 




<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>SAS 70 &#187; Access control</title>
	<atom:link href="http://itknowledgeexchange.techtarget.com/sas-70/tag/access-control/feed/" rel="self" type="application/rss+xml" />
	<link>http://itknowledgeexchange.techtarget.com/sas-70</link>
	<description></description>
	<lastBuildDate>Tue, 23 Dec 2008 17:58:25 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	
		<item>
		<title>Importance of User access policy? SAS70</title>
		<link>http://itknowledgeexchange.techtarget.com/sas-70/importance-of-user-access-policy-sas70/</link>
		<comments>http://itknowledgeexchange.techtarget.com/sas-70/importance-of-user-access-policy-sas70/#comments</comments>
		<pubDate>Sun, 07 Dec 2008 13:24:55 +0000</pubDate>
		<dc:creator>SAS70ExPERT</dc:creator>
				<category><![CDATA[Access]]></category>
		<category><![CDATA[Access control]]></category>
		<category><![CDATA[CEO]]></category>
		<category><![CDATA[CIO]]></category>
		<category><![CDATA[SAS 70]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/sas-70/importance-of-user-access-policy-sas70/</guid>
		<description><![CDATA[Recently, I was on a plane flying home and started talking to a CIO about his SAS 70 audit. He seemed dismayed about a former trusted employee taking proprietary data from his company. He noted that they had a policy in place to remove the terminated employee from the company applications; however, this employee was [...]]]></description>
				<content:encoded><![CDATA[<p><!--[if gte mso 9]&gt;     Normal   0         false   false   false                             MicrosoftInternetExplorer4   --><!--[if gte mso 9]&gt;     --> <!--  /* Style Definitions */  p.MsoNormal, li.MsoNormal, div.MsoNormal 	{mso-style-parent:""; 	margin:0in; 	margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:12.0pt; 	font-family:"Times New Roman"; 	mso-fareast-font-family:"Times New Roman";} @page Section1 	{size:8.5in 11.0in; 	margin:1.0in 1.25in 1.0in 1.25in; 	mso-header-margin:.5in; 	mso-footer-margin:.5in; 	mso-paper-source:0;} div.Section1 	{page:Section1;} --> <!--[if gte mso 10]&gt;   /* Style Definitions */  table.MsoNormalTable 	{mso-style-name:"Table Normal"; 	mso-tstyle-rowband-size:0; 	mso-tstyle-colband-size:0; 	mso-style-noshow:yes; 	mso-style-parent:""; 	mso-padding-alt:0in 5.4pt 0in 5.4pt; 	mso-para-margin:0in; 	mso-para-margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:10.0pt; 	font-family:"Times New Roman"; 	mso-ansi-language:#0400; 	mso-fareast-language:#0400; 	mso-bidi-language:#0400;}  --></p>
<p class="MsoNormal">Recently, I was on a plane flying home and started talking to a CIO about his SAS 70 audit. He seemed dismayed about a former trusted employee taking proprietary data from his company. He noted that they had a policy in place to remove the terminated employee from the company applications; however, this employee was able to walk away with the company’s list of customers.</p>
<p class="MsoNormal"> </p>
<p class="MsoNormal">Authorization of access to company applications and removal is a critical process that should be documented and followed by all employees, including executives. In our discussions, he noted that the CEO was a mover and shaker, but he did not always follow company procedures. This loss of data was a direct result of not following policy.</p>
<p class="MsoNormal"> </p>
<p class="MsoNormal">It is critical to a company and to the SAS 70 audit examination that employees and executives follow company policy to gain access and removals to company applications. Otherwise, why have a policy &#8211; Give everyone administrative access.</p>
<p class="MsoNormal"> </p>
<p class="MsoNormal">A good policy should require IT to only be the custodian of applications. They should only provide access when authorized by the business operations and initiated by human resources. Sas70expert@gmail.com</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/sas-70/importance-of-user-access-policy-sas70/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SaaS and SAS70 – SAS70ExPERT</title>
		<link>http://itknowledgeexchange.techtarget.com/sas-70/saas-and-sas70-%e2%80%93-sas70expert/</link>
		<comments>http://itknowledgeexchange.techtarget.com/sas-70/saas-and-sas70-%e2%80%93-sas70expert/#comments</comments>
		<pubDate>Mon, 17 Nov 2008 23:23:03 +0000</pubDate>
		<dc:creator>SAS70ExPERT</dc:creator>
				<category><![CDATA[Access control]]></category>
		<category><![CDATA[Data center operations]]></category>
		<category><![CDATA[Management]]></category>
		<category><![CDATA[Network]]></category>
		<category><![CDATA[SaaS]]></category>
		<category><![CDATA[SAS 70]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/sas-70/saas-and-sas70-%e2%80%93-sas70expert/</guid>
		<description><![CDATA[As more outsourcing of applications takes place in this economy by using SaaS(software-as-a-service), is Management producing costs savings? and how many SAS70&#8242;s will you be required to collect? From the Data Center operations, the IT support vendor, and the application provider?   When you perform your cost-benefit analysis items to consider are Who will benefit [...]]]></description>
				<content:encoded><![CDATA[<p><span></span><span>As more outsourcing of applications takes place in this economy by using SaaS(software-as-a-service), is Management producing costs savings? and how many SAS70&#8242;s will you be required to collect? From the Data Center operations, the IT support vendor, and the application provider?</span></p>
<p><span> </span></p>
<p><span>When you perform your cost-benefit analysis items to consider are </span></p>
<ul>
<li><span>Who will benefit from access control for your application</span></li>
<li><span>From where will your visitors/employees/customers be connecting to your information, vpn network, cellphone or pda, or other web enabled device</span></li>
<li><span>Obtain more control over your licensing costs</span><span><br />
</span></li>
</ul>
<p><span>As you develop a strategic plan to use SaaS, build fundamental close relationships with your vendors and define them carefully in your contracts. Constantly update your contracts or service level agreements to match your needs and develop tools to monitor the success of your vendor meeting your requirements.</span></p>
<p><span> </span></p>
<p><span>SAS70 must be performed on your SaaS vendor to provide you with the reliability, confidentiality and integrity of service to be provided to you and your customers. Control objectives may be similar or different, but careful examination of the audit report should be performed in order to determine that your data is secure. SAS70ExPERT.biz</span></p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/sas-70/saas-and-sas70-%e2%80%93-sas70expert/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Access Rights and SAS70 audit</title>
		<link>http://itknowledgeexchange.techtarget.com/sas-70/access-rights-and-sas70-audit/</link>
		<comments>http://itknowledgeexchange.techtarget.com/sas-70/access-rights-and-sas70-audit/#comments</comments>
		<pubDate>Tue, 21 Oct 2008 00:07:41 +0000</pubDate>
		<dc:creator>SAS70ExPERT</dc:creator>
				<category><![CDATA[Access]]></category>
		<category><![CDATA[Access control]]></category>
		<category><![CDATA[Auditing]]></category>
		<category><![CDATA[SAS 70]]></category>
		<category><![CDATA[Third-party services]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/sas-70/access-rights-and-sas70-audit/</guid>
		<description><![CDATA[Access rights for current employees are essential for the completion of a successful audit. Your company should have a hiring and firing policy that is followed to the letter of the law. When an employee is hired or fired they should have an authorization process to add or delete from company systems or applications. It [...]]]></description>
				<content:encoded><![CDATA[<p><!--[if gte mso 9]&gt;         11.5606   --><!--[if gte mso 9]&gt;     Normal   0         false   false   false                             MicrosoftInternetExplorer4   --><!--[if gte mso 9]&gt;     --> <!--  /* Font Definitions */  @font-face 	{font-family:Verdana; 	panose-1:2 11 6 4 3 5 4 4 2 4; 	mso-font-charset:0; 	mso-generic-font-family:swiss; 	mso-font-pitch:variable; 	mso-font-signature:536871559 0 0 0 415 0;}  /* Style Definitions */  p.MsoNormal, li.MsoNormal, div.MsoNormal 	{mso-style-parent:""; 	margin:0in; 	margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:12.0pt; 	font-family:"Times New Roman"; 	mso-fareast-font-family:"Times New Roman";} @page Section1 	{size:8.5in 11.0in; 	margin:1.0in 1.25in 1.0in 1.25in; 	mso-header-margin:.5in; 	mso-footer-margin:.5in; 	mso-paper-source:0;} div.Section1 	{page:Section1;}  /* List Definitions */  @list l0 	{mso-list-id:421072928; 	mso-list-type:hybrid; 	mso-list-template-ids:-1261133280 67698703 67698713 67698715 67698703 67698713 67698715 67698703 67698713 67698715;} @list l0:level1 	{mso-level-tab-stop:.5in; 	mso-level-number-position:left; 	text-indent:-.25in;} ol 	{margin-bottom:0in;} ul 	{margin-bottom:0in;} --> <!--[if gte mso 10]&gt;   /* Style Definitions */  table.MsoNormalTable 	{mso-style-name:"Table Normal"; 	mso-tstyle-rowband-size:0; 	mso-tstyle-colband-size:0; 	mso-style-noshow:yes; 	mso-style-parent:""; 	mso-padding-alt:0in 5.4pt 0in 5.4pt; 	mso-para-margin:0in; 	mso-para-margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:10.0pt; 	font-family:"Times New Roman"; 	mso-ansi-language:#0400; 	mso-fareast-language:#0400; 	mso-bidi-language:#0400;}  --><em><span></span></em></p>
<p class="MsoNormal"><span>Access rights for current employees are essential for the completion of a successful audit. Your company should have a hiring and firing policy that is followed to the letter of the law. When an employee is hired or fired they should have an authorization process to add or delete from company systems or applications. It is essential that you educate your current employees, contractors, an third party users on this process on a continual basis.</span></p>
<p class="MsoNormal"><span> </span></p>
<p class="MsoNormal"><span>Your company should company not only operating systems or applications, but physical access to company assets. Shared passwords or usernames should be immediately deactivated once an employee or third party leaves. When developing a policy for hiring or terminating consider:</span></p>
<p class="MsoNormal"><span> </span></p>
<p class="MsoNormal"><!--[if !supportLists]--><span><span>1.<span>       </span></span></span><!--[endif]--><span>whether the termination or change of employment will be initiated by your or a third party</span></p>
<p class="MsoNormal"><!--[if !supportLists]--><span><span>2.<span>       </span></span></span><!--[endif]--><span>the current responsibilities of the employee</span></p>
<p class="MsoNormal"><!--[if !supportLists]--><span><span>3.<span>       </span></span></span><!--[endif]--><span>the value of the company assets or data that the employee has access too.</span></p>
<p class="MsoNormal"><span> </span></p>
<p class="MsoNormal"><span>Without a good termination policy or checklist, you will have exceptions within your SAS 70 audit. SAS70ExPERT@gmail.com</span></p>
<p class="MsoNormal"><em><span> </span></em></p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/sas-70/access-rights-and-sas70-audit/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Escalate, Escalate, ESCALATE! if you have been phishing! – SAS70</title>
		<link>http://itknowledgeexchange.techtarget.com/sas-70/escalate-escalate-escalate-if-you-have-been-phishing-%e2%80%93-sas70/</link>
		<comments>http://itknowledgeexchange.techtarget.com/sas-70/escalate-escalate-escalate-if-you-have-been-phishing-%e2%80%93-sas70/#comments</comments>
		<pubDate>Mon, 06 Oct 2008 15:26:05 +0000</pubDate>
		<dc:creator>SAS70ExPERT</dc:creator>
				<category><![CDATA[Access control]]></category>
		<category><![CDATA[SAS 70]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/sas-70/escalate-escalate-escalate-if-you-have-been-phishing-%e2%80%93-sas70/</guid>
		<description><![CDATA[Wachovia Bank has sent you an email stating that your account has been compromised and that you must click the link and enter your username and password. STOP!!! This is phishing. Phishing usually takes the form of illegimate email that looks real! But it is only pretending to be your authorized vendor requesting information. A [...]]]></description>
				<content:encoded><![CDATA[<p><!--[if gte mso 9]&gt;     Normal   0         false   false   false                             MicrosoftInternetExplorer4   --><!--[if gte mso 9]&gt;     --> <!--  /* Font Definitions */  @font-face 	{font-family:Wingdings; 	panose-1:5 0 0 0 0 0 0 0 0 0; 	mso-font-charset:2; 	mso-generic-font-family:auto; 	mso-font-pitch:variable; 	mso-font-signature:0 268435456 0 0 -2147483648 0;} @font-face 	{font-family:Verdana; 	panose-1:2 11 6 4 3 5 4 4 2 4; 	mso-font-charset:0; 	mso-generic-font-family:swiss; 	mso-font-pitch:variable; 	mso-font-signature:536871559 0 0 0 415 0;}  /* Style Definitions */  p.MsoNormal, li.MsoNormal, div.MsoNormal 	{mso-style-parent:""; 	margin:0in; 	margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:12.0pt; 	font-family:"Times New Roman"; 	mso-fareast-font-family:"Times New Roman";} @page Section1 	{size:8.5in 11.0in; 	margin:1.0in 1.25in 1.0in 1.25in; 	mso-header-margin:.5in; 	mso-footer-margin:.5in; 	mso-paper-source:0;} div.Section1 	{page:Section1;}  /* List Definitions */  @list l0 	{mso-list-id:2015917196; 	mso-list-type:hybrid; 	mso-list-template-ids:-480987624 67698689 67698691 67698693 67698689 67698691 67698693 67698689 67698691 67698693;} @list l0:level1 	{mso-level-number-format:bullet; 	mso-level-text:; 	mso-level-tab-stop:.5in; 	mso-level-number-position:left; 	text-indent:-.25in; 	font-family:Symbol;} ol 	{margin-bottom:0in;} ul 	{margin-bottom:0in;} --> <!--[if gte mso 10]&gt;   /* Style Definitions */  table.MsoNormalTable 	{mso-style-name:"Table Normal"; 	mso-tstyle-rowband-size:0; 	mso-tstyle-colband-size:0; 	mso-style-noshow:yes; 	mso-style-parent:""; 	mso-padding-alt:0in 5.4pt 0in 5.4pt; 	mso-para-margin:0in; 	mso-para-margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:10.0pt; 	font-family:"Times New Roman"; 	mso-ansi-language:#0400; 	mso-fareast-language:#0400; 	mso-bidi-language:#0400;}  --><em><span></span></em></p>
<p class="MsoNormal"><span>Wachovia Bank has sent you an email stating that your account has been compromised and that you must click the link and enter your username and password. STOP!!! This is phishing. Phishing usually takes the form of illegimate email that looks real! But it is only pretending to be your authorized vendor requesting information. A SAS 70 auditor will require you to have an escalation policy in to assist in preventing unauthorized access to company information assets. Your companies escalation policy should include:</span></p>
<p class="MsoNormal"><!--[if !supportLists]--><span><span>·<span>          </span></span></span><!--[endif]--><span>Procedures which inform whom you should contact should such an event occur</span></p>
<p class="MsoNormal"><!--[if !supportLists]--><span><span>·<span>          </span></span></span><!--[endif]--><span>In addition, many companies will want you to report the link or forward the entire email to their corporate security administrator</span></p>
<p class="MsoNormal"><span> </span></p>
<p class="MsoNormal"><span>Be sure your authentication policy for your approved users is strong. It should require username and passwords and other secondary authentication mechanisms which are not easily guessed or used frequently. Have you been phished lately? Sas70expert@gmail.com</span></p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/sas-70/escalate-escalate-escalate-if-you-have-been-phishing-%e2%80%93-sas70/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Is pre-boot authentication required? SAS70</title>
		<link>http://itknowledgeexchange.techtarget.com/sas-70/is-pre-boot-authentication-required-sas70/</link>
		<comments>http://itknowledgeexchange.techtarget.com/sas-70/is-pre-boot-authentication-required-sas70/#comments</comments>
		<pubDate>Wed, 20 Aug 2008 04:26:41 +0000</pubDate>
		<dc:creator>SAS70ExPERT</dc:creator>
				<category><![CDATA[Access]]></category>
		<category><![CDATA[Access control]]></category>
		<category><![CDATA[Management]]></category>
		<category><![CDATA[Network]]></category>
		<category><![CDATA[SAS 70]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/sas-70/is-pre-boot-authentication-required-sas70/</guid>
		<description><![CDATA[SAS 70 audits review the authentication procedures required to access computer equipment, including the pre-boot authentication (PBA) procedure.  If pre-boot authentication is not required, then the risks of gaining access to your Company data is very high. What is PBA? Pre-boot authentication is a process that requires a user to authenticate to the operating system [...]]]></description>
				<content:encoded><![CDATA[<p>SAS 70 audits review the authentication procedures required to access computer equipment, including the pre-boot authentication (PBA) procedure.  If pre-boot authentication is not required, then the risks of gaining access to your Company data is very high.</p>
<p>What is PBA? Pre-boot authentication is a process that requires a user to authenticate to the operating system prior to loading of the application software. The user must enter his credentials &#8211; a username and password before the system load begins. Once authenticated, then Windows or Linux operating system is loaded. If the correct user name and password are not entered, the pre-boot authentication process will not load the operating system and the computer will lock down.</p>
<p>Pre-boot authentication prevents a criminal hacker from gaining access to your data by not loading the operating system. Since the bypass tools load after the operating system, then a hacker want get a chance to try to gain entry or use the Windows XP or Vista emergency disks.  SAS70ExPERT@gmail.com</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/sas-70/is-pre-boot-authentication-required-sas70/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Telecommuting as a SAS70 audit control? – SAS70ExPERT</title>
		<link>http://itknowledgeexchange.techtarget.com/sas-70/telecommuting-as-a-sas70-audit-control-%e2%80%93-sas70expert/</link>
		<comments>http://itknowledgeexchange.techtarget.com/sas-70/telecommuting-as-a-sas70-audit-control-%e2%80%93-sas70expert/#comments</comments>
		<pubDate>Sun, 10 Aug 2008 19:54:58 +0000</pubDate>
		<dc:creator>SAS70ExPERT</dc:creator>
				<category><![CDATA[Access control]]></category>
		<category><![CDATA[Auditing]]></category>
		<category><![CDATA[CIO]]></category>
		<category><![CDATA[Compliance]]></category>
		<category><![CDATA[Network]]></category>
		<category><![CDATA[SAS 70]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Telecommuting]]></category>
		<category><![CDATA[Third-party services]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/sas-70/telecommuting-as-a-sas70-audit-control-%e2%80%93-sas70expert/</guid>
		<description><![CDATA[As transportation costs continue to skyrocket over the summer, telework/telecommuting is becoming the new trend among office environments. Basically, we have been doing a form of telework by outsourcing all of our jobs overseas, so this premise is not really new, it’s just new for American workers. 92 percent of workers said their work could [...]]]></description>
				<content:encoded><![CDATA[<p><!--[if gte mso 9]&gt;     Normal   0         false   false   false                             MicrosoftInternetExplorer4   --><!--[if gte mso 9]&gt;     --><!--[if !mso]&gt;  st1\:*{behavior:url(#ieooui) }  --> <!--  /* Style Definitions */  p.MsoNormal, li.MsoNormal, div.MsoNormal 	{mso-style-parent:""; 	margin:0in; 	margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:12.0pt; 	font-family:"Times New Roman"; 	mso-fareast-font-family:"Times New Roman";} @page Section1 	{size:8.5in 11.0in; 	margin:1.0in 1.25in 1.0in 1.25in; 	mso-header-margin:.5in; 	mso-footer-margin:.5in; 	mso-paper-source:0;} div.Section1 	{page:Section1;}  /* List Definitions */  @list l0 	{mso-list-id:1625775100; 	mso-list-type:hybrid; 	mso-list-template-ids:-1362885200 67698705 67698713 67698715 67698703 67698713 67698715 67698703 67698713 67698715;} @list l0:level1 	{mso-level-text:"%1\)"; 	mso-level-tab-stop:.5in; 	mso-level-number-position:left; 	text-indent:-.25in;} ol 	{margin-bottom:0in;} ul 	{margin-bottom:0in;} --> <!--[if gte mso 10]&gt;   /* Style Definitions */  table.MsoNormalTable 	{mso-style-name:"Table Normal"; 	mso-tstyle-rowband-size:0; 	mso-tstyle-colband-size:0; 	mso-style-noshow:yes; 	mso-style-parent:""; 	mso-padding-alt:0in 5.4pt 0in 5.4pt; 	mso-para-margin:0in; 	mso-para-margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:10.0pt; 	font-family:"Times New Roman"; 	mso-ansi-language:#0400; 	mso-fareast-language:#0400; 	mso-bidi-language:#0400;}  --></p>
<p class="MsoNormal">As transportation costs continue to skyrocket over the summer, telework/telecommuting is becoming the new trend among office environments. Basically, we have been doing a form of telework by outsourcing all of our jobs overseas, so this premise is not really new, it’s just new for American workers. 92 percent of workers said their work could be performed from home according to a recent survey by advocacy group Telework Exchange. I agree that operating expenses could be reduced by:</p>
<p class="MsoNormal"><!--[if !supportLists]--><span>1)<span>      </span></span><!--[endif]-->less office space per employee</p>
<p class="MsoNormal"><!--[if !supportLists]--><span>2)<span>      </span></span><!--[endif]-->transportation costs are reduced from commuting to work</p>
<p class="MsoNormal"><!--[if !supportLists]--><span>3)<span>      </span></span><!--[endif]-->reduction in computer hardware expenses</p>
<p class="MsoNormal"> </p>
<p class="MsoNormal">But what is the downside of a remote workforce and what effect will that have on company information assets? These information assets are now stored at a families home on First Avenue, in a 3 bedroom, 2 bath, instead of your 5 story office building. These telecommuting risks will need to examined by management and should be considered in a SAS70 audit.</p>
<p class="MsoNormal"> </p>
<p class="MsoNormal">Consider that most employee homes will not have extended physical or environmental security – only garage door locks and an air conditioner. Their computer office could be located next to their children’s bathroom – which is a likely water hazard, in an open space by a garden window. How easy would it be for a burgular to reach in and knock your coffee cup over, and grab your computer from your first floor home office?Really EASY, as I think many homes today still have yet to have a home alarm system on their windows.Critical company information now could be sold on the internet.</p>
<p class="MsoNormal">&nbsp;</p>
<p class="MsoNormal">In addition, what network security are you assured that they have on their home computer? Do they have the latest virus preventing application? Is their firewall always up and running or might it be turned off to watch a movie?</p>
<p class="MsoNormal">&nbsp;</p>
<p class="MsoNormal">Is your IT staff prepared to make housecalls? Your company information assets now resids at your employees home. It is now not on the second floor of your office, but could be 20-30 miles to First Avenue home. You now must manage users that are at locations that are spread miles apart? This may be okay if 15% of your workforce is remote, but what if it is 92%? Is your IT staff trained accordingly? If they have to make housecalls, do transportation costs truly decrease? Who is managing the network while your IT Administrator is stuck in traffic on his way to the Marketing Director&#8217;s home to fix his computer?</p>
<p class="MsoNormal">&nbsp;</p>
<p class="MsoNormal">Any third party vendor must complete a SAS70 audit to assure it customer that their data is secure. Are you ready to expand your company floor space beyond the office perimeter? Telecommuting risks must be considered in the SAS70 audit process. What are some of the risks you have identified? Do you even have any policies in place at your company which specifically discuss the do’s and don’t’s of a telecommuter? SAS70ExPERT@gmail.com</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/sas-70/telecommuting-as-a-sas70-audit-control-%e2%80%93-sas70expert/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Face up to Biometrics for your SAS70 audit (SAS 70)</title>
		<link>http://itknowledgeexchange.techtarget.com/sas-70/face-up-to-biometrics-for-your-sas70-audit-sas-70/</link>
		<comments>http://itknowledgeexchange.techtarget.com/sas-70/face-up-to-biometrics-for-your-sas70-audit-sas-70/#comments</comments>
		<pubDate>Wed, 06 Aug 2008 18:35:21 +0000</pubDate>
		<dc:creator>SAS70ExPERT</dc:creator>
				<category><![CDATA[Access]]></category>
		<category><![CDATA[Access control]]></category>
		<category><![CDATA[Auditing]]></category>
		<category><![CDATA[CIO]]></category>
		<category><![CDATA[Compliance]]></category>
		<category><![CDATA[DataCenter]]></category>
		<category><![CDATA[Identity & Access Management]]></category>
		<category><![CDATA[SAS 70]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Security management]]></category>
		<category><![CDATA[Security Program Management]]></category>
		<category><![CDATA[Security tokens]]></category>
		<category><![CDATA[Third-party services]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/sas-70/face-up-to-biometrics-for-your-sas70-audit-sas-70/</guid>
		<description><![CDATA[Biometric systems are used today not only at your Data center/ co-location facility, but for plain ole’ laptop access. Finger, hand and thumb prints provide you access to all your critical data. In addition, iris/retinal scans and other facial recognition scans provide the credentials required to prevent forgery. What are you using within your Company? [...]]]></description>
				<content:encoded><![CDATA[<p><!--[if gte mso 9]&gt;     Normal   0         false   false   false                             MicrosoftInternetExplorer4   --><!--[if gte mso 9]&gt;     --><!--[if !mso]&gt;  st1\:*{behavior:url(#ieooui) }  --> <!--  /* Font Definitions */  @font-face 	{font-family:CenturyGothic; 	panose-1:0 0 0 0 0 0 0 0 0 0; 	mso-font-charset:0; 	mso-generic-font-family:auto; 	mso-font-format:other; 	mso-font-pitch:auto; 	mso-font-signature:3 0 0 0 1 0;}  /* Style Definitions */  p.MsoNormal, li.MsoNormal, div.MsoNormal 	{mso-style-parent:""; 	margin:0in; 	margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:12.0pt; 	font-family:"Times New Roman"; 	mso-fareast-font-family:"Times New Roman";} @page Section1 	{size:8.5in 11.0in; 	margin:1.0in 1.25in 1.0in 1.25in; 	mso-header-margin:.5in; 	mso-footer-margin:.5in; 	mso-paper-source:0;} div.Section1 	{page:Section1;}  /* List Definitions */  @list l0 	{mso-list-id:1407458705; 	mso-list-type:hybrid; 	mso-list-template-ids:708475470 67698705 67698713 67698715 67698703 67698713 67698715 67698703 67698713 67698715;} @list l0:level1 	{mso-level-text:"%1\)"; 	mso-level-tab-stop:.5in; 	mso-level-number-position:left; 	text-indent:-.25in;} ol 	{margin-bottom:0in;} ul 	{margin-bottom:0in;} --> <!--[if gte mso 10]&gt;   /* Style Definitions */  table.MsoNormalTable 	{mso-style-name:"Table Normal"; 	mso-tstyle-rowband-size:0; 	mso-tstyle-colband-size:0; 	mso-style-noshow:yes; 	mso-style-parent:""; 	mso-padding-alt:0in 5.4pt 0in 5.4pt; 	mso-para-margin:0in; 	mso-para-margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:10.0pt; 	font-family:"Times New Roman"; 	mso-ansi-language:#0400; 	mso-fareast-language:#0400; 	mso-bidi-language:#0400;}  --><span>Biometric systems are used today not only at your Data center/ co-location facility, but for plain ole’ laptop access. Finger, hand and thumb prints provide you access to all your critical data. In addition, iris/retinal scans and other facial recognition scans provide the credentials required to prevent forgery. What are you using within your Company? </span></p>
<p class="MsoNormal"><span> </span></p>
<p class="MsoNormal"><span>For a SAS 70 audit, critical areas to review related to biometrics are:</span></p>
<p class="MsoNormal"><!--[if !supportLists]--><span><span>1)<span>       </span></span></span><!--[endif]--><span>enrollment process for a new user</span></p>
<p class="MsoNormal"><!--[if !supportLists]--><span><span>2)<span>       </span></span></span><!--[endif]--><span>accuracy and monitoring of the biometric device</span></p>
<p class="MsoNormal"><!--[if !supportLists]--><span><span>3)<span>       </span></span></span><!--[endif]--><span>termination of users</span></p>
<p class="MsoNormal"><span> </span></p>
<p class="MsoNormal"><span>During enrollment, an individual’s biometric template is created in a database. Make sure you have a documented process for adding and authorizing new users to the database. You must know who may authorize access, and how much access to give the new employee. <span> </span></span></p>
<p class="MsoNormal"><span> </span></p>
<p class="MsoNormal"><span>Determine the accuracy and monitoring of biometric usage. Review who has used the biometric device, by reviewing the logs an identifying any unusual activity. For example, if you note that Bob has entered the facility 3 times and there is no exit<span>  </span>– then your device may not be working properly.</span></p>
<p class="MsoNormal"><span> </span></p>
<p class="MsoNormal"><span>Last, if Adam quits or Alice is fired, then how do you know to delete her credentials from the system? Make sure Human Resources has a policy to notify you immediately when a person needs to be removed from the system. IT should have a checklist of items/inventory to be returned when employee exits and the form should include a sign-off to indicate removal from the biometric device. Sas70expert@gmail.com</span></p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/sas-70/face-up-to-biometrics-for-your-sas70-audit-sas-70/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>7 essential to have in your SLA’s to have to help you manage your outsourced vendor &#8211; SAS70</title>
		<link>http://itknowledgeexchange.techtarget.com/sas-70/7-essential-to-have-in-your-sla%e2%80%99s-to-have-to-help-you-manage-your-outsourced-vendor-sas70/</link>
		<comments>http://itknowledgeexchange.techtarget.com/sas-70/7-essential-to-have-in-your-sla%e2%80%99s-to-have-to-help-you-manage-your-outsourced-vendor-sas70/#comments</comments>
		<pubDate>Thu, 24 Jul 2008 01:36:47 +0000</pubDate>
		<dc:creator>SAS70ExPERT</dc:creator>
				<category><![CDATA[Access control]]></category>
		<category><![CDATA[Auditing]]></category>
		<category><![CDATA[CIO]]></category>
		<category><![CDATA[Compliance]]></category>
		<category><![CDATA[CSO]]></category>
		<category><![CDATA[Data center operations]]></category>
		<category><![CDATA[Management]]></category>
		<category><![CDATA[Monitoring]]></category>
		<category><![CDATA[Risk management]]></category>
		<category><![CDATA[SAS 70]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Security management]]></category>
		<category><![CDATA[Security Program Management]]></category>
		<category><![CDATA[Third-party services]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/sas-70/7-essential-to-have-in-your-sla%e2%80%99s-to-have-to-help-you-manage-your-outsourced-vendor-sas70/</guid>
		<description><![CDATA[“Do you understand what impact the outsourced vendor has on your financial stability?” says a SAS 70 auditor. If they fail to make payroll or Friday or if you’re DataCenter fails, what effect will that have on your operations? So as not to be “asleep at the switch,” make sure you understand the vendor’s operations [...]]]></description>
				<content:encoded><![CDATA[<p><!--[if gte mso 9]&gt;     Normal   0         false   false   false                             MicrosoftInternetExplorer4   --><!--[if gte mso 9]&gt;     --><!--[if !mso]&gt;  st1\:*{behavior:url(#ieooui) }  --> <!--  /* Style Definitions */  p.MsoNormal, li.MsoNormal, div.MsoNormal 	{mso-style-parent:""; 	margin:0in; 	margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:12.0pt; 	font-family:"Times New Roman"; 	mso-fareast-font-family:"Times New Roman";} @page Section1 	{size:8.5in 11.0in; 	margin:1.0in 1.25in 1.0in 1.25in; 	mso-header-margin:.5in; 	mso-footer-margin:.5in; 	mso-paper-source:0;} div.Section1 	{page:Section1;} --> <!--[if gte mso 10]&gt;   /* Style Definitions */  table.MsoNormalTable 	{mso-style-name:"Table Normal"; 	mso-tstyle-rowband-size:0; 	mso-tstyle-colband-size:0; 	mso-style-noshow:yes; 	mso-style-parent:""; 	mso-padding-alt:0in 5.4pt 0in 5.4pt; 	mso-para-margin:0in; 	mso-para-margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:10.0pt; 	font-family:"Times New Roman"; 	mso-ansi-language:#0400; 	mso-fareast-language:#0400; 	mso-bidi-language:#0400;}  --></p>
<p class="MsoNormal">“Do you understand what impact the outsourced vendor has on your financial stability?” says a SAS 70 auditor. If they fail to make payroll or Friday or if you’re DataCenter fails, what effect will that have on your operations? So as not to be “asleep at the switch,” make sure you understand the vendor’s operations and risks involved. Here are 10 essential specifications that you should have in your service level agreement with you’re outsourced vendor:</p>
<p class="MsoNormal">1) Data encryption and protection – determine what your vendor is doing from an information technology perspective to protect your information. Are they using applications that have security built-in? Do they have firewalls?</p>
<p class="MsoNormal">2) Physical Security – review and management of access to buildings and data is critical to protect information technology assets. Tight control must be maintained in order to prevent identify theft and loss of valuable equipment, like exchange servers, racks, and hard drives. Each employee should have ID, preferably biometric, and you should log entry and egress into facilities.</p>
<p class="MsoNormal">3) Environmental Security – Make sure your data is not only locked in the safe room, but that the environment in the room provides essential protections. Do they have fire extinguishers? Temperature control? Air conditioners? …etc.</p>
<p class="MsoNormal">4) Confidentiality agreements – Require your business partner/vendor to sign confidentiality agreements/non-disclosure agreements to prevent loss of trade secrets, data, and patents.</p>
<p class="MsoNormal">5)Employee training – Policies are useless, unless your employees and vendors are trained and aware. Provide all vendors with awareness training of your requirements when processing your information or providing you with services.</p>
<p class="MsoNormal">6) Require employee background investigations. You want to make sure that the person responsible for managing your money is not a convicted felon. They must have a review of the work history and a validation of the skills.</p>
<p class="MsoNormal">7)Lastly, Management of vendors- After you have given your requirements to your vendor, how do you know they stay in compliance? A SAS 70 audit is required. sas70expert@gmail.com</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/sas-70/7-essential-to-have-in-your-sla%e2%80%99s-to-have-to-help-you-manage-your-outsourced-vendor-sas70/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Green is mean and lean but is it the ticket to prosperity? SAS70</title>
		<link>http://itknowledgeexchange.techtarget.com/sas-70/green-is-mean-and-lean-but-is-it-the-ticket-to-prosperity-sas70/</link>
		<comments>http://itknowledgeexchange.techtarget.com/sas-70/green-is-mean-and-lean-but-is-it-the-ticket-to-prosperity-sas70/#comments</comments>
		<pubDate>Wed, 16 Jul 2008 15:14:11 +0000</pubDate>
		<dc:creator>SAS70ExPERT</dc:creator>
				<category><![CDATA[Access control]]></category>
		<category><![CDATA[Auditing]]></category>
		<category><![CDATA[CIO]]></category>
		<category><![CDATA[Compliance]]></category>
		<category><![CDATA[DataCenter]]></category>
		<category><![CDATA[Exchange]]></category>
		<category><![CDATA[Identity & Access Management]]></category>
		<category><![CDATA[Management]]></category>
		<category><![CDATA[Network Management Systems]]></category>
		<category><![CDATA[power systems]]></category>
		<category><![CDATA[Risk management]]></category>
		<category><![CDATA[SAS 70]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Security management]]></category>
		<category><![CDATA[Security Program Management]]></category>
		<category><![CDATA[Third-party services]]></category>
		<category><![CDATA[TrendMirco]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/sas-70/green-is-mean-and-lean-but-is-it-the-ticket-to-prosperity-sas70/</guid>
		<description><![CDATA[Exchange Servers are increasingly being added to the electric grid and increasing the world’s energy consumption, carbon emissions and stream wastes. A recent report stated that “U.S. server electricity consumption has doubled in the past five years and now equals that of color TV’s. SAS70 audits review logical and network related controls for servers, but [...]]]></description>
				<content:encoded><![CDATA[<p><!--[if gte mso 9]&gt;     Normal   0         false   false   false                             MicrosoftInternetExplorer4   --><!--[if gte mso 9]&gt;     --><!--[if !mso]&gt;  st1\:*{behavior:url(#ieooui) }  --> <!--  /* Style Definitions */  p.MsoNormal, li.MsoNormal, div.MsoNormal 	{mso-style-parent:""; 	margin:0in; 	margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:12.0pt; 	font-family:"Times New Roman"; 	mso-fareast-font-family:"Times New Roman";} @page Section1 	{size:8.5in 11.0in; 	margin:1.0in 1.25in 1.0in 1.25in; 	mso-header-margin:.5in; 	mso-footer-margin:.5in; 	mso-paper-source:0;} div.Section1 	{page:Section1;} --> <!--[if gte mso 10]&gt;   /* Style Definitions */  table.MsoNormalTable 	{mso-style-name:"Table Normal"; 	mso-tstyle-rowband-size:0; 	mso-tstyle-colband-size:0; 	mso-style-noshow:yes; 	mso-style-parent:""; 	mso-padding-alt:0in 5.4pt 0in 5.4pt; 	mso-para-margin:0in; 	mso-para-margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:10.0pt; 	font-family:"Times New Roman"; 	mso-ansi-language:#0400; 	mso-fareast-language:#0400; 	mso-bidi-language:#0400;}  --></p>
<p class="MsoNormal">Exchange Servers are increasingly being added to the electric grid and increasing the world’s energy consumption, carbon emissions and stream wastes. A recent report stated that “U.S. server electricity consumption has doubled in the past five years and now equals that of color TV’s. SAS70 audits review logical and network related controls for servers, but they don’t consider the energy consumption or quality of company environmental efforts.</p>
<p class="MsoNormal"> </p>
<p class="MsoNormal">All kinds of new energy saving ideas are being developed, including air-compressed backup generators. Greenpeace has developed a &#8220;Guide to Greener Electronics.” The guide ranks the 18 top manufacturers of personal computers, mobile phones, TV&#8217;s and games consoles according to their policies on toxic chemicals and recycling.</p>
<p>I think that this is great, but is it sustainable considering our populations demand for service NOW!? In an electronic age, where I can practically order anything, see any tv show, or buy any music at the touch of a button on my i-Phone, can we expect businesses to<span>  </span>choose green over a quick dollar? As datacenter demand grows and the need for servers bandwidth is required – will you stop and say<span>  </span>“No, I want my children to enjoy clean air, and clean water.” Or will you push forward with a browner (less green) alternative computing solution? Should SAS70 audits evaluate environmental and energy efforts? sas70expert@gamil.com</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/sas-70/green-is-mean-and-lean-but-is-it-the-ticket-to-prosperity-sas70/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How laptops become serial killers?  &#8211; SAS70</title>
		<link>http://itknowledgeexchange.techtarget.com/sas-70/how-laptops-become-serial-killers-sas70/</link>
		<comments>http://itknowledgeexchange.techtarget.com/sas-70/how-laptops-become-serial-killers-sas70/#comments</comments>
		<pubDate>Sun, 06 Jul 2008 16:18:05 +0000</pubDate>
		<dc:creator>SAS70ExPERT</dc:creator>
				<category><![CDATA[Access]]></category>
		<category><![CDATA[Access control]]></category>
		<category><![CDATA[Administration]]></category>
		<category><![CDATA[Auditing]]></category>
		<category><![CDATA[CFO]]></category>
		<category><![CDATA[CIO]]></category>
		<category><![CDATA[Compliance]]></category>
		<category><![CDATA[CSO]]></category>
		<category><![CDATA[DataCenter]]></category>
		<category><![CDATA[human factors]]></category>
		<category><![CDATA[Information risk management]]></category>
		<category><![CDATA[Management]]></category>
		<category><![CDATA[Monitoring]]></category>
		<category><![CDATA[Network]]></category>
		<category><![CDATA[Network Management Systems]]></category>
		<category><![CDATA[Risk management]]></category>
		<category><![CDATA[SAS 70]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Security management]]></category>
		<category><![CDATA[Security Program Management]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/sas-70/how-laptops-become-serial-killers-sas70/</guid>
		<description><![CDATA[My business requires distribution and collection of data. Much of it resides on a centrally located server; however, there is data on the laptop that has never been transferred over to the server or that may have  been taken off the server for project work. As human beings we will never be perfect. Someone will [...]]]></description>
				<content:encoded><![CDATA[<p><!--[if gte mso 9]&gt;     Normal   0         false   false   false                             MicrosoftInternetExplorer4   --><!--[if gte mso 9]&gt;     --> <!--  /* Style Definitions */  p.MsoNormal, li.MsoNormal, div.MsoNormal 	{mso-style-parent:""; 	margin:0in; 	margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:12.0pt; 	font-family:"Times New Roman"; 	mso-fareast-font-family:"Times New Roman";} @page Section1 	{size:8.5in 11.0in; 	margin:1.0in 1.25in 1.0in 1.25in; 	mso-header-margin:.5in; 	mso-footer-margin:.5in; 	mso-paper-source:0;} div.Section1 	{page:Section1;} --> <!--[if gte mso 10]&gt;   /* Style Definitions */  table.MsoNormalTable 	{mso-style-name:"Table Normal"; 	mso-tstyle-rowband-size:0; 	mso-tstyle-colband-size:0; 	mso-style-noshow:yes; 	mso-style-parent:""; 	mso-padding-alt:0in 5.4pt 0in 5.4pt; 	mso-para-margin:0in; 	mso-para-margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:10.0pt; 	font-family:"Times New Roman"; 	mso-ansi-language:#0400; 	mso-fareast-language:#0400; 	mso-bidi-language:#0400;}  --></p>
<p class="MsoNormal">My business requires distribution and collection of data. Much of it resides on a centrally located server; however, there is data on the laptop that has never been transferred over to the server or that may have  been taken off the server for project work. As human beings we will never be perfect. Someone will lend access to their laptop to a friend or customer, a laptop will be lost or stolen, and an unprotected USB drive is a loaded gun just waiting to have the trigger pulled so that data can be transferred off your laptop. Laptops with sensitive data that goes unprotected, can become a media nightmare, a legal hassle and a may limit your customer retention and market growth &#8212; a serial killer that stops your business growth and the vendors that support you.</p>
<p class="MsoNormal">&nbsp;</p>
<p class="MsoNormal"> To protect data loss, we now have L0-jack services for laptops when they are stolen. The laptop can be found and once connected to a network will be shut down.But what about the ease we have to install and transfer data to others using USB drives. Even if you use a USB drive that requires a password, is that enough security? I have read recently that laptops were returned after being lost that contained sensitive data such as social security numbers for big companies – including Google. Now that they have the laptop back, is the risk over? What if the data was transferred off the laptop onto a USB drive?</p>
<p class="MsoNormal"> </p>
<p class="MsoNormal">Just like for the SAS70 audit, you have to perform a risk assessment to determine the controls that must be in place, and identify those that can be implemented as time permits. In the situation above, I don’t think focusing on the number of ways that data can be taken off laptops is the key to reducing risk. You should focus more on identifying the type of data that you have, mark the sensitive data, and control access to it – by limiting users, strengthening laptop controls around the sensitive data, and identifying opportunities to record transfer of sensitive data <span></span>which would provide an audit trail. How are you controlling your data on your laptops? sas70expert@gmail.com</p>
<p class="MsoNormal"> </p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/sas-70/how-laptops-become-serial-killers-sas70/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>
