the notion of the continued importance of corporate governance, regulatory compliance and security, and it becomes quite evident that SAS 70 and PCI will play a critical role for many years.    </p>
<p>Additionally, more and more states will start to adopt various provisions of the PCI DSS requirements, turning them into an actual codification of laws for their respective states. Minnesota became that first state with the MN Plastic Card Security Act, followed by Nevada and a host of other states who are seriously looking to an adoption of PCI into law.</p>
<p>As for GLBA and HIPAA, they will more than likely continue to “limp” along as they simply lack the regulatory “teeth” that <a href="http://www.sas70.us.com">SAS 70</a> and PCI have.  This may change if the SEC and The Department of Health and Human Services give HIPAA and GLBA more explicit requirements on compliance, but this is highly doubtful.  </p>
<p>If you want to learn more about compliance, visit the <a href="http://www.sas70.us.com">SAS 70 Resource Guide</a> and the <a href="http://www.pciassessment.org">PCI DSS Resource Guide</a>.</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/compliance-governance/glba-hipaa-sas-70-pci-dss-what-is-next-for-compliance/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SAS 70 Audits and PCI DSS Assessments &#124; What you NEED to Know</title>
		<link>http://itknowledgeexchange.techtarget.com/compliance-governance/sas-70-audits-and-pci-dss-assessments-what-you-need-to-know/</link>
		<comments>http://itknowledgeexchange.techtarget.com/compliance-governance/sas-70-audits-and-pci-dss-assessments-what-you-need-to-know/#comments</comments>
		<pubDate>Mon, 03 Aug 2009 19:25:01 +0000</pubDate>
		<dc:creator>Charles Denyer</dc:creator>
				<category><![CDATA[merchants]]></category>
		<category><![CDATA[payment card industry data security standards]]></category>
		<category><![CDATA[PCI DSS]]></category>
		<category><![CDATA[pci dsss level 1 assessments]]></category>
		<category><![CDATA[SAS 70]]></category>
		<category><![CDATA[sas70]]></category>
		<category><![CDATA[service organizations]]></category>
		<category><![CDATA[service providers]]></category>
		<category><![CDATA[type i]]></category>
		<category><![CDATA[type II]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/compliance-governance/sas-70-audits-and-pci-dss-assessments-what-you-need-to-know/</guid>
		<description><![CDATA[SAS 70 audits and PCI DSS Assessments are on everybody&#8217;s radar screen today, or though it seems. Particularly, SAS 70 Type II Audits and Payment Card Industry Data Security Standards (PCI DSS) Level I assessments. And why? Because many service organizations, merchants, and service providers are being asked to become compliant with either a SAS [...]]]></description>
				<content:encoded><![CDATA[<p>SAS 70 audits and PCI DSS Assessments are on everybody&#8217;s radar screen today, or though it seems. Particularly, SAS 70 Type II Audits and Payment Card Industry Data Security Standards (PCI DSS) Level I assessments. </p>
<p>And why? Because many service organizations, merchants, and service providers are being asked to become compliant with either a SAS 70 audit, a PCI DSS Assessment or both, for purposes of today&#8217;s regulatory compliance initiatives. Take note, Nevada just passed provisions of PCI into law, joining Minnesota as another state that is taking security and privacy to a new level.</p>
<p>I&#8217;ve put together a comprehensive white paper on <strong><a href="http://www.sas70.us.com/industries/organizationsthatneed.php">SAS 70 Type II audits and PCI DSS Level 1 assessments</a></strong> that is definitely good reading material if your organization has to become compliant with either of these.  </p>
<p>Visit the official <strong><a href="http://www.sas70.us.com">SAS 70 Resource Guide</a></strong> to learn more about Type I and Type II audits<br />
Visit the official <strong><a href="http://www.pciassessment.org">PCI DSS Resource Guide</a></strong> to learn more about PCI DSS Assessments.</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/compliance-governance/sas-70-audits-and-pci-dss-assessments-what-you-need-to-know/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Sample SAS 70 Type II Audit Report &#124; Learn about SAS 70 Audits</title>
		<link>http://itknowledgeexchange.techtarget.com/compliance-governance/sample-sas-70-type-ii-audit-report-learn-about-sas-70-audits/</link>
		<comments>http://itknowledgeexchange.techtarget.com/compliance-governance/sample-sas-70-type-ii-audit-report-learn-about-sas-70-audits/#comments</comments>
		<pubDate>Mon, 06 Jul 2009 15:20:57 +0000</pubDate>
		<dc:creator>Charles Denyer</dc:creator>
				<category><![CDATA[charles denyer]]></category>
		<category><![CDATA[cpa]]></category>
		<category><![CDATA[pdf]]></category>
		<category><![CDATA[sas 70 example report]]></category>
		<category><![CDATA[sas 70 sample report]]></category>
		<category><![CDATA[sas 70 type ii audit report]]></category>
		<category><![CDATA[sas70]]></category>
		<category><![CDATA[statment on auditing standards no. 70]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/compliance-governance/sample-sas-70-type-ii-audit-report-learn-about-sas-70-audits/</guid>
		<description><![CDATA[Obtaining a Sample SAS 70 Type II Audit Report is simply the best way for service organizations to learn about Statement on Auditing Standards No. 70. This can be a highly complex audit process, with much of it open to an auditor&#8217;s and service organization&#8217;s overall interpretation of man key points in the audit process. [...]]]></description>
				<content:encoded><![CDATA[<p><strong><a href="http://www.scribd.com/doc/17068540/Sample-SAS-70-Type-II-Audit-Report">Obtaining a Sample SAS 70 Type II Audit Report</a></strong> is simply the best way for service organizations to learn about Statement on Auditing Standards No. 70.  This can be a highly complex audit process, with much of it open to an auditor&#8217;s and service organization&#8217;s overall interpretation of man key points in the audit process.</p>
<p>Service organizations of all shapes and size today (data center, co-locations, software as a service, third party administrators, medical claims processors, etc.) are all being called upon to become SAS 70 Type II compliant. The regulatory drumbeat is beating louder every year and SAS 70 audits are here to stay. </p>
<p>A sample SAS 70 Type II audit report will give service organizations a fresh and unique perspective on exactly what the finished product of a SAS 70 Type II audit looks like. Look at it as  a way to truly understand the end product and what the CPA firm conducting the audit will be furnishing you with. </p>
<p>Please keep in mind because of the looseness and the flexibility of the SAS 70 auditing standard, not every report will be identical in.  However, there are, without question, common themes and subject matter that every quality report will include. The report can be downloaded via pdf</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/compliance-governance/sample-sas-70-type-ii-audit-report-learn-about-sas-70-audits/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SAS 70</title>
		<link>http://itknowledgeexchange.techtarget.com/compliance-governance/sas-70/</link>
		<comments>http://itknowledgeexchange.techtarget.com/compliance-governance/sas-70/#comments</comments>
		<pubDate>Sat, 20 Jun 2009 03:20:18 +0000</pubDate>
		<dc:creator>Charles Denyer</dc:creator>
				<category><![CDATA[charles denyer]]></category>
		<category><![CDATA[control environment]]></category>
		<category><![CDATA[general controls report]]></category>
		<category><![CDATA[sarbanes oxley act of 2002]]></category>
		<category><![CDATA[SAS 70 Type I]]></category>
		<category><![CDATA[sas70]]></category>
		<category><![CDATA[Statement on Auditing Standards No. 70]]></category>
		<category><![CDATA[type II]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/compliance-governance/sas-70/</guid>
		<description><![CDATA[Statement on Auditing Standards No. 70, simply known as SAS 70 to many, has had a profound impact on regulatory compliance since the passage of the Sarbanes Oxley Act in 2002. As a SAS 70 auditor for many years, i&#8217;ve been asked a broad and wide range of questions regarding the who, what, where, when [...]]]></description>
				<content:encoded><![CDATA[<p><a href="http://www.sas70.us.com">Statement on Auditing Standards No. 70</a>, simply known as SAS 70 to many, has had a profound impact on regulatory compliance since the passage of the Sarbanes Oxley Act in 2002.  As a SAS 70 auditor for many years, i&#8217;ve been asked a broad and wide range of questions regarding the who, what, where, when and why of SAS 70 Type I and SAS 70 Type II audits.  Thus, if you need to learn everything you possibly can about SAS 70, then visit the official <a href="http://www.sas70.us.com">SAS 70 Resource Guide</a>, where a voluminous amount of information is available.</p>
<p>Now, with that said, let me touch on a subject that has been brought up so many times it feels like a broken record: <strong>SAS 70 PRICING</strong>.  So, what do they cost? What SHOULD they cost?  These are some of the questions i fielded over the years.  With that said, i can tell you what my honest best assessment is for pricing on these engagements, so here you go.</p>
<p>A general controls SAS 70 Type I that covers no real business processes and all fieldwork can be done at one location should be between $15,000 and $25,000.</p>
<p>A general controls SAS 70 Type II that covers no real business processes and all fieldwork can be done at one location should be between $25,000 and $35,000. Thus, subsequent years &#8220;could&#8221; see a decrease in fees (marginal, that is) if the control environment stays somewhat static.</p>
<p>If you start adding in requirements to test a wide array of specific &#8220;business process&#8221; controls, the price will go up. Keep in mind, some firms may charge (and do) a slightly cheaper fee than i&#8217;ve just quoted.  But remember, you get what you pay for, especially for auditors.  Find that healthy medium from a quality, boutique CPA firm that specializes in SAS 70 audits and you should be fine.</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/compliance-governance/sas-70/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>PCI DSS and SAS 70 Audits &#124; Audit Efficiencies? Maybe&#8230;just Maybe</title>
		<link>http://itknowledgeexchange.techtarget.com/compliance-governance/pci-dss-and-sas-70-audits-audit-efficiencies-maybejust-maybe/</link>
		<comments>http://itknowledgeexchange.techtarget.com/compliance-governance/pci-dss-and-sas-70-audits-audit-efficiencies-maybejust-maybe/#comments</comments>
		<pubDate>Wed, 18 Feb 2009 19:53:46 +0000</pubDate>
		<dc:creator>Charles Denyer</dc:creator>
				<category><![CDATA[payment card industry data security standards (PCI DSS)]]></category>
		<category><![CDATA[PCI DSS]]></category>
		<category><![CDATA[pci dss assessments]]></category>
		<category><![CDATA[qsa]]></category>
		<category><![CDATA[SAS 70]]></category>
		<category><![CDATA[sas 70 audits]]></category>
		<category><![CDATA[sas70]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/compliance-governance/?p=116</guid>
		<description><![CDATA[As a SAS 70 auditor and a PCI QSA, i&#8217;m often asked about the efficiencies of scale that can be achieved with SAS 70 audits and PCI DSS assessments. I have blogged about this a few times before, so let me be more clear and transparent in what i believe can actually be obtained in [...]]]></description>
				<content:encoded><![CDATA[<p>As a SAS 70 auditor and a PCI QSA, i&#8217;m often asked about the efficiencies of scale that can be achieved with SAS 70 audits and PCI DSS assessments. I have blogged about this a few times before, so let me be more clear and transparent in what i believe can actually be obtained in regards to audit efficiencies when conducting a SAS 70 and a PCI DSS assessment on an entity.</p>
<p>First and foremost, as an auditor, there should still be independence within the SAS 70 audit and the PCI DSS assessment. Independence how? Simple, do not treat them as one audit, because they are simply not that. Technically speaking, a PCI assessment is just that, an assessment, not an audit, which requires &#8220;attestation&#8221;.  Moreover, there are significant differences between the audit and the assessment, which can be discussed at length (and will be) in a whole different blog.  </p>
<p>I stress in the title of this blog that &#8220;maybe&#8221; there can be audit efficiencies, however, it many times is dependent on the quality of the auditors, their expertise in both conducting a PCI and a SAS 70 audit, and how much they are willing to rely on evidence from the PCI DSS assessment for the SAS 70 audit, and vice versa. Good auditors will find ways to create these efficiencies; other auditors might want to conduct a PCI DSS assessment and rubber stamp a SAS 70-this is a BIG NO NO.  </p>
<p>Want to learn more about where these efficiencies of scale can be maximized?  To learn more about SAS 70 audits, visit the official <a href="http://www.sas70.us.com">SAS 70 Resource Guide</a> and to learn more about PCI DSS Assessments, visit the <a href="http://www.pciassessment.org">PCI Resource Guide</a>. </p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/compliance-governance/pci-dss-and-sas-70-audits-audit-efficiencies-maybejust-maybe/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SAS 70 Audit Guide &#124; Learn the Secrets to SAS 70 Audits</title>
		<link>http://itknowledgeexchange.techtarget.com/compliance-governance/sas-70-audit-guide-learn-the-secrets-to-sas-70-audits/</link>
		<comments>http://itknowledgeexchange.techtarget.com/compliance-governance/sas-70-audit-guide-learn-the-secrets-to-sas-70-audits/#comments</comments>
		<pubDate>Sun, 08 Feb 2009 14:59:19 +0000</pubDate>
		<dc:creator>Charles Denyer</dc:creator>
				<category><![CDATA[sas 70 audit guide]]></category>
		<category><![CDATA[sas 70 scoping and pricing]]></category>
		<category><![CDATA[SAS 70 Type I]]></category>
		<category><![CDATA[sas70]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/compliance-governance/?p=104</guid>
		<description><![CDATA[Learn more about SAS 70 audits from the Official SAS 70 Resource Guide]]></description>
				<content:encoded><![CDATA[<p>Need to learn about <strong><a href="http://www.sas70.us.com">SAS 70 audits</a></strong>? Not too sure about what the audit actually entails in regards to scope, time, effort and financial considerations? Well, if your organization is seeking to become SAS 70 Type I or Type II compliant for 2009 and beyond, then its a good idea to start educating yourself on the particulars of SAS 70 audits. The more informed and educated you are, the greater your success in going through a SAS 70 audit for your organization in a timely, efficient, and cost-effective manner.</p>
<p>Helpful suggestions on learning about SAS 70 audits include the following:</p>
<p>Know the difference between a Type I and Type II audit<br />
Learn about pricing for SAS 70 audits<br />
Understand and comprehend the meaning of audit &#8220;scope&#8221;<br />
Learn about a SAS 70 Readiness Assessment and how it can help augment the overall audit process for Type I and Type II reports. </p>
<p>Keep in mind that all organizations are different, as such, your SAS 70 requirements and what you essentially need to &#8220;get out&#8221; of your report could be significantly different from another company. For example, are you just looking to &#8220;check the box&#8221; for a compliance report or are you actually seeking value out of your SAS 70 audit. </p>
<p><strong><a href="http://www.sas70.us.com">Visit the official SAS 70 Resource Guide</a></strong> to learn more about SAS 70 Type I and Type II audits. </p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/compliance-governance/sas-70-audit-guide-learn-the-secrets-to-sas-70-audits/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Payment Card Compliance &#124; PCI DSS &#124; Tips on Passing your PCI DSS Assessment</title>
		<link>http://itknowledgeexchange.techtarget.com/compliance-governance/payment-card-compliance-pci-dss-tips-on-passing-your-pci-dss-assessment/</link>
		<comments>http://itknowledgeexchange.techtarget.com/compliance-governance/payment-card-compliance-pci-dss-tips-on-passing-your-pci-dss-assessment/#comments</comments>
		<pubDate>Sat, 17 Jan 2009 20:00:22 +0000</pubDate>
		<dc:creator>Charles Denyer</dc:creator>
				<category><![CDATA[change mangement for pci dss]]></category>
		<category><![CDATA[payment card industry data security standards]]></category>
		<category><![CDATA[pci compliance]]></category>
		<category><![CDATA[PCI DSS]]></category>
		<category><![CDATA[sas 70 audits]]></category>
		<category><![CDATA[sas70]]></category>
		<category><![CDATA[two-factor authentication for pci dss]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/compliance-governance/?p=86</guid>
		<description><![CDATA[Regarding PCI DSS, as a PCI QSA i&#8217;m often asked what&#8217;s the most difficult hurdle that organizations need to overcome for ensuring PCI DSS compliance. Well, we could talk at length about some of the technical, I.T. challenges, such as two-factor authentication, encryption (though not required.lol!). But in all seriousness, organizations are very deficient on [...]]]></description>
				<content:encoded><![CDATA[<p>Regarding PCI DSS, as a PCI QSA i&#8217;m often asked what&#8217;s the most difficult hurdle  that organizations need to overcome for ensuring PCI DSS compliance. Well, we could talk at length about some of the technical, I.T. challenges, such as two-factor authentication, encryption (though not required.lol!). But in all seriousness, organizations are very deficient on having documented policies and procedures in place for their critical infrastructure. From change management to tape/media backup and recovery procedures, many organizations fail to have these very policies and procedures documented in an organizational wide corporate security document, or something of a similar nature, such as online WIKI.  </p>
<p>So, why is this such a repetitive and persistent problem for companies? For the most part, it has to do with the lack of expertise in writing these documented policies and procedures along with finding the time to do them. They can be painstakingly slow and arduous to complete. The solution; hire a firm that have experience and expertise in developing and <strong><a href="http://pciassessment.org">writing policies and procedures for PCI DSS </a></strong>and for any other regulatory compliance mandate your company may encounter, such as <strong><a href="http://www.sas70.us.com">SAS 70 audits</a></strong>. </p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/compliance-governance/payment-card-compliance-pci-dss-tips-on-passing-your-pci-dss-assessment/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SAS 70 Audits &amp; Data Centers &#124; Tips on Preparing for the Audit</title>
		<link>http://itknowledgeexchange.techtarget.com/compliance-governance/sas-70-audits-data-centers-tips-on-preparing-for-the-audit/</link>
		<comments>http://itknowledgeexchange.techtarget.com/compliance-governance/sas-70-audits-data-centers-tips-on-preparing-for-the-audit/#comments</comments>
		<pubDate>Fri, 16 Jan 2009 15:46:54 +0000</pubDate>
		<dc:creator>Charles Denyer</dc:creator>
				<category><![CDATA[change management sas 70]]></category>
		<category><![CDATA[co-locations]]></category>
		<category><![CDATA[environmental security]]></category>
		<category><![CDATA[incident management]]></category>
		<category><![CDATA[incident management sas 70]]></category>
		<category><![CDATA[managed services sas 70]]></category>
		<category><![CDATA[payment card industry]]></category>
		<category><![CDATA[PCI]]></category>
		<category><![CDATA[PCI DSS]]></category>
		<category><![CDATA[physical security]]></category>
		<category><![CDATA[SAS 70]]></category>
		<category><![CDATA[sas 70 data centers]]></category>
		<category><![CDATA[sas70]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/compliance-governance/?p=31</guid>
		<description><![CDATA[Today&#8217;s data centers and managed services providers are complex businesses, providing customers with a wide array of services. As such, SAS 70 audits have become the standard compliance audit for assessing internal controls for data centers and managed services. But buyer beware, not all SAS 70 audits are the same when being conducted on data [...]]]></description>
				<content:encoded><![CDATA[<p>Today&#8217;s data centers and managed services providers are complex businesses, providing customers with a wide array of services.  As such, <a href="http://www.sas70.us.com">SAS 70 audits</a> have become the standard compliance audit for assessing internal controls for data centers and managed services.  But buyer beware, not all SAS 70 audits are the same when being conducted on data centers and managed service providers. So, what&#8217;s the scope, you say? Well, generally speaking a good quality SAS 70 audit process and its subsequent report should include the following areas for considerations of controls:</p>
<p>1. Executive Management/Strategic Management Drivers<br />
2. Human Resources<br />
3. Quality Assurance Activities<br />
3. Client Contract Processes<br />
4. Technical Client Provisioning Processes and Activities<br />
5. Change Management<br />
6. Incident Management<br />
7. Logical Security<br />
8. Network Security<br />
9. Shipping and Receiving Management<br />
10. Physical Security<br />
11. Environmental Security</p>
<p>Any SAS 70 conducted on data centers, managed services providers and co-locations entities that encompass the following above referenced areas can be considered a quality audit and report, at least in terms of scope. It&#8217;s then up to the CPA firm conducting the audit to actually perform testing for these above referenced areas, but that&#8217;s a whole other topic of discussion for a later date.</p>
<p>To learn more about SAS 70 audits, visit the official <a href="http://www.sas70.us.com">SAS 70 Resource Guide</a>.<br />
To learn more about PCI DSS assessments, visit the <a href="http://www.pciassessment.org">Payment Card Industry (PCI) Resource Guide</a>.</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/compliance-governance/sas-70-audits-data-centers-tips-on-preparing-for-the-audit/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SAS 70 Audit Reports &#124; Learn About SAS 70 by Obtaining a Sample Report</title>
		<link>http://itknowledgeexchange.techtarget.com/compliance-governance/sas-70-audit-reports-learn-about-sas-70-by-obtaining-a-sample-report/</link>
		<comments>http://itknowledgeexchange.techtarget.com/compliance-governance/sas-70-audit-reports-learn-about-sas-70-by-obtaining-a-sample-report/#comments</comments>
		<pubDate>Wed, 31 Dec 2008 23:36:14 +0000</pubDate>
		<dc:creator>Charles Denyer</dc:creator>
				<category><![CDATA[SAS 70]]></category>
		<category><![CDATA[SAS 70 Type I]]></category>
		<category><![CDATA[sas70]]></category>
		<category><![CDATA[type ii audit]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/compliance-governance/?p=77</guid>
		<description><![CDATA[Many service organizations who have to undergo a SAS 70 Type I or Type II audit have never had the ability to see or read what a final report looks like after the audit has been completed. With this now available, service organizations can gain a greater understanding of the auditing standard, while also having [...]]]></description>
				<content:encoded><![CDATA[<p>Many service organizations who have to undergo a <strong><a href="http://www.sas70.us.com">SAS 70 Type I or Type II</a></strong> audit have never had the ability to see or read what a final report looks like after the audit has been completed. With this now available, service organizations can gain a greater understanding of the auditing standard, while also having an expectation of what the final report should look and “feel” like.</p>
<p>It’s one of the elements that was missing in the compliance industry, so we thought it was necessary and helpful to put forth an excellent example of a SAS 70 Type II service auditor’s report. And remember, because of the looseness within the auditing standard, no two reports are going to look exactly alike. Sure, there are slightly different variations of SAS 70 reports, but they should encompass and include most of the elements contained within our sample sas 70 available to all who wish to read on and learn more about statement on auditing standards no. 70.</p>
<p>Please take time to educate yourself on this highly used auditing standard by visiting a number of other areas on the website, such as the white papers section, industry news section, along with the <strong><a href="http://www.sas70.us.com/what-is/what-is-sas70.php">what is sas 70 section</a>.<br />
</strong></p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/compliance-governance/sas-70-audit-reports-learn-about-sas-70-by-obtaining-a-sample-report/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SAS 70 Audits &#124; Understanding PRICING for SAS 70 Engagements</title>
		<link>http://itknowledgeexchange.techtarget.com/compliance-governance/sas-70-audits-understanding-pricing-for-sas-70-engagements/</link>
		<comments>http://itknowledgeexchange.techtarget.com/compliance-governance/sas-70-audits-understanding-pricing-for-sas-70-engagements/#comments</comments>
		<pubDate>Wed, 31 Dec 2008 23:30:00 +0000</pubDate>
		<dc:creator>Charles Denyer</dc:creator>
				<category><![CDATA[cpa firm]]></category>
		<category><![CDATA[Sarbanes-Oxley]]></category>
		<category><![CDATA[sas 70 audit]]></category>
		<category><![CDATA[sas 70 type i type ii]]></category>
		<category><![CDATA[sas70]]></category>
		<category><![CDATA[SOX]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/compliance-governance/?p=73</guid>
		<description><![CDATA[SAS 70 Type I and Type II audits have become common for many organizations providing critical outsourcing services to companies. Known as service organizations, they have all landed on the regulatory radar of having to be SAS 70 compliant, due in large part because of Sarbanes Oxley (SOX) or any other large number of federal [...]]]></description>
				<content:encoded><![CDATA[<p><strong><a href="http://www.sas70.us.com">SAS 70 </a></strong>Type I and Type II audits have become common for many organizations providing critical outsourcing services to companies. Known as service organizations, they have all landed on the regulatory radar of having to be SAS 70 compliant, due in large part because of Sarbanes Oxley (SOX) or any other large number of federal regulatory compliance mandates.. I’m often asked how much does a SAS 70 Type I or Type II audit cost. Well, that depends on a number of factors and circumstances that will be discussed today.</p>
<p>Issue #1: Choosing a Firm for the SAS 70 Audit</p>
<p>There are a number of providers available for SAS 70 audits, ranging from regional CPA firms to the nationally recognized big four firms. And as with anything in life, most organizations try to find the most value for their money, but remember, you get what you pay for. Small firms may be cost-effective, but they may lack the expertise and name recognition of other firms. The big four accounting firms will charge you a heavy premium audit fee, yet you get their name on the report, ultimately giving it a high level of recognition, simply based on who they are.</p>
<p>Remember, SAS 70 Type I and Type II audit prices have a wide range, so it’s probably a wise choice to pick in between, that is, a firm who is specialized, nationally known, not too large and bureaucratic, and provides you with a cost-effective, “fixed fee” that is fair, equitable, and you can live with.</p>
<p>Issue #2: Scoping the SAS 70 Audit</p>
<p>Numerous factors ultimately come into play for pricing considerations, but scoping is extremely important. It tells you and the CPA firm what will be tested, where it will be tested, and how long the test period will be, if a SAS 70 Type II audit is being performed. </p>
<p>To learn more about SAS 70 audits, <strong><a href="http://www.sas70.us.com">visit the official sas 70 resource guide</a>. </strong></p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/compliance-governance/sas-70-audits-understanding-pricing-for-sas-70-engagements/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
