I have a quick question regarding SAS-70 Certification. If my company completes a SAS-70 audit, does that automatically make us certified or are there additional steps for certification? also when we get certified how long does that certification last before it will need to be renewed? any information would be very helpful. Thanks
I need some advice from other security experts. I was recently hired to work for a small company where our data and infrastructure is at a managed hosting facility. The hosting service has a SAS 70 that is regularly audited. My company in the past relied – almost solely – on the managed service security [...]
Hello If a customer don’t wants to execute the SAS70 type 2 audit – is there any other compliance standards that you can choose from ? That is to get the same compliance documentation/status but not execute the SAS70 type 2 audit? Is there any light version of the SAS70 standards?
I’m looking for recommendations someone who has used similar services – a Security auditing vendor for SaaS applications and a SAS-70 vendor in DC/MD/VA area for a small company.
The electrical network that feeds the access points, CCTV cameras, intruder detectors, etc. must need to be independent from the electrical system that feeds the computing equipment? Is it right to ask if the logs of access point are backed up and kept in a secure place? what about the videos that cameras are recording? [...]
I would like to have a look at the standard list of questions that an auditor might ask when undertaking an SAS 70 audit……
Names of SAS 70 Compliant ISPs
When benchmarking a SAS70 audit to determine if the necessary controls were audited, what standards do you use as guidance to determine the controls to be tested and the control objectives? Does IT rely on internal audit for guidance or do you have your IT processes documented?





