<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>SAS 70 &#187; Management</title>
	<atom:link href="http://itknowledgeexchange.techtarget.com/sas-70/tag/management/feed/" rel="self" type="application/rss+xml" />
	<link>http://itknowledgeexchange.techtarget.com/sas-70</link>
	<description></description>
	<lastBuildDate>Tue, 23 Dec 2008 17:58:25 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	
		<item>
		<title>Top 10 business risks in 2009 &#8211; SAS70</title>
		<link>http://itknowledgeexchange.techtarget.com/sas-70/top-10-business-risks-in-2009-sas70/</link>
		<comments>http://itknowledgeexchange.techtarget.com/sas-70/top-10-business-risks-in-2009-sas70/#comments</comments>
		<pubDate>Thu, 18 Dec 2008 21:15:02 +0000</pubDate>
		<dc:creator>SAS70ExPERT</dc:creator>
				<category><![CDATA[budget]]></category>
		<category><![CDATA[Management]]></category>
		<category><![CDATA[SAS 70]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/sas-70/top-10-business-risks-in-2009-sas70/</guid>
		<description><![CDATA[For 2009, Ernst and Young has compiled the top 10 business risks for your companies operations. As regulation and compliance is #2, SAS 70 audits should be a priority to complete in 2009. With the downturn in the economy, your controls should not be the first area to fall.  If you must conserve, turn to [...]]]></description>
				<content:encoded><![CDATA[<p>For 2009, Ernst and Young has compiled the top 10 business risks for your companies operations. As regulation and compliance is #2, SAS 70 audits should be a priority to complete in 2009.</p>
<p>With the downturn in the economy, your controls should not be the first area to fall.  If you must conserve, turn to green controls or automate your controls using technology. Develop a long-term relationship with a respectable IT auditor that has experience in your industry. There advice may cost upfront, but the potential revenue growth can be exponential.</p>
<p>Here are the risks:</p>
<ol>
<li><strong>The credit crunch.</strong> (Number 2 in the 2008 report.)</li>
<li> <strong>Regulation and compliance.</strong> (Number 1 last year.)</li>
<li> <strong>Deepening recession.</strong> (New this year)</li>
<li> <strong>Radical greening.</strong> (9)</li>
<li> <strong>Non-traditional entrants.</strong> (16)</li>
<li> <strong>Cost cutting.</strong> (8)</li>
<li> <strong><a href="http://businessfinancemag.com/article/top-10-business-risks-2009-1217#" id="KonaLink0" target="_top" class="rcLink"><font color="blue"><span class="rcLink">Managing</span></font></a> talent.</strong> (11)</li>
<li> <strong>Executing alliances and transactions.</strong> (7)</li>
<li> <strong>Business model redundancy.</strong> (New)</li>
<li> <strong>Reputation risks.</strong> (22)</li>
</ol>
<p>sas70expert@gmail.com</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/sas-70/top-10-business-risks-in-2009-sas70/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Third party services and SAS70 audit</title>
		<link>http://itknowledgeexchange.techtarget.com/sas-70/third-party-services-and-sas70-audit/</link>
		<comments>http://itknowledgeexchange.techtarget.com/sas-70/third-party-services-and-sas70-audit/#comments</comments>
		<pubDate>Tue, 09 Dec 2008 01:16:46 +0000</pubDate>
		<dc:creator>SAS70ExPERT</dc:creator>
				<category><![CDATA[Management]]></category>
		<category><![CDATA[SAS 70]]></category>
		<category><![CDATA[Third-party services]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/sas-70/third-party-services-and-sas70-audit/</guid>
		<description><![CDATA[During a SAS 70 audit, an auditor may examine any relationships with third parties.  Any third party agreements or service level agreements should contain:   1.       procedures to protect all outsourced data, applications or hardware 2.       a description of the services provided and the target level of services 3.       the establishment of an escalation process [...]]]></description>
				<content:encoded><![CDATA[<p><!--[if gte mso 9]&gt;     Normal   0         false   false   false                             MicrosoftInternetExplorer4   --><!--[if gte mso 9]&gt;     --> <!--  /* Font Definitions */  @font-face 	{font-family:Verdana; 	panose-1:2 11 6 4 3 5 4 4 2 4; 	mso-font-charset:0; 	mso-generic-font-family:swiss; 	mso-font-pitch:variable; 	mso-font-signature:536871559 0 0 0 415 0;}  /* Style Definitions */  p.MsoNormal, li.MsoNormal, div.MsoNormal 	{mso-style-parent:""; 	margin:0in; 	margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:12.0pt; 	font-family:"Times New Roman"; 	mso-fareast-font-family:"Times New Roman";} a:link, span.MsoHyperlink 	{color:blue; 	text-decoration:underline; 	text-underline:single;} a:visited, span.MsoHyperlinkFollowed 	{color:purple; 	text-decoration:underline; 	text-underline:single;} @page Section1 	{size:8.5in 11.0in; 	margin:1.0in 1.25in 1.0in 1.25in; 	mso-header-margin:.5in; 	mso-footer-margin:.5in; 	mso-paper-source:0;} div.Section1 	{page:Section1;}  /* List Definitions */  @list l0 	{mso-list-id:1011951001; 	mso-list-type:hybrid; 	mso-list-template-ids:777698078 67698703 67698713 67698715 67698703 67698713 67698715 67698703 67698713 67698715;} @list l0:level1 	{mso-level-tab-stop:.5in; 	mso-level-number-position:left; 	text-indent:-.25in;} ol 	{margin-bottom:0in;} ul 	{margin-bottom:0in;} --> <!--[if gte mso 10]&gt;   /* Style Definitions */  table.MsoNormalTable 	{mso-style-name:"Table Normal"; 	mso-tstyle-rowband-size:0; 	mso-tstyle-colband-size:0; 	mso-style-noshow:yes; 	mso-style-parent:""; 	mso-padding-alt:0in 5.4pt 0in 5.4pt; 	mso-para-margin:0in; 	mso-para-margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:10.0pt; 	font-family:"Times New Roman"; 	mso-ansi-language:#0400; 	mso-fareast-language:#0400; 	mso-bidi-language:#0400;}  --><em><span></span></em></p>
<p class="MsoNormal"><span>During a SAS 70 audit, an auditor may examine any relationships with third parties.<span>  </span>Any third party agreements or service level agreements should contain:</span></p>
<p class="MsoNormal"><span> </span></p>
<p class="MsoNormal"><!--[if !supportLists]--><span><span>1.<span>       </span></span></span><!--[endif]--><span>procedures to protect all outsourced data, applications or hardware</span></p>
<p class="MsoNormal"><!--[if !supportLists]--><span><span>2.<span>       </span></span></span><!--[endif]--><span>a description of the services provided and the target level of services</span></p>
<p class="MsoNormal"><!--[if !supportLists]--><span><span>3.<span>       </span></span></span><!--[endif]--><span>the establishment of an escalation process should an incident occur</span></p>
<p class="MsoNormal"><!--[if !supportLists]--><span><span>4.<span>       </span></span></span><!--[endif]--><span>the right to audit and determine that they are adhering to your agreement</span></p>
<p class="MsoNormal"><!--[if !supportLists]--><span><span>5.<span>       </span></span></span><!--[endif]--><span>the respective liabilities of both parties should an incident occur.</span></p>
<p class="MsoNormal"><span> </span></p>
<p class="MsoNormal"><span>During a SAS70 audit, you have a choice to exclude your outsourced services or include them in the examination. I would recommend you include them, especially if they are essential to the services you are providing to your customers. <a href="mailto:SAS70ExPERT@gmail.com">SAS70ExPERT@gmail.com</a></span></p>
<p class="MsoNormal"><span> </span></p>
<p class="MsoNormal"><em><span> </span></em></p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/sas-70/third-party-services-and-sas70-audit/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>IFRS and the new accounting guidelines? SAS 70</title>
		<link>http://itknowledgeexchange.techtarget.com/sas-70/ifrs-and-the-new-accounting-guidelines-sas-70/</link>
		<comments>http://itknowledgeexchange.techtarget.com/sas-70/ifrs-and-the-new-accounting-guidelines-sas-70/#comments</comments>
		<pubDate>Wed, 03 Dec 2008 16:52:59 +0000</pubDate>
		<dc:creator>SAS70ExPERT</dc:creator>
				<category><![CDATA[Management]]></category>
		<category><![CDATA[SAS 70]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/sas-70/ifrs-and-the-new-accounting-guidelines-sas-70/</guid>
		<description><![CDATA[Finally, international accounting standards are being implemented. Even though this will cause some upfront additional expense for companies to conform, in the long run, you will be better able to evaluate the financial stability of companies worldwide. Will this mean SAS 70 audit requirements will also be international?   In Canada currently they have similar [...]]]></description>
				<content:encoded><![CDATA[<p><!--[if gte mso 9]&gt;     Normal   0         false   false   false                             MicrosoftInternetExplorer4   --><!--[if gte mso 9]&gt;     --><!--[if !mso]&gt;  st1\:*{behavior:url(#ieooui) }  --> <!--  /* Style Definitions */  p.MsoNormal, li.MsoNormal, div.MsoNormal 	{mso-style-parent:""; 	margin:0in; 	margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:12.0pt; 	font-family:"Times New Roman"; 	mso-fareast-font-family:"Times New Roman";} @page Section1 	{size:8.5in 11.0in; 	margin:1.0in 1.25in 1.0in 1.25in; 	mso-header-margin:.5in; 	mso-footer-margin:.5in; 	mso-paper-source:0;} div.Section1 	{page:Section1;} --> <!--[if gte mso 10]&gt;   /* Style Definitions */  table.MsoNormalTable 	{mso-style-name:"Table Normal"; 	mso-tstyle-rowband-size:0; 	mso-tstyle-colband-size:0; 	mso-style-noshow:yes; 	mso-style-parent:""; 	mso-padding-alt:0in 5.4pt 0in 5.4pt; 	mso-para-margin:0in; 	mso-para-margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:10.0pt; 	font-family:"Times New Roman"; 	mso-ansi-language:#0400; 	mso-fareast-language:#0400; 	mso-bidi-language:#0400;}  --></p>
<p class="MsoNormal">Finally, international accounting standards are being implemented. Even though this will cause some upfront additional expense for companies to conform, in the long run, you will be better able to evaluate the financial stability of companies worldwide. Will this mean SAS 70 audit requirements will also be international?</p>
<p class="MsoNormal"> </p>
<p class="MsoNormal">In Canada currently they have similar SAS 70 audit legislation, but in Europe they do not. If America continues to outsource our financial, medical and application processing, don’t you think that European countries should have a SAS70 audit? If you bank at Citigroup, your help desk may reside in India. Without the SAS 70 audit standard being applied in India, will your financial data be safe? Someone could steal your identify and funds from a server in India; is there enough regulation to help you, especially when you need to purchase your Christmas gifts tomorrow?</p>
<p class="MsoNormal"> </p>
<p class="MsoNormal">As we continue to become a one-world economy, we must take fundamental steps to institute standards to protect our basic financial interests. This includes requiring a SAS 70 audit to be completed by all companies in any country that provides a service. Have you as a consumer requested to see your service providers SAS 70 audit today? Sas70expert@gmail.com</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/sas-70/ifrs-and-the-new-accounting-guidelines-sas-70/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What cabinet position would you want to be elected too? SAS 70</title>
		<link>http://itknowledgeexchange.techtarget.com/sas-70/what-cabinet-position-would-you-want-to-be-elected-too-sas-70/</link>
		<comments>http://itknowledgeexchange.techtarget.com/sas-70/what-cabinet-position-would-you-want-to-be-elected-too-sas-70/#comments</comments>
		<pubDate>Sun, 30 Nov 2008 20:39:11 +0000</pubDate>
		<dc:creator>SAS70ExPERT</dc:creator>
				<category><![CDATA[Auditing]]></category>
		<category><![CDATA[Management]]></category>
		<category><![CDATA[SAS 70]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/sas-70/what-cabinet-position-would-you-want-to-be-elected-too-sas-70/</guid>
		<description><![CDATA[As we begin a new election process, our President is currently in the process of deciding who will fill cabinet level positions. Some bring foreign prestige, such as Secretary of State, and others focus more on domestic issues, such as Secretary of Treasury. Any of these positions will require persons with decisions making ability and [...]]]></description>
				<content:encoded><![CDATA[<p><!--[if gte mso 9]&gt;     Normal   0         false   false   false                             MicrosoftInternetExplorer4   --><!--[if gte mso 9]&gt;     --> <!--  /* Style Definitions */  p.MsoNormal, li.MsoNormal, div.MsoNormal 	{mso-style-parent:""; 	margin:0in; 	margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:12.0pt; 	font-family:"Times New Roman"; 	mso-fareast-font-family:"Times New Roman";} @page Section1 	{size:8.5in 11.0in; 	margin:1.0in 1.25in 1.0in 1.25in; 	mso-header-margin:.5in; 	mso-footer-margin:.5in; 	mso-paper-source:0;} div.Section1 	{page:Section1;} --> <!--[if gte mso 10]&gt;   /* Style Definitions */  table.MsoNormalTable 	{mso-style-name:"Table Normal"; 	mso-tstyle-rowband-size:0; 	mso-tstyle-colband-size:0; 	mso-style-noshow:yes; 	mso-style-parent:""; 	mso-padding-alt:0in 5.4pt 0in 5.4pt; 	mso-para-margin:0in; 	mso-para-margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:10.0pt; 	font-family:"Times New Roman"; 	mso-ansi-language:#0400; 	mso-fareast-language:#0400; 	mso-bidi-language:#0400;}  --></p>
<p class="MsoNormal">As we begin a new election process, our President is currently in the process of deciding who will fill cabinet level positions. Some bring foreign prestige, such as Secretary of State, and others focus more on domestic issues, such as Secretary of Treasury. Any of these positions will require persons with decisions making ability and new imaginative ideas to manage our growing economy. If I were Director of Office and Management and Budget, I would want to quickly define requirements to manage any new economic stimulus packages. SAS 70 audits would be a requirement that would be enclosed in any new legislation.</p>
<p class="MsoNormal"> </p>
<p class="MsoNormal">If the Federal Government and Warren Buffett is going to own much of our economy, how can we be sure that the financial transactions are processed correctly and that our personal data is kept safe? Yes! SAS 70 audits can fulfill that role.</p>
<p class="MsoNormal"> </p>
<p class="MsoNormal">Currently, we are dishing out funds at record pace. Sometimes {sarcastically}, I wonder why don’t we give every American a printer, and tell them to print only what they need. As a taxpayer, I don’t have any idea what my return on this investment will be. When you purchase Coca-Cola stock, I know what their dividend will be? What is our return on our investment in Citigroup and AIG?</p>
<p class="MsoNormal">AS 70 audits must become a fundamental requirement for almost any service organization to conduct business with the Federal Government. Do you agree? Sas70expert@gmail.com</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/sas-70/what-cabinet-position-would-you-want-to-be-elected-too-sas-70/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SaaS and SAS70 – SAS70ExPERT</title>
		<link>http://itknowledgeexchange.techtarget.com/sas-70/saas-and-sas70-%e2%80%93-sas70expert/</link>
		<comments>http://itknowledgeexchange.techtarget.com/sas-70/saas-and-sas70-%e2%80%93-sas70expert/#comments</comments>
		<pubDate>Mon, 17 Nov 2008 23:23:03 +0000</pubDate>
		<dc:creator>SAS70ExPERT</dc:creator>
				<category><![CDATA[Access control]]></category>
		<category><![CDATA[Data center operations]]></category>
		<category><![CDATA[Management]]></category>
		<category><![CDATA[Network]]></category>
		<category><![CDATA[SaaS]]></category>
		<category><![CDATA[SAS 70]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/sas-70/saas-and-sas70-%e2%80%93-sas70expert/</guid>
		<description><![CDATA[As more outsourcing of applications takes place in this economy by using SaaS(software-as-a-service), is Management producing costs savings? and how many SAS70&#8242;s will you be required to collect? From the Data Center operations, the IT support vendor, and the application provider?   When you perform your cost-benefit analysis items to consider are Who will benefit [...]]]></description>
				<content:encoded><![CDATA[<p><span></span><span>As more outsourcing of applications takes place in this economy by using SaaS(software-as-a-service), is Management producing costs savings? and how many SAS70&#8242;s will you be required to collect? From the Data Center operations, the IT support vendor, and the application provider?</span></p>
<p><span> </span></p>
<p><span>When you perform your cost-benefit analysis items to consider are </span></p>
<ul>
<li><span>Who will benefit from access control for your application</span></li>
<li><span>From where will your visitors/employees/customers be connecting to your information, vpn network, cellphone or pda, or other web enabled device</span></li>
<li><span>Obtain more control over your licensing costs</span><span><br />
</span></li>
</ul>
<p><span>As you develop a strategic plan to use SaaS, build fundamental close relationships with your vendors and define them carefully in your contracts. Constantly update your contracts or service level agreements to match your needs and develop tools to monitor the success of your vendor meeting your requirements.</span></p>
<p><span> </span></p>
<p><span>SAS70 must be performed on your SaaS vendor to provide you with the reliability, confidentiality and integrity of service to be provided to you and your customers. Control objectives may be similar or different, but careful examination of the audit report should be performed in order to determine that your data is secure. SAS70ExPERT.biz</span></p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/sas-70/saas-and-sas70-%e2%80%93-sas70expert/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Privacy issues and the SAS70 audit</title>
		<link>http://itknowledgeexchange.techtarget.com/sas-70/privacy-issues-and-the-sas70-audit/</link>
		<comments>http://itknowledgeexchange.techtarget.com/sas-70/privacy-issues-and-the-sas70-audit/#comments</comments>
		<pubDate>Sat, 25 Oct 2008 01:43:25 +0000</pubDate>
		<dc:creator>SAS70ExPERT</dc:creator>
				<category><![CDATA[Management]]></category>
		<category><![CDATA[Risk management]]></category>
		<category><![CDATA[SAS 70]]></category>
		<category><![CDATA[Security Program Management]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/sas-70/privacy-issues-and-the-sas70-audit/</guid>
		<description><![CDATA[Privacy as part of your Security Program Management program means adherence to trust and obligation within your company policy, standards, and procedures. SAS 70 auditors may assist you in implementing this risk management into your company standards by:   1.       identifying the data or information that is personable, 2.       examining the private information collected, disclosed [...]]]></description>
				<content:encoded><![CDATA[<p><!--[if gte mso 9]&gt;     Normal   0         false   false   false                             MicrosoftInternetExplorer4   --><!--[if gte mso 9]&gt;     --> <!--  /* Font Definitions */  @font-face 	{font-family:Verdana; 	panose-1:2 11 6 4 3 5 4 4 2 4; 	mso-font-charset:0; 	mso-generic-font-family:swiss; 	mso-font-pitch:variable; 	mso-font-signature:536871559 0 0 0 415 0;}  /* Style Definitions */  p.MsoNormal, li.MsoNormal, div.MsoNormal 	{mso-style-parent:""; 	margin:0in; 	margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:12.0pt; 	font-family:"Times New Roman"; 	mso-fareast-font-family:"Times New Roman";} @page Section1 	{size:8.5in 11.0in; 	margin:1.0in 1.25in 1.0in 1.25in; 	mso-header-margin:.5in; 	mso-footer-margin:.5in; 	mso-paper-source:0;} div.Section1 	{page:Section1;}  /* List Definitions */  @list l0 	{mso-list-id:1765809275; 	mso-list-type:hybrid; 	mso-list-template-ids:-1161523944 67698703 67698713 67698715 67698703 67698713 67698715 67698703 67698713 67698715;} @list l0:level1 	{mso-level-tab-stop:.5in; 	mso-level-number-position:left; 	text-indent:-.25in;} ol 	{margin-bottom:0in;} ul 	{margin-bottom:0in;} --> <!--[if gte mso 10]&gt;   /* Style Definitions */  table.MsoNormalTable 	{mso-style-name:"Table Normal"; 	mso-tstyle-rowband-size:0; 	mso-tstyle-colband-size:0; 	mso-style-noshow:yes; 	mso-style-parent:""; 	mso-padding-alt:0in 5.4pt 0in 5.4pt; 	mso-para-margin:0in; 	mso-para-margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:10.0pt; 	font-family:"Times New Roman"; 	mso-ansi-language:#0400; 	mso-fareast-language:#0400; 	mso-bidi-language:#0400;}  --><em><span></span></em></p>
<p class="MsoNormal"><span>Privacy as part of your Security Program Management program means adherence to trust and obligation within your company policy, standards, and procedures. SAS 70 auditors may assist you in implementing this risk management into your company standards by:</span></p>
<p class="MsoNormal"><span> </span></p>
<p class="MsoNormal"><!--[if !supportLists]--><span><span>1.<span>       </span></span></span><!--[endif]--><span>identifying the data or information that is personable,</span></p>
<p class="MsoNormal"><!--[if !supportLists]--><span><span>2.<span>       </span></span></span><!--[endif]--><span>examining the private information collected, disclosed and that should be destroyed</span></p>
<p class="MsoNormal"><!--[if !supportLists]--><span><span>3.<span>       </span></span></span><!--[endif]--><span>ensuring the accountability of the private data</span></p>
<p class="MsoNormal"><!--[if !supportLists]--><span><span>4.<span>       </span></span></span><!--[endif]--><span>assisting in developing policy and procedure for the risks associated with private data</span></p>
<p class="MsoNormal"><span> </span></p>
<p class="MsoNormal"><span>Based on this standard, you should be able to comply with legal and compliance regulations. This would ensure that privacy standards are considered in all IT projects. SAS70ExPERT@gmail.com</span></p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/sas-70/privacy-issues-and-the-sas70-audit/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Third party agreements and SAS70 audit &#8211; SAS 70</title>
		<link>http://itknowledgeexchange.techtarget.com/sas-70/third-party-agreements-and-sas70-audit-sas-70/</link>
		<comments>http://itknowledgeexchange.techtarget.com/sas-70/third-party-agreements-and-sas70-audit-sas-70/#comments</comments>
		<pubDate>Wed, 22 Oct 2008 02:26:05 +0000</pubDate>
		<dc:creator>SAS70ExPERT</dc:creator>
				<category><![CDATA[Management]]></category>
		<category><![CDATA[Monitoring]]></category>
		<category><![CDATA[SAS 70]]></category>
		<category><![CDATA[Third-party services]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/sas-70/third-party-agreements-and-sas70-audit-sas-70/</guid>
		<description><![CDATA[  During a SAS70 audit, an auditor may examine any relationships with third parties.  Any third party agreements or service level agreements should contain:   1.       procedures to protect all outsourced data, applications or hardware 2.       a description of the services provided and the target level of services 3.       the establishment of an escalation process [...]]]></description>
				<content:encoded><![CDATA[<p><!--[if gte mso 9]&gt;     Normal   0         false   false   false                             MicrosoftInternetExplorer4   --><!--[if gte mso 9]&gt;     --> <!--  /* Font Definitions */  @font-face 	{font-family:Verdana; 	panose-1:2 11 6 4 3 5 4 4 2 4; 	mso-font-charset:0; 	mso-generic-font-family:swiss; 	mso-font-pitch:variable; 	mso-font-signature:536871559 0 0 0 415 0;}  /* Style Definitions */  p.MsoNormal, li.MsoNormal, div.MsoNormal 	{mso-style-parent:""; 	margin:0in; 	margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:12.0pt; 	font-family:"Times New Roman"; 	mso-fareast-font-family:"Times New Roman";} a:link, span.MsoHyperlink 	{color:blue; 	text-decoration:underline; 	text-underline:single;} a:visited, span.MsoHyperlinkFollowed 	{color:purple; 	text-decoration:underline; 	text-underline:single;} @page Section1 	{size:8.5in 11.0in; 	margin:1.0in 1.25in 1.0in 1.25in; 	mso-header-margin:.5in; 	mso-footer-margin:.5in; 	mso-paper-source:0;} div.Section1 	{page:Section1;}  /* List Definitions */  @list l0 	{mso-list-id:1011951001; 	mso-list-type:hybrid; 	mso-list-template-ids:777698078 67698703 67698713 67698715 67698703 67698713 67698715 67698703 67698713 67698715;} @list l0:level1 	{mso-level-tab-stop:.5in; 	mso-level-number-position:left; 	text-indent:-.25in;} ol 	{margin-bottom:0in;} ul 	{margin-bottom:0in;} --> <!--[if gte mso 10]&gt;   /* Style Definitions */  table.MsoNormalTable 	{mso-style-name:"Table Normal"; 	mso-tstyle-rowband-size:0; 	mso-tstyle-colband-size:0; 	mso-style-noshow:yes; 	mso-style-parent:""; 	mso-padding-alt:0in 5.4pt 0in 5.4pt; 	mso-para-margin:0in; 	mso-para-margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:10.0pt; 	font-family:"Times New Roman"; 	mso-ansi-language:#0400; 	mso-fareast-language:#0400; 	mso-bidi-language:#0400;}  --><em><span> </span></em></p>
<p class="MsoNormal"><span>During a SAS70 audit, an auditor may examine any relationships with third parties.<span>  </span>Any third party agreements or service level agreements should contain:</span></p>
<p class="MsoNormal"><span> </span></p>
<p class="MsoNormal"><!--[if !supportLists]--><span><span>1.<span>       </span></span></span><!--[endif]--><span>procedures to protect all outsourced data, applications or hardware</span></p>
<p class="MsoNormal"><!--[if !supportLists]--><span><span>2.<span>       </span></span></span><!--[endif]--><span>a description of the services provided and the target level of services</span></p>
<p class="MsoNormal"><!--[if !supportLists]--><span><span>3.<span>       </span></span></span><!--[endif]--><span>the establishment of an escalation process should an incident occur</span></p>
<p class="MsoNormal"><!--[if !supportLists]--><span><span>4.<span>       </span></span></span><!--[endif]--><span>the right to audit and determine that they are adhering to your agreement</span></p>
<p class="MsoNormal"><!--[if !supportLists]--><span><span>5.<span>       </span></span></span><!--[endif]--><span>the respective liabilities of both parties should an incident occur.</span></p>
<p class="MsoNormal"><span> </span></p>
<p class="MsoNormal"><span>During a SAS70 audit, you have a choice to exclude your outsourced services or include them in the examination. I would recommend you include them, especially if they are essential to the services you are providing to your customers. <a href="mailto:SAS70ExPERT@gmail.com">SAS70ExPERT@gmail.com</a></span></p>
<p class="MsoNormal"><span> </span></p>
<p class="MsoNormal"><em><span> </span></em></p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/sas-70/third-party-agreements-and-sas70-audit-sas-70/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Outsourcing your data backup process – SAS70</title>
		<link>http://itknowledgeexchange.techtarget.com/sas-70/outsourcing-your-data-backup-process-%e2%80%93-sas70/</link>
		<comments>http://itknowledgeexchange.techtarget.com/sas-70/outsourcing-your-data-backup-process-%e2%80%93-sas70/#comments</comments>
		<pubDate>Thu, 25 Sep 2008 11:06:55 +0000</pubDate>
		<dc:creator>SAS70ExPERT</dc:creator>
				<category><![CDATA[Backup]]></category>
		<category><![CDATA[Management]]></category>
		<category><![CDATA[SAS 70]]></category>
		<category><![CDATA[Third-party services]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/sas-70/outsourcing-your-data-backup-process-%e2%80%93-sas70/</guid>
		<description><![CDATA[During the SAS70 audit, an examination will be performed on your data backup process. If you have outsourced this to a local vendor, you are still responsible for making sure that your data is kept safe, secure, and is backed up properly. Hosted or online backup processes are very attractive for small to medium size [...]]]></description>
				<content:encoded><![CDATA[<p><!--[if gte mso 9]&gt;     Normal   0         false   false   false                             MicrosoftInternetExplorer4   --><!--[if gte mso 9]&gt;     --> <!--  /* Font Definitions */  @font-face 	{font-family:Verdana; 	panose-1:2 11 6 4 3 5 4 4 2 4; 	mso-font-charset:0; 	mso-generic-font-family:swiss; 	mso-font-pitch:variable; 	mso-font-signature:536871559 0 0 0 415 0;}  /* Style Definitions */  p.MsoNormal, li.MsoNormal, div.MsoNormal 	{mso-style-parent:""; 	margin:0in; 	margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:12.0pt; 	font-family:"Times New Roman"; 	mso-fareast-font-family:"Times New Roman";} @page Section1 	{size:8.5in 11.0in; 	margin:1.0in 1.25in 1.0in 1.25in; 	mso-header-margin:.5in; 	mso-footer-margin:.5in; 	mso-paper-source:0;} div.Section1 	{page:Section1;} --> <!--[if gte mso 10]&gt;   /* Style Definitions */  table.MsoNormalTable 	{mso-style-name:"Table Normal"; 	mso-tstyle-rowband-size:0; 	mso-tstyle-colband-size:0; 	mso-style-noshow:yes; 	mso-style-parent:""; 	mso-padding-alt:0in 5.4pt 0in 5.4pt; 	mso-para-margin:0in; 	mso-para-margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:10.0pt; 	font-family:"Times New Roman"; 	mso-ansi-language:#0400; 	mso-fareast-language:#0400; 	mso-bidi-language:#0400;}  --></p>
<p class="MsoNormal">
<!--[if gte mso 9]&gt;     Normal   0         false   false   false                             MicrosoftInternetExplorer4   --><!--[if gte mso 9]&gt;     --> <!--  /* Font Definitions */  @font-face 	{font-family:Verdana; 	panose-1:2 11 6 4 3 5 4 4 2 4; 	mso-font-charset:0; 	mso-generic-font-family:swiss; 	mso-font-pitch:variable; 	mso-font-signature:536871559 0 0 0 415 0;}  /* Style Definitions */  p.MsoNormal, li.MsoNormal, div.MsoNormal 	{mso-style-parent:""; 	margin:0in; 	margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:12.0pt; 	font-family:"Times New Roman"; 	mso-fareast-font-family:"Times New Roman";} @page Section1 	{size:8.5in 11.0in; 	margin:1.0in 1.25in 1.0in 1.25in; 	mso-header-margin:.5in; 	mso-footer-margin:.5in; 	mso-paper-source:0;} div.Section1 	{page:Section1;} --> <!--[if gte mso 10]&gt;   /* Style Definitions */  table.MsoNormalTable 	{mso-style-name:"Table Normal"; 	mso-tstyle-rowband-size:0; 	mso-tstyle-colband-size:0; 	mso-style-noshow:yes; 	mso-style-parent:""; 	mso-padding-alt:0in 5.4pt 0in 5.4pt; 	mso-para-margin:0in; 	mso-para-margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:10.0pt; 	font-family:"Times New Roman"; 	mso-ansi-language:#0400; 	mso-fareast-language:#0400; 	mso-bidi-language:#0400;}  --><span></span></p>
<p class="MsoNormal"><span>During the SAS70 audit, an examination will be performed on your data backup process. If you have outsourced this to a local vendor, you are still responsible for making sure that your data is kept safe, secure, and is backed up properly. Hosted or online backup processes are very attractive for small to medium size businesses. Why? They don’t have to maintain the expertise internally and the IT equipment is expensive.</span></p>
<p class="MsoNormal"><span> </span></p>
<p class="MsoNormal"><span>How best do you manage your backup provider? Be sure to have a service level agreement in place. The service level agreement should provide you response times for when you need help. And you will! When you need to find that lost report that is due for your presentation today, you will want the file restored today – <em>NOT</em> in 24-36 hours. In addition, review your own internet connection as you will need a fast one to transfer your data. Does your outsourced vendor take care of your needs? SAS70ExPERT@gmail.com</span></p>
<p class="MsoNormal"><span> </span></p>
<p><em><span>Outsourcing your data backup process – SAS70</span></em></p>
<p class="MsoNormal"><span> </span></p>
<p class="MsoNormal"><span>During the SAS70 audit, an examination will be performed on your data backup process. If you have outsourced this to a local vendor, you are still responsible for making sure that your data is kept safe, secure, and is backed up properly. Hosted or online backup processes are very attractive for small to medium size businesses. Why? They don’t have to maintain the expertise internally and the IT equipment is expensive.</span></p>
<p class="MsoNormal"><span> </span></p>
<p class="MsoNormal"><span>How best do you manage your backup provider? Be sure to have a service level agreement in place. The service level agreement should provide you response times for when you need help. And you will! When you need to find that lost report that is due for your presentation today, you will want the file restored today – <em>NOT</em> in 24-36 hours. In addition, review your own internet connection as you will need a fast one to transfer your data. Does your outsourced vendor take care of your needs? SAS70ExPERT@gmail.com</span></p>
<p class="MsoNormal"><span> </span></p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/sas-70/outsourcing-your-data-backup-process-%e2%80%93-sas70/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SAS70 audits require preventative maintenance too!</title>
		<link>http://itknowledgeexchange.techtarget.com/sas-70/sas70-audits-require-preventative-maintenance-too/</link>
		<comments>http://itknowledgeexchange.techtarget.com/sas-70/sas70-audits-require-preventative-maintenance-too/#comments</comments>
		<pubDate>Mon, 22 Sep 2008 12:21:29 +0000</pubDate>
		<dc:creator>SAS70ExPERT</dc:creator>
				<category><![CDATA[cooling systems]]></category>
		<category><![CDATA[DataCenter]]></category>
		<category><![CDATA[Incident response]]></category>
		<category><![CDATA[Management]]></category>
		<category><![CDATA[Risk management]]></category>
		<category><![CDATA[SAS 70]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/sas-70/sas70-audits-require-preventative-maintenance-too/</guid>
		<description><![CDATA[During a SAS 70 audit of your DataCenter, an auditor will examine the installation of generators, cooling systems, and UPS backup systems. Questions will arise not only about installation, but of continuing preventative maintenance and incident response. An integrated approach should be followed which has is a holistic plan that clearly identifies scheduling, execution, documentation, [...]]]></description>
				<content:encoded><![CDATA[<p><!--[if gte mso 9]&gt;     Normal   0         false   false   false                             MicrosoftInternetExplorer4   --><!--[if gte mso 9]&gt;     --> <!--  /* Font Definitions */  @font-face 	{font-family:Wingdings; 	panose-1:5 0 0 0 0 0 0 0 0 0; 	mso-font-charset:2; 	mso-generic-font-family:auto; 	mso-font-pitch:variable; 	mso-font-signature:0 268435456 0 0 -2147483648 0;}  /* Style Definitions */  p.MsoNormal, li.MsoNormal, div.MsoNormal 	{mso-style-parent:""; 	margin:0in; 	margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:12.0pt; 	font-family:"Times New Roman"; 	mso-fareast-font-family:"Times New Roman";} @page Section1 	{size:8.5in 11.0in; 	margin:1.0in 1.25in 1.0in 1.25in; 	mso-header-margin:.5in; 	mso-footer-margin:.5in; 	mso-paper-source:0;} div.Section1 	{page:Section1;}  /* List Definitions */  @list l0 	{mso-list-id:1809081993; 	mso-list-type:hybrid; 	mso-list-template-ids:-1464947684 67698689 67698691 67698693 67698689 67698691 67698693 67698689 67698691 67698693;} @list l0:level1 	{mso-level-number-format:bullet; 	mso-level-text:; 	mso-level-tab-stop:38.25pt; 	mso-level-number-position:left; 	margin-left:38.25pt; 	text-indent:-.25in; 	font-family:Symbol;} ol 	{margin-bottom:0in;} ul 	{margin-bottom:0in;} --> <!--[if gte mso 10]&gt;   /* Style Definitions */  table.MsoNormalTable 	{mso-style-name:"Table Normal"; 	mso-tstyle-rowband-size:0; 	mso-tstyle-colband-size:0; 	mso-style-noshow:yes; 	mso-style-parent:""; 	mso-padding-alt:0in 5.4pt 0in 5.4pt; 	mso-para-margin:0in; 	mso-para-margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:10.0pt; 	font-family:"Times New Roman"; 	mso-ansi-language:#0400; 	mso-fareast-language:#0400; 	mso-bidi-language:#0400;}  --><span></span></p>
<p class="MsoNormal"><span>During a SAS 70 audit of your DataCenter, an auditor will examine the installation of generators, cooling systems, and UPS backup systems. Questions will arise not only about installation, but of continuing preventative maintenance and incident response. An integrated approach should be followed which has is a holistic plan that clearly identifies scheduling, execution, documentation, risk management, and continuing follow-up inspections.</span></p>
<p class="MsoNormal"><span> When preventative maintenance occurs, four results can be expected:</span></p>
<p class="MsoNormal"><!--[if !supportLists]--><span><span>·<span>         </span></span></span><!--[endif]--><span>a potential issue is identified and immediate actions are taken to prevent a future failure.</span></p>
<p class="MsoNormal"><!--[if !supportLists]--><span><span>·<span>         </span></span></span><!--[endif]--><span>a potential issues is identified and a repair is scheduled</span></p>
<p class="MsoNormal"><!--[if !supportLists]--><span><span>·<span>         </span></span></span><!--[endif]--><span>the regular maintenance does not uncover any potential repair</span></p>
<p class="MsoNormal"><!--[if !supportLists]--><span><span>·<span>         </span></span></span><!--[endif]--><span>a defect is uncovered and unanticipated repair time occurs.</span></p>
<p class="MsoNormal"><span> In order to optimize maintenance windows, Managers should maintain the age of equipment, history of operating and environmental experience (temperature, voltage, run-time, abnormal events), and operating characteristics such as noise, temperature and vibration. Where is your preventative maintenance plan and do you have service level agreements in place today to monitor your network services? SAS70ExPERT@gmail.com</span></p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/sas-70/sas70-audits-require-preventative-maintenance-too/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Security is essential for all new technology investments? SAS70</title>
		<link>http://itknowledgeexchange.techtarget.com/sas-70/security-is-essential-for-all-new-technology-investments-sas70/</link>
		<comments>http://itknowledgeexchange.techtarget.com/sas-70/security-is-essential-for-all-new-technology-investments-sas70/#comments</comments>
		<pubDate>Sun, 21 Sep 2008 21:22:21 +0000</pubDate>
		<dc:creator>SAS70ExPERT</dc:creator>
				<category><![CDATA[Auditing]]></category>
		<category><![CDATA[Management]]></category>
		<category><![CDATA[Network]]></category>
		<category><![CDATA[SAS 70]]></category>
		<category><![CDATA[Security management]]></category>
		<category><![CDATA[Third-party services]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/sas-70/security-is-essential-for-all-new-technology-investments-sas70/</guid>
		<description><![CDATA[Which new technologies are you adopting? With Web 2.0, social networking, wikis, and blogs – oh mY! With so many new avenues to penetrate your market, the decisions you make today can effect the success of your SAS 70 audit. When evaluating new technology, always first determine your company objectives as we previously discussed. In [...]]]></description>
				<content:encoded><![CDATA[<p><!--[if gte mso 9]&gt;     Normal   0         false   false   false                             MicrosoftInternetExplorer4   --><!--[if gte mso 9]&gt;     --> <!--  /* Font Definitions */  @font-face 	{font-family:Bembo; 	panose-1:0 0 0 0 0 0 0 0 0 0; 	mso-font-charset:0; 	mso-generic-font-family:roman; 	mso-font-format:other; 	mso-font-pitch:auto; 	mso-font-signature:3 0 0 0 1 0;}  /* Style Definitions */  p.MsoNormal, li.MsoNormal, div.MsoNormal 	{mso-style-parent:""; 	margin:0in; 	margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:12.0pt; 	font-family:"Times New Roman"; 	mso-fareast-font-family:"Times New Roman";} @page Section1 	{size:8.5in 11.0in; 	margin:1.0in 1.25in 1.0in 1.25in; 	mso-header-margin:.5in; 	mso-footer-margin:.5in; 	mso-paper-source:0;} div.Section1 	{page:Section1;} --> <!--[if gte mso 10]&gt;   /* Style Definitions */  table.MsoNormalTable 	{mso-style-name:"Table Normal"; 	mso-tstyle-rowband-size:0; 	mso-tstyle-colband-size:0; 	mso-style-noshow:yes; 	mso-style-parent:""; 	mso-padding-alt:0in 5.4pt 0in 5.4pt; 	mso-para-margin:0in; 	mso-para-margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:10.0pt; 	font-family:"Times New Roman"; 	mso-ansi-language:#0400; 	mso-fareast-language:#0400; 	mso-bidi-language:#0400;}  --></p>
<p class="MsoNormal"><span>Which new technologies are you adopting? With Web 2.0, social networking, wikis, and blogs – oh mY! With so many new avenues to penetrate your market, the decisions you make today can effect the success of your SAS 70 audit. When evaluating new technology, always first determine your company objectives as we previously discussed. In addition, you will need to remember to consider what new security features must be implemented in your computing environment to prevent downtime. It is essential early in the process that you identify the threats, the risks, and then create a plan.</span></p>
<p class="MsoNormal"><span> </span></p>
<p class="MsoNormal"><span><span> </span></span><span>In identifying threats, the assessment team must consider who or what could compromise a target system’s components such that the system’s security attributes would be jeopardized. You should focus on how the information assets and components differ from what you already have. In identifying the security risks, consider what will th total potential impact on the organization. When your system is compromised – and it will be – how would you handle the loss of critical data?</span></p>
<p class="MsoNormal"><span> </span></p>
<p class="MsoNormal"><span>To address technology security risks, requires a documented plan and you must train your employees on how to enact the plan. The SAS70 audit will require you to have a plan in place and it will examine who are the participants in the plan. The plan should include not only IT, but operations and senior management. Where is your security plan? SAS70ExPERT@gmail.com</span></p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/sas-70/security-is-essential-for-all-new-technology-investments-sas70/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>
