 




<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>SAS 70 &#187; Access</title>
	<atom:link href="http://itknowledgeexchange.techtarget.com/sas-70/tag/access/feed/" rel="self" type="application/rss+xml" />
	<link>http://itknowledgeexchange.techtarget.com/sas-70</link>
	<description></description>
	<lastBuildDate>Tue, 23 Dec 2008 17:58:25 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	
		<item>
		<title>Importance of User access policy? SAS70</title>
		<link>http://itknowledgeexchange.techtarget.com/sas-70/importance-of-user-access-policy-sas70/</link>
		<comments>http://itknowledgeexchange.techtarget.com/sas-70/importance-of-user-access-policy-sas70/#comments</comments>
		<pubDate>Sun, 07 Dec 2008 13:24:55 +0000</pubDate>
		<dc:creator>SAS70ExPERT</dc:creator>
				<category><![CDATA[Access]]></category>
		<category><![CDATA[Access control]]></category>
		<category><![CDATA[CEO]]></category>
		<category><![CDATA[CIO]]></category>
		<category><![CDATA[SAS 70]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/sas-70/importance-of-user-access-policy-sas70/</guid>
		<description><![CDATA[Recently, I was on a plane flying home and started talking to a CIO about his SAS 70 audit. He seemed dismayed about a former trusted employee taking proprietary data from his company. He noted that they had a policy in place to remove the terminated employee from the company applications; however, this employee was [...]]]></description>
				<content:encoded><![CDATA[<p><!--[if gte mso 9]&gt;     Normal   0         false   false   false                             MicrosoftInternetExplorer4   --><!--[if gte mso 9]&gt;     --> <!--  /* Style Definitions */  p.MsoNormal, li.MsoNormal, div.MsoNormal 	{mso-style-parent:""; 	margin:0in; 	margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:12.0pt; 	font-family:"Times New Roman"; 	mso-fareast-font-family:"Times New Roman";} @page Section1 	{size:8.5in 11.0in; 	margin:1.0in 1.25in 1.0in 1.25in; 	mso-header-margin:.5in; 	mso-footer-margin:.5in; 	mso-paper-source:0;} div.Section1 	{page:Section1;} --> <!--[if gte mso 10]&gt;   /* Style Definitions */  table.MsoNormalTable 	{mso-style-name:"Table Normal"; 	mso-tstyle-rowband-size:0; 	mso-tstyle-colband-size:0; 	mso-style-noshow:yes; 	mso-style-parent:""; 	mso-padding-alt:0in 5.4pt 0in 5.4pt; 	mso-para-margin:0in; 	mso-para-margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:10.0pt; 	font-family:"Times New Roman"; 	mso-ansi-language:#0400; 	mso-fareast-language:#0400; 	mso-bidi-language:#0400;}  --></p>
<p class="MsoNormal">Recently, I was on a plane flying home and started talking to a CIO about his SAS 70 audit. He seemed dismayed about a former trusted employee taking proprietary data from his company. He noted that they had a policy in place to remove the terminated employee from the company applications; however, this employee was able to walk away with the company’s list of customers.</p>
<p class="MsoNormal"> </p>
<p class="MsoNormal">Authorization of access to company applications and removal is a critical process that should be documented and followed by all employees, including executives. In our discussions, he noted that the CEO was a mover and shaker, but he did not always follow company procedures. This loss of data was a direct result of not following policy.</p>
<p class="MsoNormal"> </p>
<p class="MsoNormal">It is critical to a company and to the SAS 70 audit examination that employees and executives follow company policy to gain access and removals to company applications. Otherwise, why have a policy &#8211; Give everyone administrative access.</p>
<p class="MsoNormal"> </p>
<p class="MsoNormal">A good policy should require IT to only be the custodian of applications. They should only provide access when authorized by the business operations and initiated by human resources. Sas70expert@gmail.com</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/sas-70/importance-of-user-access-policy-sas70/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Access Rights and SAS70 audit</title>
		<link>http://itknowledgeexchange.techtarget.com/sas-70/access-rights-and-sas70-audit/</link>
		<comments>http://itknowledgeexchange.techtarget.com/sas-70/access-rights-and-sas70-audit/#comments</comments>
		<pubDate>Tue, 21 Oct 2008 00:07:41 +0000</pubDate>
		<dc:creator>SAS70ExPERT</dc:creator>
				<category><![CDATA[Access]]></category>
		<category><![CDATA[Access control]]></category>
		<category><![CDATA[Auditing]]></category>
		<category><![CDATA[SAS 70]]></category>
		<category><![CDATA[Third-party services]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/sas-70/access-rights-and-sas70-audit/</guid>
		<description><![CDATA[Access rights for current employees are essential for the completion of a successful audit. Your company should have a hiring and firing policy that is followed to the letter of the law. When an employee is hired or fired they should have an authorization process to add or delete from company systems or applications. It [...]]]></description>
				<content:encoded><![CDATA[<p><!--[if gte mso 9]&gt;         11.5606   --><!--[if gte mso 9]&gt;     Normal   0         false   false   false                             MicrosoftInternetExplorer4   --><!--[if gte mso 9]&gt;     --> <!--  /* Font Definitions */  @font-face 	{font-family:Verdana; 	panose-1:2 11 6 4 3 5 4 4 2 4; 	mso-font-charset:0; 	mso-generic-font-family:swiss; 	mso-font-pitch:variable; 	mso-font-signature:536871559 0 0 0 415 0;}  /* Style Definitions */  p.MsoNormal, li.MsoNormal, div.MsoNormal 	{mso-style-parent:""; 	margin:0in; 	margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:12.0pt; 	font-family:"Times New Roman"; 	mso-fareast-font-family:"Times New Roman";} @page Section1 	{size:8.5in 11.0in; 	margin:1.0in 1.25in 1.0in 1.25in; 	mso-header-margin:.5in; 	mso-footer-margin:.5in; 	mso-paper-source:0;} div.Section1 	{page:Section1;}  /* List Definitions */  @list l0 	{mso-list-id:421072928; 	mso-list-type:hybrid; 	mso-list-template-ids:-1261133280 67698703 67698713 67698715 67698703 67698713 67698715 67698703 67698713 67698715;} @list l0:level1 	{mso-level-tab-stop:.5in; 	mso-level-number-position:left; 	text-indent:-.25in;} ol 	{margin-bottom:0in;} ul 	{margin-bottom:0in;} --> <!--[if gte mso 10]&gt;   /* Style Definitions */  table.MsoNormalTable 	{mso-style-name:"Table Normal"; 	mso-tstyle-rowband-size:0; 	mso-tstyle-colband-size:0; 	mso-style-noshow:yes; 	mso-style-parent:""; 	mso-padding-alt:0in 5.4pt 0in 5.4pt; 	mso-para-margin:0in; 	mso-para-margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:10.0pt; 	font-family:"Times New Roman"; 	mso-ansi-language:#0400; 	mso-fareast-language:#0400; 	mso-bidi-language:#0400;}  --><em><span></span></em></p>
<p class="MsoNormal"><span>Access rights for current employees are essential for the completion of a successful audit. Your company should have a hiring and firing policy that is followed to the letter of the law. When an employee is hired or fired they should have an authorization process to add or delete from company systems or applications. It is essential that you educate your current employees, contractors, an third party users on this process on a continual basis.</span></p>
<p class="MsoNormal"><span> </span></p>
<p class="MsoNormal"><span>Your company should company not only operating systems or applications, but physical access to company assets. Shared passwords or usernames should be immediately deactivated once an employee or third party leaves. When developing a policy for hiring or terminating consider:</span></p>
<p class="MsoNormal"><span> </span></p>
<p class="MsoNormal"><!--[if !supportLists]--><span><span>1.<span>       </span></span></span><!--[endif]--><span>whether the termination or change of employment will be initiated by your or a third party</span></p>
<p class="MsoNormal"><!--[if !supportLists]--><span><span>2.<span>       </span></span></span><!--[endif]--><span>the current responsibilities of the employee</span></p>
<p class="MsoNormal"><!--[if !supportLists]--><span><span>3.<span>       </span></span></span><!--[endif]--><span>the value of the company assets or data that the employee has access too.</span></p>
<p class="MsoNormal"><span> </span></p>
<p class="MsoNormal"><span>Without a good termination policy or checklist, you will have exceptions within your SAS 70 audit. SAS70ExPERT@gmail.com</span></p>
<p class="MsoNormal"><em><span> </span></em></p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/sas-70/access-rights-and-sas70-audit/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Risk Assessments and the SAS 70 audit</title>
		<link>http://itknowledgeexchange.techtarget.com/sas-70/risk-assessments-and-the-sas-70-audit/</link>
		<comments>http://itknowledgeexchange.techtarget.com/sas-70/risk-assessments-and-the-sas-70-audit/#comments</comments>
		<pubDate>Wed, 17 Sep 2008 15:35:03 +0000</pubDate>
		<dc:creator>SAS70ExPERT</dc:creator>
				<category><![CDATA[Access]]></category>
		<category><![CDATA[Auditing]]></category>
		<category><![CDATA[CIO]]></category>
		<category><![CDATA[COBIT]]></category>
		<category><![CDATA[Management]]></category>
		<category><![CDATA[Monitoring]]></category>
		<category><![CDATA[Network]]></category>
		<category><![CDATA[Risk management]]></category>
		<category><![CDATA[SAS 70]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/sas-70/risk-assessments-and-the-sas-70-audit/</guid>
		<description><![CDATA[Management’s risk assessment process is required to be audited in a SAS70 examination; however, in my experience, most auditors do not adequately review Management’s risk assessment process. Without adequate auditing experience, most auditors would not have a basis to determine if Management had reviewed the control risk universe. In addition, Management mostly does not formally [...]]]></description>
				<content:encoded><![CDATA[<p><!--[if !mso]&gt;  v\:* {behavior:url(#default#VML);} o\:* {behavior:url(#default#VML);} w\:* {behavior:url(#default#VML);} .shape {behavior:url(#default#VML);}  --><!--[if gte mso 9]&gt;     Normal   0         false   false   false                             MicrosoftInternetExplorer4   --><!--[if gte mso 9]&gt;     --> <!--  /* Font Definitions */  @font-face 	{font-family:"Arial Narrow"; 	panose-1:2 11 5 6 2 2 2 3 2 4; 	mso-font-charset:0; 	mso-generic-font-family:swiss; 	mso-font-pitch:variable; 	mso-font-signature:647 0 0 0 159 0;}  /* Style Definitions */  p.MsoNormal, li.MsoNormal, div.MsoNormal 	{mso-style-parent:""; 	margin:0in; 	margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:12.0pt; 	font-family:"Times New Roman"; 	mso-fareast-font-family:"Times New Roman";} a:link, span.MsoHyperlink 	{color:blue; 	text-decoration:underline; 	text-underline:single;} a:visited, span.MsoHyperlinkFollowed 	{color:purple; 	text-decoration:underline; 	text-underline:single;} @page Section1 	{size:8.5in 11.0in; 	margin:1.0in 1.25in 1.0in 1.25in; 	mso-header-margin:.5in; 	mso-footer-margin:.5in; 	mso-paper-source:0;} div.Section1 	{page:Section1;} --> <!--[if gte mso 10]&gt;   /* Style Definitions */  table.MsoNormalTable 	{mso-style-name:"Table Normal"; 	mso-tstyle-rowband-size:0; 	mso-tstyle-colband-size:0; 	mso-style-noshow:yes; 	mso-style-parent:""; 	mso-padding-alt:0in 5.4pt 0in 5.4pt; 	mso-para-margin:0in; 	mso-para-margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:10.0pt; 	font-family:"Times New Roman"; 	mso-ansi-language:#0400; 	mso-fareast-language:#0400; 	mso-bidi-language:#0400;}  --><!--[if gte mso 9]&gt;   --><!--[if gte mso 9]&gt;       --><span></span></p>
<p class="MsoNormal"><span>Management’s risk assessment process is required to be audited in a SAS70 examination; however, in my experience, most auditors do not adequately review Management’s risk assessment process. Without adequate auditing experience, most auditors would not have a basis to determine if Management had reviewed the control risk universe. In addition, Management mostly does not formally document risks, but they are discussed only in Board meeting with among C-level executive’s. The COBIT risk assessment framework can provide Management with the criteria and the details that an inexperienced auditor may use as a guide to examine their risk assessment process</span></p>
<p class="MsoNormal"><span> </span></p>
<p class="MsoNormal"><span>COBIT consists</span><span> of information that is required to help achieve business objectives. You must first begin with a vulnerability analysis of your business operations. Then determine the threats to these vulnerabilities For example, your greatest risk may be related to the legal liabilities due to incorrect financial statements….. or something more simpler, like loss of a backup tape which contained your customers social security numbers. Third, determine the impact of this threat. Is it a million dollar monetary fine, or could your license to conduct business be taken away. The conclusion is an action plan after which the cycle can start again. </span></p>
<p class="MsoNormal"><span> </span></p>
<p class="MsoNormal"><span>When the SAS 70 auditor discusses your risk assessment process, don’t be afraid to say that you have it all stored in your brain. Without risk documentation, an experience auditing firm will assist you in forming a roadmap of risks that lead to your business success. Mr. CIO, have you determine what are your business risks or your information technology risks today? Have you formally discussed and evaluated them with other c-level executives or with your peers and association’s within your industry. Note from the diagram below the a formal risk assessment process. Next time we will discuss each of these layers in detail. <a href="mailto:SAS70ExPERT@gmail.com">SAS70ExPERT@gmail.com</a> </span></p>
<p class="MsoNormal"><span> </span></p>
<p class="MsoNormal"><!--[if mso &amp; !supportInlineShapes &amp; supportFields]&gt;<span><span></span><span> </span>SHAPE<span>  </span>\* MERGEFORMAT <span></span></span>&#8211;><span><!--[if gte vml 1]&gt;-->                                                                                       </p>
<table cellpadding="0" cellspacing="0" width="100%">
<tr>
<td>
<div>
<p class="MsoNormal" align="center"><span>Asset</span></p>
<p class="MsoNormal" align="center"><span>Identification</span></p>
<p class="MsoNormal" align="center"><span>and Valuation</span></p>
</div>
</td>
</tr>
</table>
<table cellpadding="0" cellspacing="0" width="100%">
<tr>
<td>
<div>
<p class="MsoNormal"><span>Vulnerability</span></p>
<p class="MsoNormal"><span>&nbsp;</span></p>
</div>
</td>
</tr>
</table>
<table cellpadding="0" cellspacing="0" width="100%">
<tr>
<td>
<div>
<p class="MsoNormal"><span><span> </span>Assessment</span></p>
</div>
</td>
</tr>
</table>
<table cellpadding="0" cellspacing="0" width="100%">
<tr>
<td>
<div>
<p class="MsoNormal"><span><span>   </span>Threat</span></p>
<p class="MsoNormal"><span>&nbsp;</span></p>
</div>
</td>
</tr>
</table>
<table cellpadding="0" cellspacing="0" width="100%">
<tr>
<td>
<div>
<p class="MsoNormal"><span>Assessment</span></p>
</div>
</td>
</tr>
</table>
<table cellpadding="0" cellspacing="0" width="100%">
<tr>
<td>
<div>
<p class="MsoNormal"><span><span>    </span>Risk</span></p>
<p class="MsoNormal"><span>&nbsp;</span></p>
</div>
</td>
</tr>
</table>
<table cellpadding="0" cellspacing="0" width="100%">
<tr>
<td>
<div>
<p class="MsoNormal"><span>Assessment</span></p>
</div>
</td>
</tr>
</table>
<table cellpadding="0" cellspacing="0" width="100%">
<tr>
<td>
<div>
<p class="MsoNormal"><span><span> </span>Counter-</span></p>
<p class="MsoNormal"><span>&nbsp;</span></p>
</div>
</td>
</tr>
</table>
<table cellpadding="0" cellspacing="0" width="100%">
<tr>
<td>
<div>
<p class="MsoNormal"><span><span> </span>measures</span></p>
</div>
</td>
</tr>
</table>
<table cellpadding="0" cellspacing="0" width="100%">
<tr>
<td>
<div>
<p class="MsoNormal"><span><span> </span></span><span>Control</span></p>
<p class="MsoNormal"><span>&nbsp;</span></p>
</div>
</td>
</tr>
</table>
<table cellpadding="0" cellspacing="0" width="100%">
<tr>
<td>
<div>
<p class="MsoNormal"><span>Evaluation</span></p>
</div>
</td>
</tr>
</table>
<table cellpadding="0" cellspacing="0" width="100%">
<tr>
<td>
<div>
<p class="MsoNormal"><span>Residual</span></p>
<p class="MsoNormal"><span>&nbsp;</span></p>
</div>
</td>
</tr>
</table>
<table cellpadding="0" cellspacing="0" width="100%">
<tr>
<td>
<div>
<p class="MsoNormal"><span>Risk</span></p>
</div>
</td>
</tr>
</table>
<table cellpadding="0" cellspacing="0" width="100%">
<tr>
<td>
<div>
<p class="MsoNormal"><span>Action</span></p>
<p class="MsoNormal"><span>&nbsp;</span></p>
</div>
</td>
</tr>
</table>
<table cellpadding="0" cellspacing="0" width="100%">
<tr>
<td>
<div>
<p class="MsoNormal"><span><span>  </span>Plan</span></p>
</div>
</td>
</tr>
</table>
<p>                                                                                                                                                  <!--[if !vml]--><br />
<!--[endif]--></span><!--[if mso &amp; !supportInlineShapes &amp; supportFields]&gt;<span>   <span></span></span>&#8211;><span></span></p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/sas-70/risk-assessments-and-the-sas-70-audit/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Is pre-boot authentication required? SAS70</title>
		<link>http://itknowledgeexchange.techtarget.com/sas-70/is-pre-boot-authentication-required-sas70/</link>
		<comments>http://itknowledgeexchange.techtarget.com/sas-70/is-pre-boot-authentication-required-sas70/#comments</comments>
		<pubDate>Wed, 20 Aug 2008 04:26:41 +0000</pubDate>
		<dc:creator>SAS70ExPERT</dc:creator>
				<category><![CDATA[Access]]></category>
		<category><![CDATA[Access control]]></category>
		<category><![CDATA[Management]]></category>
		<category><![CDATA[Network]]></category>
		<category><![CDATA[SAS 70]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/sas-70/is-pre-boot-authentication-required-sas70/</guid>
		<description><![CDATA[SAS 70 audits review the authentication procedures required to access computer equipment, including the pre-boot authentication (PBA) procedure.  If pre-boot authentication is not required, then the risks of gaining access to your Company data is very high. What is PBA? Pre-boot authentication is a process that requires a user to authenticate to the operating system [...]]]></description>
				<content:encoded><![CDATA[<p>SAS 70 audits review the authentication procedures required to access computer equipment, including the pre-boot authentication (PBA) procedure.  If pre-boot authentication is not required, then the risks of gaining access to your Company data is very high.</p>
<p>What is PBA? Pre-boot authentication is a process that requires a user to authenticate to the operating system prior to loading of the application software. The user must enter his credentials &#8211; a username and password before the system load begins. Once authenticated, then Windows or Linux operating system is loaded. If the correct user name and password are not entered, the pre-boot authentication process will not load the operating system and the computer will lock down.</p>
<p>Pre-boot authentication prevents a criminal hacker from gaining access to your data by not loading the operating system. Since the bypass tools load after the operating system, then a hacker want get a chance to try to gain entry or use the Windows XP or Vista emergency disks.  SAS70ExPERT@gmail.com</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/sas-70/is-pre-boot-authentication-required-sas70/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Face up to Biometrics for your SAS70 audit (SAS 70)</title>
		<link>http://itknowledgeexchange.techtarget.com/sas-70/face-up-to-biometrics-for-your-sas70-audit-sas-70/</link>
		<comments>http://itknowledgeexchange.techtarget.com/sas-70/face-up-to-biometrics-for-your-sas70-audit-sas-70/#comments</comments>
		<pubDate>Wed, 06 Aug 2008 18:35:21 +0000</pubDate>
		<dc:creator>SAS70ExPERT</dc:creator>
				<category><![CDATA[Access]]></category>
		<category><![CDATA[Access control]]></category>
		<category><![CDATA[Auditing]]></category>
		<category><![CDATA[CIO]]></category>
		<category><![CDATA[Compliance]]></category>
		<category><![CDATA[DataCenter]]></category>
		<category><![CDATA[Identity & Access Management]]></category>
		<category><![CDATA[SAS 70]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Security management]]></category>
		<category><![CDATA[Security Program Management]]></category>
		<category><![CDATA[Security tokens]]></category>
		<category><![CDATA[Third-party services]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/sas-70/face-up-to-biometrics-for-your-sas70-audit-sas-70/</guid>
		<description><![CDATA[Biometric systems are used today not only at your Data center/ co-location facility, but for plain ole’ laptop access. Finger, hand and thumb prints provide you access to all your critical data. In addition, iris/retinal scans and other facial recognition scans provide the credentials required to prevent forgery. What are you using within your Company? [...]]]></description>
				<content:encoded><![CDATA[<p><!--[if gte mso 9]&gt;     Normal   0         false   false   false                             MicrosoftInternetExplorer4   --><!--[if gte mso 9]&gt;     --><!--[if !mso]&gt;  st1\:*{behavior:url(#ieooui) }  --> <!--  /* Font Definitions */  @font-face 	{font-family:CenturyGothic; 	panose-1:0 0 0 0 0 0 0 0 0 0; 	mso-font-charset:0; 	mso-generic-font-family:auto; 	mso-font-format:other; 	mso-font-pitch:auto; 	mso-font-signature:3 0 0 0 1 0;}  /* Style Definitions */  p.MsoNormal, li.MsoNormal, div.MsoNormal 	{mso-style-parent:""; 	margin:0in; 	margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:12.0pt; 	font-family:"Times New Roman"; 	mso-fareast-font-family:"Times New Roman";} @page Section1 	{size:8.5in 11.0in; 	margin:1.0in 1.25in 1.0in 1.25in; 	mso-header-margin:.5in; 	mso-footer-margin:.5in; 	mso-paper-source:0;} div.Section1 	{page:Section1;}  /* List Definitions */  @list l0 	{mso-list-id:1407458705; 	mso-list-type:hybrid; 	mso-list-template-ids:708475470 67698705 67698713 67698715 67698703 67698713 67698715 67698703 67698713 67698715;} @list l0:level1 	{mso-level-text:"%1\)"; 	mso-level-tab-stop:.5in; 	mso-level-number-position:left; 	text-indent:-.25in;} ol 	{margin-bottom:0in;} ul 	{margin-bottom:0in;} --> <!--[if gte mso 10]&gt;   /* Style Definitions */  table.MsoNormalTable 	{mso-style-name:"Table Normal"; 	mso-tstyle-rowband-size:0; 	mso-tstyle-colband-size:0; 	mso-style-noshow:yes; 	mso-style-parent:""; 	mso-padding-alt:0in 5.4pt 0in 5.4pt; 	mso-para-margin:0in; 	mso-para-margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:10.0pt; 	font-family:"Times New Roman"; 	mso-ansi-language:#0400; 	mso-fareast-language:#0400; 	mso-bidi-language:#0400;}  --><span>Biometric systems are used today not only at your Data center/ co-location facility, but for plain ole’ laptop access. Finger, hand and thumb prints provide you access to all your critical data. In addition, iris/retinal scans and other facial recognition scans provide the credentials required to prevent forgery. What are you using within your Company? </span></p>
<p class="MsoNormal"><span> </span></p>
<p class="MsoNormal"><span>For a SAS 70 audit, critical areas to review related to biometrics are:</span></p>
<p class="MsoNormal"><!--[if !supportLists]--><span><span>1)<span>       </span></span></span><!--[endif]--><span>enrollment process for a new user</span></p>
<p class="MsoNormal"><!--[if !supportLists]--><span><span>2)<span>       </span></span></span><!--[endif]--><span>accuracy and monitoring of the biometric device</span></p>
<p class="MsoNormal"><!--[if !supportLists]--><span><span>3)<span>       </span></span></span><!--[endif]--><span>termination of users</span></p>
<p class="MsoNormal"><span> </span></p>
<p class="MsoNormal"><span>During enrollment, an individual’s biometric template is created in a database. Make sure you have a documented process for adding and authorizing new users to the database. You must know who may authorize access, and how much access to give the new employee. <span> </span></span></p>
<p class="MsoNormal"><span> </span></p>
<p class="MsoNormal"><span>Determine the accuracy and monitoring of biometric usage. Review who has used the biometric device, by reviewing the logs an identifying any unusual activity. For example, if you note that Bob has entered the facility 3 times and there is no exit<span>  </span>– then your device may not be working properly.</span></p>
<p class="MsoNormal"><span> </span></p>
<p class="MsoNormal"><span>Last, if Adam quits or Alice is fired, then how do you know to delete her credentials from the system? Make sure Human Resources has a policy to notify you immediately when a person needs to be removed from the system. IT should have a checklist of items/inventory to be returned when employee exits and the form should include a sign-off to indicate removal from the biometric device. Sas70expert@gmail.com</span></p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/sas-70/face-up-to-biometrics-for-your-sas70-audit-sas-70/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How laptops become serial killers?  &#8211; SAS70</title>
		<link>http://itknowledgeexchange.techtarget.com/sas-70/how-laptops-become-serial-killers-sas70/</link>
		<comments>http://itknowledgeexchange.techtarget.com/sas-70/how-laptops-become-serial-killers-sas70/#comments</comments>
		<pubDate>Sun, 06 Jul 2008 16:18:05 +0000</pubDate>
		<dc:creator>SAS70ExPERT</dc:creator>
				<category><![CDATA[Access]]></category>
		<category><![CDATA[Access control]]></category>
		<category><![CDATA[Administration]]></category>
		<category><![CDATA[Auditing]]></category>
		<category><![CDATA[CFO]]></category>
		<category><![CDATA[CIO]]></category>
		<category><![CDATA[Compliance]]></category>
		<category><![CDATA[CSO]]></category>
		<category><![CDATA[DataCenter]]></category>
		<category><![CDATA[human factors]]></category>
		<category><![CDATA[Information risk management]]></category>
		<category><![CDATA[Management]]></category>
		<category><![CDATA[Monitoring]]></category>
		<category><![CDATA[Network]]></category>
		<category><![CDATA[Network Management Systems]]></category>
		<category><![CDATA[Risk management]]></category>
		<category><![CDATA[SAS 70]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Security management]]></category>
		<category><![CDATA[Security Program Management]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/sas-70/how-laptops-become-serial-killers-sas70/</guid>
		<description><![CDATA[My business requires distribution and collection of data. Much of it resides on a centrally located server; however, there is data on the laptop that has never been transferred over to the server or that may have  been taken off the server for project work. As human beings we will never be perfect. Someone will [...]]]></description>
				<content:encoded><![CDATA[<p><!--[if gte mso 9]&gt;     Normal   0         false   false   false                             MicrosoftInternetExplorer4   --><!--[if gte mso 9]&gt;     --> <!--  /* Style Definitions */  p.MsoNormal, li.MsoNormal, div.MsoNormal 	{mso-style-parent:""; 	margin:0in; 	margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:12.0pt; 	font-family:"Times New Roman"; 	mso-fareast-font-family:"Times New Roman";} @page Section1 	{size:8.5in 11.0in; 	margin:1.0in 1.25in 1.0in 1.25in; 	mso-header-margin:.5in; 	mso-footer-margin:.5in; 	mso-paper-source:0;} div.Section1 	{page:Section1;} --> <!--[if gte mso 10]&gt;   /* Style Definitions */  table.MsoNormalTable 	{mso-style-name:"Table Normal"; 	mso-tstyle-rowband-size:0; 	mso-tstyle-colband-size:0; 	mso-style-noshow:yes; 	mso-style-parent:""; 	mso-padding-alt:0in 5.4pt 0in 5.4pt; 	mso-para-margin:0in; 	mso-para-margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:10.0pt; 	font-family:"Times New Roman"; 	mso-ansi-language:#0400; 	mso-fareast-language:#0400; 	mso-bidi-language:#0400;}  --></p>
<p class="MsoNormal">My business requires distribution and collection of data. Much of it resides on a centrally located server; however, there is data on the laptop that has never been transferred over to the server or that may have  been taken off the server for project work. As human beings we will never be perfect. Someone will lend access to their laptop to a friend or customer, a laptop will be lost or stolen, and an unprotected USB drive is a loaded gun just waiting to have the trigger pulled so that data can be transferred off your laptop. Laptops with sensitive data that goes unprotected, can become a media nightmare, a legal hassle and a may limit your customer retention and market growth &#8212; a serial killer that stops your business growth and the vendors that support you.</p>
<p class="MsoNormal">&nbsp;</p>
<p class="MsoNormal"> To protect data loss, we now have L0-jack services for laptops when they are stolen. The laptop can be found and once connected to a network will be shut down.But what about the ease we have to install and transfer data to others using USB drives. Even if you use a USB drive that requires a password, is that enough security? I have read recently that laptops were returned after being lost that contained sensitive data such as social security numbers for big companies – including Google. Now that they have the laptop back, is the risk over? What if the data was transferred off the laptop onto a USB drive?</p>
<p class="MsoNormal"> </p>
<p class="MsoNormal">Just like for the SAS70 audit, you have to perform a risk assessment to determine the controls that must be in place, and identify those that can be implemented as time permits. In the situation above, I don’t think focusing on the number of ways that data can be taken off laptops is the key to reducing risk. You should focus more on identifying the type of data that you have, mark the sensitive data, and control access to it – by limiting users, strengthening laptop controls around the sensitive data, and identifying opportunities to record transfer of sensitive data <span></span>which would provide an audit trail. How are you controlling your data on your laptops? sas70expert@gmail.com</p>
<p class="MsoNormal"> </p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/sas-70/how-laptops-become-serial-killers-sas70/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>To IM or not to IM is the question? – SAS70</title>
		<link>http://itknowledgeexchange.techtarget.com/sas-70/to-im-or-not-to-im-is-the-question-%e2%80%93-sas70/</link>
		<comments>http://itknowledgeexchange.techtarget.com/sas-70/to-im-or-not-to-im-is-the-question-%e2%80%93-sas70/#comments</comments>
		<pubDate>Fri, 04 Jul 2008 12:30:30 +0000</pubDate>
		<dc:creator>SAS70ExPERT</dc:creator>
				<category><![CDATA[Access]]></category>
		<category><![CDATA[Administration]]></category>
		<category><![CDATA[Auditing]]></category>
		<category><![CDATA[CEO]]></category>
		<category><![CDATA[CFO]]></category>
		<category><![CDATA[CIO]]></category>
		<category><![CDATA[Compliance]]></category>
		<category><![CDATA[DataCenter]]></category>
		<category><![CDATA[Information risk management]]></category>
		<category><![CDATA[Intrustion management]]></category>
		<category><![CDATA[Network]]></category>
		<category><![CDATA[Network monitoring]]></category>
		<category><![CDATA[Network security]]></category>
		<category><![CDATA[SAS 70]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Security management]]></category>
		<category><![CDATA[Third-party services]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/sas-70/to-im-or-not-to-im-is-the-question-%e2%80%93-sas70/</guid>
		<description><![CDATA[Yahoo Messenger, Googletalk, and AIM Messenger instant messaging services are frequently used by employees today for work and social networking. Less than 10% of companies today have policies and those that do have policies do not enforce them. Many SAS70 audits find installation of instant messaging software within corporate environments and that it may cause [...]]]></description>
				<content:encoded><![CDATA[<p><!--[if gte mso 9]&gt;     Normal   0         false   false   false                             MicrosoftInternetExplorer4   --><!--[if gte mso 9]&gt;     --> <!--  /* Style Definitions */  p.MsoNormal, li.MsoNormal, div.MsoNormal 	{mso-style-parent:""; 	margin:0in; 	margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:12.0pt; 	font-family:"Times New Roman"; 	mso-fareast-font-family:"Times New Roman";} @page Section1 	{size:8.5in 11.0in; 	margin:1.0in 1.25in 1.0in 1.25in; 	mso-header-margin:.5in; 	mso-footer-margin:.5in; 	mso-paper-source:0;} div.Section1 	{page:Section1;} --> <!--[if gte mso 10]&gt;   /* Style Definitions */  table.MsoNormalTable 	{mso-style-name:"Table Normal"; 	mso-tstyle-rowband-size:0; 	mso-tstyle-colband-size:0; 	mso-style-noshow:yes; 	mso-style-parent:""; 	mso-padding-alt:0in 5.4pt 0in 5.4pt; 	mso-para-margin:0in; 	mso-para-margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:10.0pt; 	font-family:"Times New Roman"; 	mso-ansi-language:#0400; 	mso-fareast-language:#0400; 	mso-bidi-language:#0400;}  --></p>
<p class="MsoNormal">Yahoo Messenger, Googletalk, and AIM Messenger instant messaging services are frequently used by employees today for work and social networking. Less than 10% of companies today have policies and those that do have policies do not enforce them. Many SAS70 audits find installation of instant messaging software within corporate environments and that it may cause introduction of malicious coding or cause loss of sensitive data. Therefore, should IM security software be standard installation – whether in the form of email and internet security tools, appliances, or third-party hosted solutions. IM security software would protect against incoming Trojan horses/viruses and detect outgoing data loss by using content filtering; logging and archiving all IM messages, and ensure compliance with company policy. Are you using IM security software protection? If so, which one and is it on a third-party hosted platform? Have you found it to be effective?sas70expert@gmail.com</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/sas-70/to-im-or-not-to-im-is-the-question-%e2%80%93-sas70/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Do you need the Secret Service to guard your data? – SAS70</title>
		<link>http://itknowledgeexchange.techtarget.com/sas-70/do-you-need-the-secret-service-to-guard-your-data-%e2%80%93-sas70/</link>
		<comments>http://itknowledgeexchange.techtarget.com/sas-70/do-you-need-the-secret-service-to-guard-your-data-%e2%80%93-sas70/#comments</comments>
		<pubDate>Tue, 01 Jul 2008 17:45:52 +0000</pubDate>
		<dc:creator>SAS70ExPERT</dc:creator>
				<category><![CDATA[Access]]></category>
		<category><![CDATA[Access control]]></category>
		<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[Administration]]></category>
		<category><![CDATA[Backup]]></category>
		<category><![CDATA[Backup & recovery]]></category>
		<category><![CDATA[budget]]></category>
		<category><![CDATA[bugeting]]></category>
		<category><![CDATA[business/IT alignment]]></category>
		<category><![CDATA[CEO]]></category>
		<category><![CDATA[CFO]]></category>
		<category><![CDATA[CIO]]></category>
		<category><![CDATA[cooling systems]]></category>
		<category><![CDATA[CSO]]></category>
		<category><![CDATA[Data center design]]></category>
		<category><![CDATA[Data center operations]]></category>
		<category><![CDATA[Database]]></category>
		<category><![CDATA[Database issues]]></category>
		<category><![CDATA[Database Management Systems]]></category>
		<category><![CDATA[DataCenter]]></category>
		<category><![CDATA[DataManagement]]></category>
		<category><![CDATA[Disaster Recovery]]></category>
		<category><![CDATA[Exchange]]></category>
		<category><![CDATA[Financials]]></category>
		<category><![CDATA[FTP]]></category>
		<category><![CDATA[human factors]]></category>
		<category><![CDATA[Industry Solutions]]></category>
		<category><![CDATA[Information risk management]]></category>
		<category><![CDATA[Management]]></category>
		<category><![CDATA[management software]]></category>
		<category><![CDATA[Microsoft Windows]]></category>
		<category><![CDATA[Network]]></category>
		<category><![CDATA[Network Management Systems]]></category>
		<category><![CDATA[Network monitoring]]></category>
		<category><![CDATA[Network security]]></category>
		<category><![CDATA[Networking]]></category>
		<category><![CDATA[power systems]]></category>
		<category><![CDATA[Risk management]]></category>
		<category><![CDATA[SAS 70]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Security management]]></category>
		<category><![CDATA[Security Program Management]]></category>
		<category><![CDATA[Servers]]></category>
		<category><![CDATA[Single sign-on]]></category>
		<category><![CDATA[Storage]]></category>
		<category><![CDATA[Third-party services]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/sas-70/do-you-need-the-secret-service-to-guard-your-data-%e2%80%93-sas70/</guid>
		<description><![CDATA[It’s election year and security to protect some of our most valuable assets is being discussed more frequently – including politicians and data privacy requirements (proposed Regulation S-P). Does that mean you should be considering the Secret Service to guard your data? I don’t think so; however, you should have a plan to manage risk [...]]]></description>
				<content:encoded><![CDATA[<p><!--[if gte mso 9]&gt;     Normal   0         false   false   false                             MicrosoftInternetExplorer4   --><!--[if gte mso 9]&gt;     --> <!--  /* Style Definitions */  p.MsoNormal, li.MsoNormal, div.MsoNormal 	{mso-style-parent:""; 	margin:0in; 	margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:12.0pt; 	font-family:"Times New Roman"; 	mso-fareast-font-family:"Times New Roman";} @page Section1 	{size:8.5in 11.0in; 	margin:1.0in 1.25in 1.0in 1.25in; 	mso-header-margin:.5in; 	mso-footer-margin:.5in; 	mso-paper-source:0;} div.Section1 	{page:Section1;} --> <!--[if gte mso 10]&gt;   /* Style Definitions */  table.MsoNormalTable 	{mso-style-name:"Table Normal"; 	mso-tstyle-rowband-size:0; 	mso-tstyle-colband-size:0; 	mso-style-noshow:yes; 	mso-style-parent:""; 	mso-padding-alt:0in 5.4pt 0in 5.4pt; 	mso-para-margin:0in; 	mso-para-margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:10.0pt; 	font-family:"Times New Roman"; 	mso-ansi-language:#0400; 	mso-fareast-language:#0400; 	mso-bidi-language:#0400;}  --></p>
<p class="MsoNormal">It’s election year and security to protect some of our most valuable assets is being discussed more frequently – including politicians and data privacy requirements (proposed Regulation S-P). Does that mean you should be considering the Secret Service to guard your data? I don’t think so; however, you should have a plan to manage risk of data loss. This plan should contain proactive thinking that promotes a culture of prevention. A SAS70 audit will assist you in determining your vulnerabilities and identifying weaknesses in information technology network; however, you must continually assess and evaluate scenarios, and stay informed of the latest and greatest networking threats. Communication and training are key to a data protection plan. What are some of the other characteristics?SAS70expert@gmail.com</p>
<p class="MsoNormal"> </p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/sas-70/do-you-need-the-secret-service-to-guard-your-data-%e2%80%93-sas70/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What’s your data loss prevention strategy? – SAS70</title>
		<link>http://itknowledgeexchange.techtarget.com/sas-70/what%e2%80%99s-your-data-loss-prevention-strategy-%e2%80%93-sas70/</link>
		<comments>http://itknowledgeexchange.techtarget.com/sas-70/what%e2%80%99s-your-data-loss-prevention-strategy-%e2%80%93-sas70/#comments</comments>
		<pubDate>Thu, 26 Jun 2008 04:30:32 +0000</pubDate>
		<dc:creator>SAS70ExPERT</dc:creator>
				<category><![CDATA[Access]]></category>
		<category><![CDATA[Access control]]></category>
		<category><![CDATA[Auditing]]></category>
		<category><![CDATA[business/IT alignment]]></category>
		<category><![CDATA[CEO]]></category>
		<category><![CDATA[CFO]]></category>
		<category><![CDATA[CIO]]></category>
		<category><![CDATA[Compliance]]></category>
		<category><![CDATA[Configuration]]></category>
		<category><![CDATA[CSO]]></category>
		<category><![CDATA[Data center design]]></category>
		<category><![CDATA[Database]]></category>
		<category><![CDATA[Database issues]]></category>
		<category><![CDATA[Database Management Systems]]></category>
		<category><![CDATA[DataCenter]]></category>
		<category><![CDATA[DataManagement]]></category>
		<category><![CDATA[Firewalls]]></category>
		<category><![CDATA[Identity & Access Management]]></category>
		<category><![CDATA[Incident response]]></category>
		<category><![CDATA[Information risk management]]></category>
		<category><![CDATA[Intrustion management]]></category>
		<category><![CDATA[Management]]></category>
		<category><![CDATA[management software]]></category>
		<category><![CDATA[Monitoring]]></category>
		<category><![CDATA[Network]]></category>
		<category><![CDATA[Network Management Systems]]></category>
		<category><![CDATA[Network monitoring]]></category>
		<category><![CDATA[Network security]]></category>
		<category><![CDATA[Networking]]></category>
		<category><![CDATA[Patch management]]></category>
		<category><![CDATA[patching]]></category>
		<category><![CDATA[router configuration]]></category>
		<category><![CDATA[routers]]></category>
		<category><![CDATA[SAS 70]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Security management]]></category>
		<category><![CDATA[Security Program Management]]></category>
		<category><![CDATA[Security tokens]]></category>
		<category><![CDATA[Third-party services]]></category>
		<category><![CDATA[TrendMirco]]></category>
		<category><![CDATA[Viruses]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/sas-70/what%e2%80%99s-your-data-loss-prevention-strategy-%e2%80%93-sas70/</guid>
		<description><![CDATA[Are you reviewing you firewall rules quarterly? Have you implemented an (IDS) intrusion detection system? Are your routers set up to prevent unauthorized intruders? Do you have the latest and greatest virus protection? Are you performing a SAS70 audit every six months? Database security breaches are increasing daily and costing tremendous amounts of dollars that [...]]]></description>
				<content:encoded><![CDATA[<p><!--[if gte mso 9]&gt;     Normal   0         false   false   false                             MicrosoftInternetExplorer4   --><!--[if gte mso 9]&gt;     --> <!--  /* Style Definitions */  p.MsoNormal, li.MsoNormal, div.MsoNormal 	{mso-style-parent:""; 	margin:0in; 	margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:12.0pt; 	font-family:"Times New Roman"; 	mso-fareast-font-family:"Times New Roman";} a:link, span.MsoHyperlink 	{color:blue; 	text-decoration:underline; 	text-underline:single;} a:visited, span.MsoHyperlinkFollowed 	{color:purple; 	text-decoration:underline; 	text-underline:single;} @page Section1 	{size:8.5in 11.0in; 	margin:1.0in 1.25in 1.0in 1.25in; 	mso-header-margin:.5in; 	mso-footer-margin:.5in; 	mso-paper-source:0;} div.Section1 	{page:Section1;} --> <!--[if gte mso 10]&gt;   /* Style Definitions */  table.MsoNormalTable 	{mso-style-name:"Table Normal"; 	mso-tstyle-rowband-size:0; 	mso-tstyle-colband-size:0; 	mso-style-noshow:yes; 	mso-style-parent:""; 	mso-padding-alt:0in 5.4pt 0in 5.4pt; 	mso-para-margin:0in; 	mso-para-margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:10.0pt; 	font-family:"Times New Roman"; 	mso-ansi-language:#0400; 	mso-fareast-language:#0400; 	mso-bidi-language:#0400;}  --></p>
<p class="MsoNormal">Are you reviewing you firewall rules quarterly? Have you implemented an (IDS) intrusion detection system? Are your routers set up to prevent unauthorized intruders? Do you have the latest and greatest virus protection? Are you performing a SAS70 audit every six months? Database security breaches are increasing daily and costing tremendous amounts of dollars that should have been spent on IT projects. You should at least have an emergency plan in place when data loss occurs. Without an emergency plan in place, the breach could continue and the legal costs could continue to escalate.</p>
<p class="MsoNormal"> </p>
<p><span> <a href="http://itknowledgeexchange.techtarget.com/itanswers/tag/data-center-design/" title="Data center design (18)"><span></span></a></span><a href="http://itknowledgeexchange.techtarget.com/itanswers/tag/security-program-management/" title="Security Program Management (112)"><br />
</a></p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/sas-70/what%e2%80%99s-your-data-loss-prevention-strategy-%e2%80%93-sas70/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Which search engine owns you? Identity management is owned by whom? – SAS70</title>
		<link>http://itknowledgeexchange.techtarget.com/sas-70/which-search-engine-owns-you-identity-management-is-owned-by-whom-%e2%80%93-sas70/</link>
		<comments>http://itknowledgeexchange.techtarget.com/sas-70/which-search-engine-owns-you-identity-management-is-owned-by-whom-%e2%80%93-sas70/#comments</comments>
		<pubDate>Thu, 19 Jun 2008 14:28:09 +0000</pubDate>
		<dc:creator>SAS70ExPERT</dc:creator>
				<category><![CDATA[Access]]></category>
		<category><![CDATA[Access control]]></category>
		<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[Auditing]]></category>
		<category><![CDATA[CIO]]></category>
		<category><![CDATA[Compliance]]></category>
		<category><![CDATA[CSO]]></category>
		<category><![CDATA[DataCenter]]></category>
		<category><![CDATA[DataManagement]]></category>
		<category><![CDATA[Exchange]]></category>
		<category><![CDATA[Identity & Access Management]]></category>
		<category><![CDATA[Microsoft Windows]]></category>
		<category><![CDATA[SAS 70]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Single sign-on]]></category>
		<category><![CDATA[Third-party services]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/sas-70/which-search-engine-owns-you-identity-management-is-owned-by-whom-%e2%80%93-sas70/</guid>
		<description><![CDATA[ Is it Yahoo? Or Google? Or? Shouldn’t it be the individual consumer? Every time you register on a website to download a movie or order a box of nuts, that information is being recorded. Some websites don’t keep this information confidential; it becomes entrenched in the search engine optimization techniques used by search engines and [...]]]></description>
				<content:encoded><![CDATA[<p><!--[if gte mso 9]&gt;     Normal   0         false   false   false                             MicrosoftInternetExplorer4   --><!--[if gte mso 9]&gt;     --> <!--  /* Style Definitions */  p.MsoNormal, li.MsoNormal, div.MsoNormal 	{mso-style-parent:""; 	margin:0in; 	margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:12.0pt; 	font-family:"Times New Roman"; 	mso-fareast-font-family:"Times New Roman";} @page Section1 	{size:8.5in 11.0in; 	margin:1.0in 1.25in 1.0in 1.25in; 	mso-header-margin:.5in; 	mso-footer-margin:.5in; 	mso-paper-source:0;} div.Section1 	{page:Section1;} --> <!--[if gte mso 10]&gt;   /* Style Definitions */  table.MsoNormalTable 	{mso-style-name:"Table Normal"; 	mso-tstyle-rowband-size:0; 	mso-tstyle-colband-size:0; 	mso-style-noshow:yes; 	mso-style-parent:""; 	mso-padding-alt:0in 5.4pt 0in 5.4pt; 	mso-para-margin:0in; 	mso-para-margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:10.0pt; 	font-family:"Times New Roman"; 	mso-ansi-language:#0400; 	mso-fareast-language:#0400; 	mso-bidi-language:#0400;}  --></p>
<p class="MsoNormal"><span> </span>Is it Yahoo? Or Google? Or? Shouldn’t it be the individual consumer? Every time you register on a website to download a movie or order a box of nuts, that information is being recorded. Some websites don’t keep this information confidential; it becomes entrenched in the search engine optimization techniques used by search engines and your name, address, and phone number may be appearing in random searches by someone in the Antarctic.</p>
<p class="MsoNormal"> </p>
<p class="MsoNormal">Without additional privacy legislation and SAS70 audits, your personal information may not be so personal anymore. Currently, if your personal information is leaked to the public, Companies only have to inform you of the data breach, and get you a credit monitoring service. Does this<span>  </span>seem fair? Should you have a single signon that is secure and corruption is preventable?</p>
<p class="MsoNormal">&nbsp;</p>
<p class="MsoNormal">&nbsp;</p>
<p class="MsoNormal"> </p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/sas-70/which-search-engine-owns-you-identity-management-is-owned-by-whom-%e2%80%93-sas70/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
