I would like to have a look at the standard list of questions that an auditor might ask when undertaking an SAS 70 audit......
Access control, Administrative privileges, Antivirus, Application security, Auditing, Authentication, Biometrics, Cisco IOS, Cisco PIX, Cisco router configuration, Current threats, Digital certificates, Encryption, Firewalls, Forensics, Hacking, Identity & Access Management, Incident response, Information risk management, Intrusion management, ISA Server, malware, Password, Patch management, patching, PEN testing, PIX, Platform Security, Risk management, Secure Coding, Security management, Security products, Security Program Management, Security tokens, Single sign-on, Spyware, SSL, SSL/TLS, Switch configuration, Symantec, Trojans, User Permissions, Veritas, Viruses, Vulnerability Assessment & Audit, vulnerability management, Web security, Windows Security, Wireless routers, worms >>VIEW ALL TAGS