Auditing archives - SAS 70

SAS 70:

Auditing

Nov 30 2008   8:39PM GMT

What cabinet position would you want to be elected too? SAS 70



Posted by: sas70expert
Management, Auditing, SAS 70

As we begin a new election process, our President is currently in the process of deciding who will fill cabinet level positions. Some bring foreign prestige, such as Secretary of State, and others focus more on domestic issues, such as Secretary of Treasury. Any of these positions will require persons with decisions making ability and new imaginative ideas to manage our growing economy. If I were Director of Office and Management and Budget, I would want to quickly define requirements to manage any new economic stimulus packages. SAS 70 audits would be a requirement that would be enclosed in any new legislation.

 

If the Federal Government and Warren Buffett is going to own much of our economy, how can we be sure that the financial transactions are processed correctly and that our personal data is kept safe? Yes! SAS 70 audits can fulfill that role.

 

Currently, we are dishing out funds at record pace. Sometimes {sarcastically}, I wonder why don’t we give every American a printer, and tell them to print only what they need. As a taxpayer, I don’t have any idea what my return on this investment will be. When you purchase Coca-Cola stock, I know what their dividend will be? What is our return on our investment in Citigroup and AIG?

AS 70 audits must become a fundamental requirement for almost any service organization to conduct business with the Federal Government. Do you agree?  Trackback URL

AddThis Social Bookmark Button     0 Comments     RSS Feed     Email a friend

Oct 21 2008   12:07AM GMT

Access Rights and SAS70 audit



Posted by: sas70expert
Third-party services, Auditing, Access, Access control, SAS 70

Access rights for current employees are essential for the completion of a successful audit. Your company should have a hiring and firing policy that is followed to the letter of the law. When an employee is hired or fired they should have an authorization process to add or delete from company systems or applications. It is essential that you educate your current employees, contractors, an third party users on this process on a continual basis.

 

Your company should company not only operating systems or applications, but physical access to company assets. Shared passwords or usernames should be immediately deactivated once an employee or third party leaves. When developing a policy for hiring or terminating consider:

 

1.       whether the termination or change of employment will be initiated by your or a third party

2.       the current responsibilities of the employee

3.       the value of the company assets or data that the employee has access too.

 

Without a good termination policy or checklist, you will have exceptions within your SAS 70 audit.   

AddThis Social Bookmark Button     0 Comments     RSS Feed     Email a friend


Sep 21 2008   9:22PM GMT

Security is essential for all new technology investments? SAS70



Posted by: sas70expert
Security management, Third-party services, Management, Auditing, Network, SAS 70

Which new technologies are you adopting? With Web 2.0, social networking, wikis, and blogs – oh mY! With so many new avenues to penetrate your market, the decisions you make today can effect the success of your SAS 70 audit. When evaluating new technology, always first determine your company objectives as we previously discussed. In addition, you will need to remember to consider what new security features must be implemented in your computing environment to prevent downtime. It is essential early in the process that you identify the threats, the risks, and then create a plan.

 

 In identifying threats, the assessment team must consider who or what could compromise a target system’s components such that the system’s security attributes would be jeopardized. You should focus on how the information assets and components differ from what you already have. In identifying the security risks, consider what will th total potential impact on the organization. When your system is compromised – and it will be – how would you handle the loss of critical data?

 

To address technology security risks, requires a documented plan and you must train your employees on how to enact the plan. The SAS70 audit will require you to have a plan in place and it will examine who are the participants in the plan. The plan should include not only IT, but operations and senior management. Where is your security plan?  Trackback URL

AddThis Social Bookmark Button     1 Comment     RSS Feed     Email a friend


Sep 17 2008   3:35PM GMT

Risk Assessments and the SAS 70 audit



Posted by: sas70expert
Management, Risk management, Auditing, Monitoring, Access, Network, CIO, COBIT, SAS 70

Management’s risk assessment process is required to be audited in a SAS70 examination; however, in my experience, most auditors do not adequately review Management’s risk assessment process. Without adequate auditing experience, most auditors would not have a basis to determine if Management had reviewed the control risk universe. In addition, Management mostly does not formally document risks, but they are discussed only in Board meeting with among C-level executive’s. The COBIT risk assessment framework can provide Management with the criteria and the details that an inexperienced auditor may use as a guide to examine their risk assessment process

 

COBIT consists of information that is required to help achieve business objectives. You must first begin with a vulnerability analysis of your business operations. Then determine the threats to these vulnerabilities For example, your greatest risk may be related to the legal liabilities due to incorrect financial statements….. or something more simpler, like loss of a backup tape which contained your customers social security numbers. Third, determine the impact of this threat. Is it a million dollar monetary fine, or could your license to conduct business be taken away. The conclusion is an action plan after which the cycle can start again.

 

When the SAS 70 auditor discusses your risk assessment process, don’t be afraid to say that you have it all stored in your brain. Without risk documentation, an experience auditing firm will assist you in forming a roadmap of risks that lead to your business success. Mr. CIO, have you determine what are your business risks or your information technology risks today? Have you formally discussed and evaluated them with other c-level executives or with your peers and association’s within your industry. Note from the diagram below the a formal risk assessment process. Next time we will discuss each of these layers in detail. SAS70ExPERT@gmail.com

 

Asset

Identification

and Valuation

Vulnerability

 

 Assessment

   Threat

 

Assessment

    Risk

 

Assessment

 Counter-

 

 measures

 Control

 

Evaluation

Residual

 

Risk

Action

 

  Plan



Sep 14 2008   11:17PM GMT

Encrypting for Security - SAS70



Posted by: sas70expert
Uncategorized, Networking, Network monitoring, Identity & Access Management, routers, Security Program Management, Encryption, Auditing, Development, Network

SAS 70 audits review the not only the security of your networks but of the data that is transported across your networks and on the security of your data that remains on your servers and laptops. Before choosing an encryption vendor, there are factors you consider:

  • What administrative actions are required? Can keys be changed and modified by the user or does your network administrator have to take action? What if the key is compromised, can it be changed at will? If the key is changed, how do you remember it?
  • What steps are taken to manage keys? Are keys kept in a secure database or are they managed individually? Independent solutions allow you more flexibility, but independent users may not always follow the company standards which may give hackers an opportunity.
  • Are multiple keys supported and can you create a master? The more critical and sensitive the data, the tougher the key should be crack. 
  • Is there PKI in corporation? Does the encryption product integrate with an existing PKI production ro des it require software in order to function? Any vendor solution should be able too.  Trackback URL
AddThis Social Bookmark Button     0 Comments     RSS Feed     Email a friend


Sep 12 2008   5:17AM GMT

CIO’s deserve respect? Are you respectable and what are these characteristics? SAS70



Posted by: sas70expert
Compliance, Auditing, Network, CIO, SAS 70, CSO

SAS 70 audits focus on COSO controls and examine the leadership experience of executives and training. CIO’s and CSO’s march to the executive suite takes many paths. Opportunities to lead in the C-Level suite come in many forms….some are perhaps luck, others are from angels, but what job titles lead to the CIO or CSO role? According to a recent survey, most CIO’s have a background primarily in IT. In recent, weeks, I have begun to question this polling as I have met several well-respected CIO’s who understand strategy and operations, but do not have a clue as to operating systems, applications or how networks function. In this same poll, only 15% of CIO’s and CSO’ came from areas outside of IT. What side of the fence do you stand on? Do you think an extensive background and training in information technology makes a difference as a c-level executive? As I consider myself a hybrid with a little knowledge and experience on both sides of the fence, I wonder what is respectable?  Trackback URL

AddThis Social Bookmark Button     0 Comments     RSS Feed     Email a friend


Sep 10 2008   12:16AM GMT

11th Commandment - Thou shalt perform the data backup process. – SAS70



Posted by: sas70expert
Management, Compliance, Auditing, Backup, SAS 70

It’s Monday at 9am, Your server data has been lost. You ask for the backup tape to perform the restore and determine that Friday night backup process failed. You don’t want to start the week off by committing such a sin as to not follow the 11th commandment. The backup data process must occur according to your company schedule and any identified failures should be noted and resolved. In addition, don’t make the mistake of keeping your backup tape on-site. A SAS70 audit that focuses on computer operations will examine your processes to confirm that you are adequately performing data backups. The SAS 70 audit will monitor your compliance with your Company policy – are you required to perform full or incremental backups? How do you know that your backup process was successful? A daily log should be received to indicate which file directories and files were backed up and if it was successful. In addition, your backup software should perform a verification process. When an auditor performs the SAS70 audit, one of the common mistakes by the Management is to forget to review the backup log. Who is in charge of your backup process?  SAS70ExPERT at gmail.com


Sep 8 2008   1:35PM GMT

Successful traits of a CIO equal successful SAS70 audits (Part 6) – SAS 70



Posted by: sas70expert
Compliance, Auditing, CIO, SAS 70

Shazzam!!! Clap on, Clap off!!  None of these sayings work to build a strong team for a CIO. An effective CIO must work daily to build trust and a strong bond between his employees.

 

A SAS70 audit will examine the processes used by a CIO to hire and monitor his employees. A CIO that requires new IT employees to complete an employment application, perform background checks and requires frequent employee evaluations will have a successful SAS70 audit. What are you doing within your Company to build a strong IT team?   

AddThis Social Bookmark Button     0 Comments     RSS Feed     Email a friend


Sep 5 2008   7:19AM GMT

Successful traits of a CIO equal successful SAS70 audits (Part 5) – SAS 70



Posted by: sas70expert
Security, Compliance, Auditing, Financials, Network, CIO, SAS 70

SAS 70 SAS70

Do you have 3 mainframes systems and one stand alone application that you use for recording financial results? Do any of these systems talk to one another? Are you starting to use Saas applications to better manage your data? Knowing how to leverage technologies, old or new, is key to being an effective CIO.

 

During a SAS70 audit, it is critical that you have an deep understanding of your systems and how they work together. If you are able to provide documentation, such as network diagrams, and data hierarchies to your auditor, then they will be more efficient when determining the controls necessary to be tested within your organization. An effective CIO cannot leverage technologies within corporate walls or as outsourced solutions without having a complete understanding of IT networks, applications, and operating systems. What helps you know how to leverage your company technologies? Or to predict what technologies will work best within your company?   

AddThis Social Bookmark Button     0 Comments     RSS Feed     Email a friend


Sep 2 2008   8:57PM GMT

Successful traits of a CIO equal successful SAS70 audits (Part 4) – SAS 70



Posted by: sas70expert
Compliance, Auditing, Financials, CIO, SAS 70, budget, bugeting

Budgets, financial statements, and account analysis all provide you with detailed information on the financial operations of your company. An effective CIO must have a good grasp of his Companies revenue and expenses and how this information flows into his IT operations.

 

If you are aware of the finances of your operation, then you will be able to understand the facets of the SAS70 audit that deal with the testing and examination of financial transactions. By understanding the processes that record financial transaction, an effective CIO will quickly be able to explain abnormal differences to an auditor. Do you have financial information required to manage your operations? Or are you still managing with an abacus? What types of reports are most effective for helping you guide your organization? Are you using balanced scorecards? Sas70expert@gmail.com