 




<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>SAS 70 &#187; Monitoring</title>
	<atom:link href="http://itknowledgeexchange.techtarget.com/sas-70/tag/monitoring/feed/" rel="self" type="application/rss+xml" />
	<link>http://itknowledgeexchange.techtarget.com/sas-70</link>
	<description></description>
	<lastBuildDate>Tue, 23 Dec 2008 17:58:25 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	
		<item>
		<title>Outsource with a Plan &#8211; SAS70</title>
		<link>http://itknowledgeexchange.techtarget.com/sas-70/outsource-with-a-plan-sas70/</link>
		<comments>http://itknowledgeexchange.techtarget.com/sas-70/outsource-with-a-plan-sas70/#comments</comments>
		<pubDate>Thu, 27 Nov 2008 01:40:56 +0000</pubDate>
		<dc:creator>SAS70ExPERT</dc:creator>
				<category><![CDATA[Disaster Recovery]]></category>
		<category><![CDATA[Monitoring]]></category>
		<category><![CDATA[SaaS]]></category>
		<category><![CDATA[SAS 70]]></category>
		<category><![CDATA[Third-party services]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/sas-70/outsource-with-a-plan-sas70/</guid>
		<description><![CDATA[As more businesses outsource IT to third-party services, data privacy and integrity are paramount to the success of your operations. The SaaS small and medium businesses have a responsibility to ensure your data is processed correctly and that it is kept safe. SAS 70 audits are requirement. Before outsourcing to save funds, make sure you [...]]]></description>
				<content:encoded><![CDATA[<p>As more businesses outsource IT to third-party services, data privacy and integrity are paramount to the success of your operations. The SaaS small and medium businesses have a responsibility to ensure your data is processed correctly and that it is kept safe. SAS 70 audits are requirement.</p>
<p>Before outsourcing to save funds, make sure you have a defined plan. Without it, one small security breach of a politicians&#8217; social security number can destroy your company reputation and your ability to generate new business. This plan should included:</p>
<p>1)definitions related to service levels. You will require your vendor to have uptime of at least 99%.</p>
<p>2) the ability to process your information quickly. Customers accesses your company website and purchasing items should occur relatively fast.</p>
<p>3) reporting functions which allow you monitoring capability and to  capture your data and analyze.</p>
<p>4) a Disaster Recovery plan, a single hardware failure can result in the loss of business.</p>
<p>SAS70expert@gmail.com</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/sas-70/outsource-with-a-plan-sas70/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Third party agreements and SAS70 audit &#8211; SAS 70</title>
		<link>http://itknowledgeexchange.techtarget.com/sas-70/third-party-agreements-and-sas70-audit-sas-70/</link>
		<comments>http://itknowledgeexchange.techtarget.com/sas-70/third-party-agreements-and-sas70-audit-sas-70/#comments</comments>
		<pubDate>Wed, 22 Oct 2008 02:26:05 +0000</pubDate>
		<dc:creator>SAS70ExPERT</dc:creator>
				<category><![CDATA[Management]]></category>
		<category><![CDATA[Monitoring]]></category>
		<category><![CDATA[SAS 70]]></category>
		<category><![CDATA[Third-party services]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/sas-70/third-party-agreements-and-sas70-audit-sas-70/</guid>
		<description><![CDATA[  During a SAS70 audit, an auditor may examine any relationships with third parties.  Any third party agreements or service level agreements should contain:   1.       procedures to protect all outsourced data, applications or hardware 2.       a description of the services provided and the target level of services 3.       the establishment of an escalation process [...]]]></description>
				<content:encoded><![CDATA[<p><!--[if gte mso 9]&gt;     Normal   0         false   false   false                             MicrosoftInternetExplorer4   --><!--[if gte mso 9]&gt;     --> <!--  /* Font Definitions */  @font-face 	{font-family:Verdana; 	panose-1:2 11 6 4 3 5 4 4 2 4; 	mso-font-charset:0; 	mso-generic-font-family:swiss; 	mso-font-pitch:variable; 	mso-font-signature:536871559 0 0 0 415 0;}  /* Style Definitions */  p.MsoNormal, li.MsoNormal, div.MsoNormal 	{mso-style-parent:""; 	margin:0in; 	margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:12.0pt; 	font-family:"Times New Roman"; 	mso-fareast-font-family:"Times New Roman";} a:link, span.MsoHyperlink 	{color:blue; 	text-decoration:underline; 	text-underline:single;} a:visited, span.MsoHyperlinkFollowed 	{color:purple; 	text-decoration:underline; 	text-underline:single;} @page Section1 	{size:8.5in 11.0in; 	margin:1.0in 1.25in 1.0in 1.25in; 	mso-header-margin:.5in; 	mso-footer-margin:.5in; 	mso-paper-source:0;} div.Section1 	{page:Section1;}  /* List Definitions */  @list l0 	{mso-list-id:1011951001; 	mso-list-type:hybrid; 	mso-list-template-ids:777698078 67698703 67698713 67698715 67698703 67698713 67698715 67698703 67698713 67698715;} @list l0:level1 	{mso-level-tab-stop:.5in; 	mso-level-number-position:left; 	text-indent:-.25in;} ol 	{margin-bottom:0in;} ul 	{margin-bottom:0in;} --> <!--[if gte mso 10]&gt;   /* Style Definitions */  table.MsoNormalTable 	{mso-style-name:"Table Normal"; 	mso-tstyle-rowband-size:0; 	mso-tstyle-colband-size:0; 	mso-style-noshow:yes; 	mso-style-parent:""; 	mso-padding-alt:0in 5.4pt 0in 5.4pt; 	mso-para-margin:0in; 	mso-para-margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:10.0pt; 	font-family:"Times New Roman"; 	mso-ansi-language:#0400; 	mso-fareast-language:#0400; 	mso-bidi-language:#0400;}  --><em><span> </span></em></p>
<p class="MsoNormal"><span>During a SAS70 audit, an auditor may examine any relationships with third parties.<span>  </span>Any third party agreements or service level agreements should contain:</span></p>
<p class="MsoNormal"><span> </span></p>
<p class="MsoNormal"><!--[if !supportLists]--><span><span>1.<span>       </span></span></span><!--[endif]--><span>procedures to protect all outsourced data, applications or hardware</span></p>
<p class="MsoNormal"><!--[if !supportLists]--><span><span>2.<span>       </span></span></span><!--[endif]--><span>a description of the services provided and the target level of services</span></p>
<p class="MsoNormal"><!--[if !supportLists]--><span><span>3.<span>       </span></span></span><!--[endif]--><span>the establishment of an escalation process should an incident occur</span></p>
<p class="MsoNormal"><!--[if !supportLists]--><span><span>4.<span>       </span></span></span><!--[endif]--><span>the right to audit and determine that they are adhering to your agreement</span></p>
<p class="MsoNormal"><!--[if !supportLists]--><span><span>5.<span>       </span></span></span><!--[endif]--><span>the respective liabilities of both parties should an incident occur.</span></p>
<p class="MsoNormal"><span> </span></p>
<p class="MsoNormal"><span>During a SAS70 audit, you have a choice to exclude your outsourced services or include them in the examination. I would recommend you include them, especially if they are essential to the services you are providing to your customers. <a href="mailto:SAS70ExPERT@gmail.com">SAS70ExPERT@gmail.com</a></span></p>
<p class="MsoNormal"><span> </span></p>
<p class="MsoNormal"><em><span> </span></em></p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/sas-70/third-party-agreements-and-sas70-audit-sas-70/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Risk Assessments and the SAS 70 audit</title>
		<link>http://itknowledgeexchange.techtarget.com/sas-70/risk-assessments-and-the-sas-70-audit/</link>
		<comments>http://itknowledgeexchange.techtarget.com/sas-70/risk-assessments-and-the-sas-70-audit/#comments</comments>
		<pubDate>Wed, 17 Sep 2008 15:35:03 +0000</pubDate>
		<dc:creator>SAS70ExPERT</dc:creator>
				<category><![CDATA[Access]]></category>
		<category><![CDATA[Auditing]]></category>
		<category><![CDATA[CIO]]></category>
		<category><![CDATA[COBIT]]></category>
		<category><![CDATA[Management]]></category>
		<category><![CDATA[Monitoring]]></category>
		<category><![CDATA[Network]]></category>
		<category><![CDATA[Risk management]]></category>
		<category><![CDATA[SAS 70]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/sas-70/risk-assessments-and-the-sas-70-audit/</guid>
		<description><![CDATA[Management’s risk assessment process is required to be audited in a SAS70 examination; however, in my experience, most auditors do not adequately review Management’s risk assessment process. Without adequate auditing experience, most auditors would not have a basis to determine if Management had reviewed the control risk universe. In addition, Management mostly does not formally [...]]]></description>
				<content:encoded><![CDATA[<p><!--[if !mso]&gt;  v\:* {behavior:url(#default#VML);} o\:* {behavior:url(#default#VML);} w\:* {behavior:url(#default#VML);} .shape {behavior:url(#default#VML);}  --><!--[if gte mso 9]&gt;     Normal   0         false   false   false                             MicrosoftInternetExplorer4   --><!--[if gte mso 9]&gt;     --> <!--  /* Font Definitions */  @font-face 	{font-family:"Arial Narrow"; 	panose-1:2 11 5 6 2 2 2 3 2 4; 	mso-font-charset:0; 	mso-generic-font-family:swiss; 	mso-font-pitch:variable; 	mso-font-signature:647 0 0 0 159 0;}  /* Style Definitions */  p.MsoNormal, li.MsoNormal, div.MsoNormal 	{mso-style-parent:""; 	margin:0in; 	margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:12.0pt; 	font-family:"Times New Roman"; 	mso-fareast-font-family:"Times New Roman";} a:link, span.MsoHyperlink 	{color:blue; 	text-decoration:underline; 	text-underline:single;} a:visited, span.MsoHyperlinkFollowed 	{color:purple; 	text-decoration:underline; 	text-underline:single;} @page Section1 	{size:8.5in 11.0in; 	margin:1.0in 1.25in 1.0in 1.25in; 	mso-header-margin:.5in; 	mso-footer-margin:.5in; 	mso-paper-source:0;} div.Section1 	{page:Section1;} --> <!--[if gte mso 10]&gt;   /* Style Definitions */  table.MsoNormalTable 	{mso-style-name:"Table Normal"; 	mso-tstyle-rowband-size:0; 	mso-tstyle-colband-size:0; 	mso-style-noshow:yes; 	mso-style-parent:""; 	mso-padding-alt:0in 5.4pt 0in 5.4pt; 	mso-para-margin:0in; 	mso-para-margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:10.0pt; 	font-family:"Times New Roman"; 	mso-ansi-language:#0400; 	mso-fareast-language:#0400; 	mso-bidi-language:#0400;}  --><!--[if gte mso 9]&gt;   --><!--[if gte mso 9]&gt;       --><span></span></p>
<p class="MsoNormal"><span>Management’s risk assessment process is required to be audited in a SAS70 examination; however, in my experience, most auditors do not adequately review Management’s risk assessment process. Without adequate auditing experience, most auditors would not have a basis to determine if Management had reviewed the control risk universe. In addition, Management mostly does not formally document risks, but they are discussed only in Board meeting with among C-level executive’s. The COBIT risk assessment framework can provide Management with the criteria and the details that an inexperienced auditor may use as a guide to examine their risk assessment process</span></p>
<p class="MsoNormal"><span> </span></p>
<p class="MsoNormal"><span>COBIT consists</span><span> of information that is required to help achieve business objectives. You must first begin with a vulnerability analysis of your business operations. Then determine the threats to these vulnerabilities For example, your greatest risk may be related to the legal liabilities due to incorrect financial statements….. or something more simpler, like loss of a backup tape which contained your customers social security numbers. Third, determine the impact of this threat. Is it a million dollar monetary fine, or could your license to conduct business be taken away. The conclusion is an action plan after which the cycle can start again. </span></p>
<p class="MsoNormal"><span> </span></p>
<p class="MsoNormal"><span>When the SAS 70 auditor discusses your risk assessment process, don’t be afraid to say that you have it all stored in your brain. Without risk documentation, an experience auditing firm will assist you in forming a roadmap of risks that lead to your business success. Mr. CIO, have you determine what are your business risks or your information technology risks today? Have you formally discussed and evaluated them with other c-level executives or with your peers and association’s within your industry. Note from the diagram below the a formal risk assessment process. Next time we will discuss each of these layers in detail. <a href="mailto:SAS70ExPERT@gmail.com">SAS70ExPERT@gmail.com</a> </span></p>
<p class="MsoNormal"><span> </span></p>
<p class="MsoNormal"><!--[if mso &amp; !supportInlineShapes &amp; supportFields]&gt;<span><span></span><span> </span>SHAPE<span>  </span>\* MERGEFORMAT <span></span></span>&#8211;><span><!--[if gte vml 1]&gt;-->                                                                                       </p>
<table cellpadding="0" cellspacing="0" width="100%">
<tr>
<td>
<div>
<p class="MsoNormal" align="center"><span>Asset</span></p>
<p class="MsoNormal" align="center"><span>Identification</span></p>
<p class="MsoNormal" align="center"><span>and Valuation</span></p>
</div>
</td>
</tr>
</table>
<table cellpadding="0" cellspacing="0" width="100%">
<tr>
<td>
<div>
<p class="MsoNormal"><span>Vulnerability</span></p>
<p class="MsoNormal"><span>&nbsp;</span></p>
</div>
</td>
</tr>
</table>
<table cellpadding="0" cellspacing="0" width="100%">
<tr>
<td>
<div>
<p class="MsoNormal"><span><span> </span>Assessment</span></p>
</div>
</td>
</tr>
</table>
<table cellpadding="0" cellspacing="0" width="100%">
<tr>
<td>
<div>
<p class="MsoNormal"><span><span>   </span>Threat</span></p>
<p class="MsoNormal"><span>&nbsp;</span></p>
</div>
</td>
</tr>
</table>
<table cellpadding="0" cellspacing="0" width="100%">
<tr>
<td>
<div>
<p class="MsoNormal"><span>Assessment</span></p>
</div>
</td>
</tr>
</table>
<table cellpadding="0" cellspacing="0" width="100%">
<tr>
<td>
<div>
<p class="MsoNormal"><span><span>    </span>Risk</span></p>
<p class="MsoNormal"><span>&nbsp;</span></p>
</div>
</td>
</tr>
</table>
<table cellpadding="0" cellspacing="0" width="100%">
<tr>
<td>
<div>
<p class="MsoNormal"><span>Assessment</span></p>
</div>
</td>
</tr>
</table>
<table cellpadding="0" cellspacing="0" width="100%">
<tr>
<td>
<div>
<p class="MsoNormal"><span><span> </span>Counter-</span></p>
<p class="MsoNormal"><span>&nbsp;</span></p>
</div>
</td>
</tr>
</table>
<table cellpadding="0" cellspacing="0" width="100%">
<tr>
<td>
<div>
<p class="MsoNormal"><span><span> </span>measures</span></p>
</div>
</td>
</tr>
</table>
<table cellpadding="0" cellspacing="0" width="100%">
<tr>
<td>
<div>
<p class="MsoNormal"><span><span> </span></span><span>Control</span></p>
<p class="MsoNormal"><span>&nbsp;</span></p>
</div>
</td>
</tr>
</table>
<table cellpadding="0" cellspacing="0" width="100%">
<tr>
<td>
<div>
<p class="MsoNormal"><span>Evaluation</span></p>
</div>
</td>
</tr>
</table>
<table cellpadding="0" cellspacing="0" width="100%">
<tr>
<td>
<div>
<p class="MsoNormal"><span>Residual</span></p>
<p class="MsoNormal"><span>&nbsp;</span></p>
</div>
</td>
</tr>
</table>
<table cellpadding="0" cellspacing="0" width="100%">
<tr>
<td>
<div>
<p class="MsoNormal"><span>Risk</span></p>
</div>
</td>
</tr>
</table>
<table cellpadding="0" cellspacing="0" width="100%">
<tr>
<td>
<div>
<p class="MsoNormal"><span>Action</span></p>
<p class="MsoNormal"><span>&nbsp;</span></p>
</div>
</td>
</tr>
</table>
<table cellpadding="0" cellspacing="0" width="100%">
<tr>
<td>
<div>
<p class="MsoNormal"><span><span>  </span>Plan</span></p>
</div>
</td>
</tr>
</table>
<p>                                                                                                                                                  <!--[if !vml]--><br />
<!--[endif]--></span><!--[if mso &amp; !supportInlineShapes &amp; supportFields]&gt;<span>   <span></span></span>&#8211;><span></span></p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/sas-70/risk-assessments-and-the-sas-70-audit/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Successful traits of a CIO equal successful SAS70 audits (Part 3) – SAS 70</title>
		<link>http://itknowledgeexchange.techtarget.com/sas-70/successful-traits-of-a-cio-equal-successful-sas70-audits-part-3-%e2%80%93-sas-70/</link>
		<comments>http://itknowledgeexchange.techtarget.com/sas-70/successful-traits-of-a-cio-equal-successful-sas70-audits-part-3-%e2%80%93-sas-70/#comments</comments>
		<pubDate>Wed, 27 Aug 2008 14:30:02 +0000</pubDate>
		<dc:creator>SAS70ExPERT</dc:creator>
				<category><![CDATA[Auditing]]></category>
		<category><![CDATA[CEO]]></category>
		<category><![CDATA[CIO]]></category>
		<category><![CDATA[Compliance]]></category>
		<category><![CDATA[Management]]></category>
		<category><![CDATA[Monitoring]]></category>
		<category><![CDATA[SAS 70]]></category>
		<category><![CDATA[Third-party services]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/sas-70/successful-traits-of-a-cio-equal-successful-sas70-audits-part-3-%e2%80%93-sas-70/</guid>
		<description><![CDATA[  At 5pm, the CEO returned to his office with a cup of coffee and a very unpleasant frown. He barked out a few orders to his administrative assistant. I knew then that ….it was all going to roll down hill. Apparently, an IT Director signed a vendor contract with some very unfavorable terms. Luckily, [...]]]></description>
				<content:encoded><![CDATA[<p><!--[if gte mso 9]&gt;     Normal   0         false   false   false                             MicrosoftInternetExplorer4   --><!--[if gte mso 9]&gt;     --> <!--  /* Style Definitions */  p.MsoNormal, li.MsoNormal, div.MsoNormal 	{mso-style-parent:""; 	margin:0in; 	margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:12.0pt; 	font-family:"Times New Roman"; 	mso-fareast-font-family:"Times New Roman";} @page Section1 	{size:8.5in 11.0in; 	margin:1.0in 1.25in 1.0in 1.25in; 	mso-header-margin:.5in; 	mso-footer-margin:.5in; 	mso-paper-source:0;} div.Section1 	{page:Section1;} --> <!--[if gte mso 10]&gt;   /* Style Definitions */  table.MsoNormalTable 	{mso-style-name:"Table Normal"; 	mso-tstyle-rowband-size:0; 	mso-tstyle-colband-size:0; 	mso-style-noshow:yes; 	mso-style-parent:""; 	mso-padding-alt:0in 5.4pt 0in 5.4pt; 	mso-para-margin:0in; 	mso-para-margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:10.0pt; 	font-family:"Times New Roman"; 	mso-ansi-language:#0400; 	mso-fareast-language:#0400; 	mso-bidi-language:#0400;}  --></p>
<p class="MsoNormal"> <br />
<!--[if gte mso 9]&gt;     Normal   0         false   false   false                             MicrosoftInternetExplorer4   --><!--[if gte mso 9]&gt;     --> <!--  /* Style Definitions */  p.MsoNormal, li.MsoNormal, div.MsoNormal 	{mso-style-parent:""; 	margin:0in; 	margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:12.0pt; 	font-family:"Times New Roman"; 	mso-fareast-font-family:"Times New Roman";} @page Section1 	{size:8.5in 11.0in; 	margin:1.0in 1.25in 1.0in 1.25in; 	mso-header-margin:.5in; 	mso-footer-margin:.5in; 	mso-paper-source:0;} div.Section1 	{page:Section1;} --> <!--[if gte mso 10]&gt;   /* Style Definitions */  table.MsoNormalTable 	{mso-style-name:"Table Normal"; 	mso-tstyle-rowband-size:0; 	mso-tstyle-colband-size:0; 	mso-style-noshow:yes; 	mso-style-parent:""; 	mso-padding-alt:0in 5.4pt 0in 5.4pt; 	mso-para-margin:0in; 	mso-para-margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:10.0pt; 	font-family:"Times New Roman"; 	mso-ansi-language:#0400; 	mso-fareast-language:#0400; 	mso-bidi-language:#0400;}  --><span></span></p>
<p class="MsoNormal"><span></span></p>
<p class="MsoNormal">At 5pm, the CEO returned to his office with a cup of coffee and a very unpleasant frown. He barked out a few orders to his administrative assistant. I knew then that ….it was all going to roll down hill. Apparently, an IT Director signed a vendor contract with some very unfavorable terms. Luckily, the IT Director was no longer with the Company, therefore, the CIO, was the one who would be assigned the cleanup work.</p>
<p class="MsoNormal"> </p>
<p class="MsoNormal">In order to deal with this situation, the CIO would have to quickly understand the requirements of the CEO and the expectations of the vendor. If he failed at delivering for either of them, then the effects could have serious consequences on IT operations. These types of political maneuvers happen everyday and it takes a skillful politician as a CIO to produce favorable results.</p>
<p class="MsoNormal"> </p>
<p class="MsoNormal">A CIO can use her political skills to effectively deal with a SAS70 audit. When an auditor identifies an audit exception, the CIO may fully agree with the auditor; however, the description of the audit exception may need to be qualified in order to maintain a close relationship with the CEO. Sometimes, negotiations are even held over simple words, such as “sometimes” as they can make a big difference in the eyes of the Board of Directors or Audit Committee. What are some of the circumstances that you may have been involved in? Were you successful in avoiding pitfalls? What worked best for you?</p>
<p class="MsoNormal">Sas70expert@gmail.com</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/sas-70/successful-traits-of-a-cio-equal-successful-sas70-audits-part-3-%e2%80%93-sas-70/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Successful traits of a CIO equal successful SAS70 audits (Part 1) – SAS 70</title>
		<link>http://itknowledgeexchange.techtarget.com/sas-70/successful-traits-of-a-cio-equal-successful-sas70-audits-part-1-%e2%80%93-sas-70/</link>
		<comments>http://itknowledgeexchange.techtarget.com/sas-70/successful-traits-of-a-cio-equal-successful-sas70-audits-part-1-%e2%80%93-sas-70/#comments</comments>
		<pubDate>Thu, 21 Aug 2008 00:59:15 +0000</pubDate>
		<dc:creator>SAS70ExPERT</dc:creator>
				<category><![CDATA[Auditing]]></category>
		<category><![CDATA[CIO]]></category>
		<category><![CDATA[Compliance]]></category>
		<category><![CDATA[CSO]]></category>
		<category><![CDATA[Monitoring]]></category>
		<category><![CDATA[SAS 70]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/sas-70/successful-traits-of-a-cio-equal-successful-sas70-audits-part-1-%e2%80%93-sas-70/</guid>
		<description><![CDATA[If you have to conduct a SAS70 audit within your organization, are you ready? As a CIO, do you have the necessary leadership skills to make an audit a success?   A recent survey by TechRepublic lists the following criteria that an effective CIO or CSO must have in order to lead a 21st century [...]]]></description>
				<content:encoded><![CDATA[<p><!--[if gte mso 9]&gt;     Normal   0         false   false   false                             MicrosoftInternetExplorer4   --><!--[if gte mso 9]&gt;     --><!--[if !mso]&gt;  st1\:*{behavior:url(#ieooui) }  --> <!--  /* Style Definitions */  p.MsoNormal, li.MsoNormal, div.MsoNormal 	{mso-style-parent:""; 	margin:0in; 	margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:12.0pt; 	font-family:"Times New Roman"; 	mso-fareast-font-family:"Times New Roman";} @page Section1 	{size:8.5in 11.0in; 	margin:1.0in 1.25in 1.0in 1.25in; 	mso-header-margin:.5in; 	mso-footer-margin:.5in; 	mso-paper-source:0;} div.Section1 	{page:Section1;} --> <!--[if gte mso 10]&gt;   /* Style Definitions */  table.MsoNormalTable 	{mso-style-name:"Table Normal"; 	mso-tstyle-rowband-size:0; 	mso-tstyle-colband-size:0; 	mso-style-noshow:yes; 	mso-style-parent:""; 	mso-padding-alt:0in 5.4pt 0in 5.4pt; 	mso-para-margin:0in; 	mso-para-margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:10.0pt; 	font-family:"Times New Roman"; 	mso-ansi-language:#0400; 	mso-fareast-language:#0400; 	mso-bidi-language:#0400;}  --></p>
<p class="MsoNormal">If you have to conduct a SAS70 audit within your organization, are you ready? As a CIO, do you have the necessary leadership skills to make an audit a success?</p>
<p class="MsoNormal"> </p>
<p class="MsoNormal">A recent survey by TechRepublic lists the following criteria that an effective CIO or CSO must have in order to lead a 21<sup>st</sup> century information technology (IT) team. These characteristics are, but not necessarily in order of priority:</p>
<p class="MsoNormal"> </p>
<p class="MsoNormal">Communication skills</p>
<p class="MsoNormal">Be a visionary</p>
<p class="MsoNormal">Able to deal with office politics effectively</p>
<p class="MsoNormal">Have an understanding of financials</p>
<p class="MsoNormal">Leverage key technologies</p>
<p class="MsoNormal">Ability to build a strong team</p>
<p class="MsoNormal"> </p>
<p class="MsoNormal">As a CIO, these characteristics are required to be an effective leader. In addition, these same characteristics will make you an effective CIO or CSO when a SAS70 audit is conducted. From the initial planning and scoping phases of the audit, you must take the initiative to develop a strong relationship with your auditor. Don’t be afraid to tell him all the bad and the good when discussing your IT operations. By developing an open rapport, and having frank discussions, you will be able to quickly develop a lasting bond with your auditor. Do you have this type of relationship with your auditor? sas70expert@gmail.com</p>
<p class="MsoNormal"> </p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/sas-70/successful-traits-of-a-cio-equal-successful-sas70-audits-part-1-%e2%80%93-sas-70/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>7 essential to have in your SLA’s to have to help you manage your outsourced vendor &#8211; SAS70</title>
		<link>http://itknowledgeexchange.techtarget.com/sas-70/7-essential-to-have-in-your-sla%e2%80%99s-to-have-to-help-you-manage-your-outsourced-vendor-sas70/</link>
		<comments>http://itknowledgeexchange.techtarget.com/sas-70/7-essential-to-have-in-your-sla%e2%80%99s-to-have-to-help-you-manage-your-outsourced-vendor-sas70/#comments</comments>
		<pubDate>Thu, 24 Jul 2008 01:36:47 +0000</pubDate>
		<dc:creator>SAS70ExPERT</dc:creator>
				<category><![CDATA[Access control]]></category>
		<category><![CDATA[Auditing]]></category>
		<category><![CDATA[CIO]]></category>
		<category><![CDATA[Compliance]]></category>
		<category><![CDATA[CSO]]></category>
		<category><![CDATA[Data center operations]]></category>
		<category><![CDATA[Management]]></category>
		<category><![CDATA[Monitoring]]></category>
		<category><![CDATA[Risk management]]></category>
		<category><![CDATA[SAS 70]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Security management]]></category>
		<category><![CDATA[Security Program Management]]></category>
		<category><![CDATA[Third-party services]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/sas-70/7-essential-to-have-in-your-sla%e2%80%99s-to-have-to-help-you-manage-your-outsourced-vendor-sas70/</guid>
		<description><![CDATA[“Do you understand what impact the outsourced vendor has on your financial stability?” says a SAS 70 auditor. If they fail to make payroll or Friday or if you’re DataCenter fails, what effect will that have on your operations? So as not to be “asleep at the switch,” make sure you understand the vendor’s operations [...]]]></description>
				<content:encoded><![CDATA[<p><!--[if gte mso 9]&gt;     Normal   0         false   false   false                             MicrosoftInternetExplorer4   --><!--[if gte mso 9]&gt;     --><!--[if !mso]&gt;  st1\:*{behavior:url(#ieooui) }  --> <!--  /* Style Definitions */  p.MsoNormal, li.MsoNormal, div.MsoNormal 	{mso-style-parent:""; 	margin:0in; 	margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:12.0pt; 	font-family:"Times New Roman"; 	mso-fareast-font-family:"Times New Roman";} @page Section1 	{size:8.5in 11.0in; 	margin:1.0in 1.25in 1.0in 1.25in; 	mso-header-margin:.5in; 	mso-footer-margin:.5in; 	mso-paper-source:0;} div.Section1 	{page:Section1;} --> <!--[if gte mso 10]&gt;   /* Style Definitions */  table.MsoNormalTable 	{mso-style-name:"Table Normal"; 	mso-tstyle-rowband-size:0; 	mso-tstyle-colband-size:0; 	mso-style-noshow:yes; 	mso-style-parent:""; 	mso-padding-alt:0in 5.4pt 0in 5.4pt; 	mso-para-margin:0in; 	mso-para-margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:10.0pt; 	font-family:"Times New Roman"; 	mso-ansi-language:#0400; 	mso-fareast-language:#0400; 	mso-bidi-language:#0400;}  --></p>
<p class="MsoNormal">“Do you understand what impact the outsourced vendor has on your financial stability?” says a SAS 70 auditor. If they fail to make payroll or Friday or if you’re DataCenter fails, what effect will that have on your operations? So as not to be “asleep at the switch,” make sure you understand the vendor’s operations and risks involved. Here are 10 essential specifications that you should have in your service level agreement with you’re outsourced vendor:</p>
<p class="MsoNormal">1) Data encryption and protection – determine what your vendor is doing from an information technology perspective to protect your information. Are they using applications that have security built-in? Do they have firewalls?</p>
<p class="MsoNormal">2) Physical Security – review and management of access to buildings and data is critical to protect information technology assets. Tight control must be maintained in order to prevent identify theft and loss of valuable equipment, like exchange servers, racks, and hard drives. Each employee should have ID, preferably biometric, and you should log entry and egress into facilities.</p>
<p class="MsoNormal">3) Environmental Security – Make sure your data is not only locked in the safe room, but that the environment in the room provides essential protections. Do they have fire extinguishers? Temperature control? Air conditioners? …etc.</p>
<p class="MsoNormal">4) Confidentiality agreements – Require your business partner/vendor to sign confidentiality agreements/non-disclosure agreements to prevent loss of trade secrets, data, and patents.</p>
<p class="MsoNormal">5)Employee training – Policies are useless, unless your employees and vendors are trained and aware. Provide all vendors with awareness training of your requirements when processing your information or providing you with services.</p>
<p class="MsoNormal">6) Require employee background investigations. You want to make sure that the person responsible for managing your money is not a convicted felon. They must have a review of the work history and a validation of the skills.</p>
<p class="MsoNormal">7)Lastly, Management of vendors- After you have given your requirements to your vendor, how do you know they stay in compliance? A SAS 70 audit is required. sas70expert@gmail.com</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/sas-70/7-essential-to-have-in-your-sla%e2%80%99s-to-have-to-help-you-manage-your-outsourced-vendor-sas70/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How laptops become serial killers?  &#8211; SAS70</title>
		<link>http://itknowledgeexchange.techtarget.com/sas-70/how-laptops-become-serial-killers-sas70/</link>
		<comments>http://itknowledgeexchange.techtarget.com/sas-70/how-laptops-become-serial-killers-sas70/#comments</comments>
		<pubDate>Sun, 06 Jul 2008 16:18:05 +0000</pubDate>
		<dc:creator>SAS70ExPERT</dc:creator>
				<category><![CDATA[Access]]></category>
		<category><![CDATA[Access control]]></category>
		<category><![CDATA[Administration]]></category>
		<category><![CDATA[Auditing]]></category>
		<category><![CDATA[CFO]]></category>
		<category><![CDATA[CIO]]></category>
		<category><![CDATA[Compliance]]></category>
		<category><![CDATA[CSO]]></category>
		<category><![CDATA[DataCenter]]></category>
		<category><![CDATA[human factors]]></category>
		<category><![CDATA[Information risk management]]></category>
		<category><![CDATA[Management]]></category>
		<category><![CDATA[Monitoring]]></category>
		<category><![CDATA[Network]]></category>
		<category><![CDATA[Network Management Systems]]></category>
		<category><![CDATA[Risk management]]></category>
		<category><![CDATA[SAS 70]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Security management]]></category>
		<category><![CDATA[Security Program Management]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/sas-70/how-laptops-become-serial-killers-sas70/</guid>
		<description><![CDATA[My business requires distribution and collection of data. Much of it resides on a centrally located server; however, there is data on the laptop that has never been transferred over to the server or that may have  been taken off the server for project work. As human beings we will never be perfect. Someone will [...]]]></description>
				<content:encoded><![CDATA[<p><!--[if gte mso 9]&gt;     Normal   0         false   false   false                             MicrosoftInternetExplorer4   --><!--[if gte mso 9]&gt;     --> <!--  /* Style Definitions */  p.MsoNormal, li.MsoNormal, div.MsoNormal 	{mso-style-parent:""; 	margin:0in; 	margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:12.0pt; 	font-family:"Times New Roman"; 	mso-fareast-font-family:"Times New Roman";} @page Section1 	{size:8.5in 11.0in; 	margin:1.0in 1.25in 1.0in 1.25in; 	mso-header-margin:.5in; 	mso-footer-margin:.5in; 	mso-paper-source:0;} div.Section1 	{page:Section1;} --> <!--[if gte mso 10]&gt;   /* Style Definitions */  table.MsoNormalTable 	{mso-style-name:"Table Normal"; 	mso-tstyle-rowband-size:0; 	mso-tstyle-colband-size:0; 	mso-style-noshow:yes; 	mso-style-parent:""; 	mso-padding-alt:0in 5.4pt 0in 5.4pt; 	mso-para-margin:0in; 	mso-para-margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:10.0pt; 	font-family:"Times New Roman"; 	mso-ansi-language:#0400; 	mso-fareast-language:#0400; 	mso-bidi-language:#0400;}  --></p>
<p class="MsoNormal">My business requires distribution and collection of data. Much of it resides on a centrally located server; however, there is data on the laptop that has never been transferred over to the server or that may have  been taken off the server for project work. As human beings we will never be perfect. Someone will lend access to their laptop to a friend or customer, a laptop will be lost or stolen, and an unprotected USB drive is a loaded gun just waiting to have the trigger pulled so that data can be transferred off your laptop. Laptops with sensitive data that goes unprotected, can become a media nightmare, a legal hassle and a may limit your customer retention and market growth &#8212; a serial killer that stops your business growth and the vendors that support you.</p>
<p class="MsoNormal">&nbsp;</p>
<p class="MsoNormal"> To protect data loss, we now have L0-jack services for laptops when they are stolen. The laptop can be found and once connected to a network will be shut down.But what about the ease we have to install and transfer data to others using USB drives. Even if you use a USB drive that requires a password, is that enough security? I have read recently that laptops were returned after being lost that contained sensitive data such as social security numbers for big companies – including Google. Now that they have the laptop back, is the risk over? What if the data was transferred off the laptop onto a USB drive?</p>
<p class="MsoNormal"> </p>
<p class="MsoNormal">Just like for the SAS70 audit, you have to perform a risk assessment to determine the controls that must be in place, and identify those that can be implemented as time permits. In the situation above, I don’t think focusing on the number of ways that data can be taken off laptops is the key to reducing risk. You should focus more on identifying the type of data that you have, mark the sensitive data, and control access to it – by limiting users, strengthening laptop controls around the sensitive data, and identifying opportunities to record transfer of sensitive data <span></span>which would provide an audit trail. How are you controlling your data on your laptops? sas70expert@gmail.com</p>
<p class="MsoNormal"> </p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/sas-70/how-laptops-become-serial-killers-sas70/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Are you ready to make decisions as CSO or CIO? – SAS70</title>
		<link>http://itknowledgeexchange.techtarget.com/sas-70/are-you-ready-to-make-decisions-as-cso-or-cio-%e2%80%93-sas70/</link>
		<comments>http://itknowledgeexchange.techtarget.com/sas-70/are-you-ready-to-make-decisions-as-cso-or-cio-%e2%80%93-sas70/#comments</comments>
		<pubDate>Sat, 28 Jun 2008 01:33:52 +0000</pubDate>
		<dc:creator>SAS70ExPERT</dc:creator>
				<category><![CDATA[Administration]]></category>
		<category><![CDATA[Auditing]]></category>
		<category><![CDATA[business/IT alignment]]></category>
		<category><![CDATA[Career development]]></category>
		<category><![CDATA[CEO]]></category>
		<category><![CDATA[CFO]]></category>
		<category><![CDATA[CIO]]></category>
		<category><![CDATA[Compliance]]></category>
		<category><![CDATA[CSO]]></category>
		<category><![CDATA[Data center operations]]></category>
		<category><![CDATA[DataCenter]]></category>
		<category><![CDATA[DataManagement]]></category>
		<category><![CDATA[Email]]></category>
		<category><![CDATA[Exchange]]></category>
		<category><![CDATA[Financials]]></category>
		<category><![CDATA[human factors]]></category>
		<category><![CDATA[Information risk management]]></category>
		<category><![CDATA[Management]]></category>
		<category><![CDATA[management software]]></category>
		<category><![CDATA[Microsoft Windows]]></category>
		<category><![CDATA[Monitoring]]></category>
		<category><![CDATA[Networking]]></category>
		<category><![CDATA[Risk management]]></category>
		<category><![CDATA[SAS 70]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Security management]]></category>
		<category><![CDATA[Security Program Management]]></category>
		<category><![CDATA[Strategic Enterprise Management]]></category>
		<category><![CDATA[Third-party services]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/sas-70/are-you-ready-to-make-decisions-as-cso-or-cio-%e2%80%93-sas70/</guid>
		<description><![CDATA[As you complete that CISSP or CISA designation and move up the corporate ladder, do you have the right skills to begin making the decisions as CSO or CIO? Even if you have a great understanding of IT operations(networking, disaster recovery, datacenter management), compliance(SAS70, Webtrust, Systrust, SOX), and leadership(Project management, financial budgeting and administration), if [...]]]></description>
				<content:encoded><![CDATA[<p><!--[if gte mso 9]&gt;     Normal   0         false   false   false                             MicrosoftInternetExplorer4   --><!--[if gte mso 9]&gt;     --> <!--  /* Font Definitions */  @font-face 	{font-family:Wingdings; 	panose-1:5 0 0 0 0 0 0 0 0 0; 	mso-font-charset:2; 	mso-generic-font-family:auto; 	mso-font-pitch:variable; 	mso-font-signature:0 268435456 0 0 -2147483648 0;}  /* Style Definitions */  p.MsoNormal, li.MsoNormal, div.MsoNormal 	{mso-style-parent:""; 	margin:0in; 	margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:12.0pt; 	font-family:"Times New Roman"; 	mso-fareast-font-family:"Times New Roman";} a:link, span.MsoHyperlink 	{color:blue; 	text-decoration:underline; 	text-underline:single;} a:visited, span.MsoHyperlinkFollowed 	{color:purple; 	text-decoration:underline; 	text-underline:single;} @page Section1 	{size:8.5in 11.0in; 	margin:1.0in 1.25in 1.0in 1.25in; 	mso-header-margin:.5in; 	mso-footer-margin:.5in; 	mso-paper-source:0;} div.Section1 	{page:Section1;}  /* List Definitions */  @list l0 	{mso-list-id:757990981; 	mso-list-type:hybrid; 	mso-list-template-ids:1827948222 67698689 67698691 67698693 67698689 67698691 67698693 67698689 67698691 67698693;} @list l0:level1 	{mso-level-number-format:bullet; 	mso-level-text:; 	mso-level-tab-stop:.5in; 	mso-level-number-position:left; 	text-indent:-.25in; 	font-family:Symbol;} ol 	{margin-bottom:0in;} ul 	{margin-bottom:0in;} --> <!--[if gte mso 10]&gt;   /* Style Definitions */  table.MsoNormalTable 	{mso-style-name:"Table Normal"; 	mso-tstyle-rowband-size:0; 	mso-tstyle-colband-size:0; 	mso-style-noshow:yes; 	mso-style-parent:""; 	mso-padding-alt:0in 5.4pt 0in 5.4pt; 	mso-para-margin:0in; 	mso-para-margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:10.0pt; 	font-family:"Times New Roman"; 	mso-ansi-language:#0400; 	mso-fareast-language:#0400; 	mso-bidi-language:#0400;}  --></p>
<p class="MsoNormal">As you complete that CISSP or CISA designation and move up the corporate ladder, do you have the right skills to begin making the decisions as CSO or CIO? Even if you have a great understanding of IT operations(<em>networking, disaster recovery, datacenter management</em>), compliance(<em>SAS70, Webtrust, Systrust, SOX</em>), and leadership(<em>Project management</em>, financial budgeting and administration), if you don&#8217;t communicate effectively you will not make the list. IT leaders can write, speak until they are red in the face; however, if they are unable to speak general business language, the business audience will not support their IT objectives or provide funding. Some of the more important skills to have as CSO or CIO are:</p>
<ul>
<li class="MsoNormal">Communicate      effectively</li>
<li class="MsoNormal">Lead      during a disaster</li>
<li class="MsoNormal">Provide      an IT strategy</li>
</ul>
<p class="MsoNormal"> What are the important skills that a CSO or CIO must have to be a success? As a team leader? To build Board support? To be an effective information technology project manager/business leader? To build another Google, Microsoft Windows, or Email Exchange?</p>
<p class="MsoNormal"><em>SAS70ExPERT@gmail.com </em></p>
<p class="MsoNormal"> </p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/sas-70/are-you-ready-to-make-decisions-as-cso-or-cio-%e2%80%93-sas70/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What’s your data loss prevention strategy? – SAS70</title>
		<link>http://itknowledgeexchange.techtarget.com/sas-70/what%e2%80%99s-your-data-loss-prevention-strategy-%e2%80%93-sas70/</link>
		<comments>http://itknowledgeexchange.techtarget.com/sas-70/what%e2%80%99s-your-data-loss-prevention-strategy-%e2%80%93-sas70/#comments</comments>
		<pubDate>Thu, 26 Jun 2008 04:30:32 +0000</pubDate>
		<dc:creator>SAS70ExPERT</dc:creator>
				<category><![CDATA[Access]]></category>
		<category><![CDATA[Access control]]></category>
		<category><![CDATA[Auditing]]></category>
		<category><![CDATA[business/IT alignment]]></category>
		<category><![CDATA[CEO]]></category>
		<category><![CDATA[CFO]]></category>
		<category><![CDATA[CIO]]></category>
		<category><![CDATA[Compliance]]></category>
		<category><![CDATA[Configuration]]></category>
		<category><![CDATA[CSO]]></category>
		<category><![CDATA[Data center design]]></category>
		<category><![CDATA[Database]]></category>
		<category><![CDATA[Database issues]]></category>
		<category><![CDATA[Database Management Systems]]></category>
		<category><![CDATA[DataCenter]]></category>
		<category><![CDATA[DataManagement]]></category>
		<category><![CDATA[Firewalls]]></category>
		<category><![CDATA[Identity & Access Management]]></category>
		<category><![CDATA[Incident response]]></category>
		<category><![CDATA[Information risk management]]></category>
		<category><![CDATA[Intrustion management]]></category>
		<category><![CDATA[Management]]></category>
		<category><![CDATA[management software]]></category>
		<category><![CDATA[Monitoring]]></category>
		<category><![CDATA[Network]]></category>
		<category><![CDATA[Network Management Systems]]></category>
		<category><![CDATA[Network monitoring]]></category>
		<category><![CDATA[Network security]]></category>
		<category><![CDATA[Networking]]></category>
		<category><![CDATA[Patch management]]></category>
		<category><![CDATA[patching]]></category>
		<category><![CDATA[router configuration]]></category>
		<category><![CDATA[routers]]></category>
		<category><![CDATA[SAS 70]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Security management]]></category>
		<category><![CDATA[Security Program Management]]></category>
		<category><![CDATA[Security tokens]]></category>
		<category><![CDATA[Third-party services]]></category>
		<category><![CDATA[TrendMirco]]></category>
		<category><![CDATA[Viruses]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/sas-70/what%e2%80%99s-your-data-loss-prevention-strategy-%e2%80%93-sas70/</guid>
		<description><![CDATA[Are you reviewing you firewall rules quarterly? Have you implemented an (IDS) intrusion detection system? Are your routers set up to prevent unauthorized intruders? Do you have the latest and greatest virus protection? Are you performing a SAS70 audit every six months? Database security breaches are increasing daily and costing tremendous amounts of dollars that [...]]]></description>
				<content:encoded><![CDATA[<p><!--[if gte mso 9]&gt;     Normal   0         false   false   false                             MicrosoftInternetExplorer4   --><!--[if gte mso 9]&gt;     --> <!--  /* Style Definitions */  p.MsoNormal, li.MsoNormal, div.MsoNormal 	{mso-style-parent:""; 	margin:0in; 	margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:12.0pt; 	font-family:"Times New Roman"; 	mso-fareast-font-family:"Times New Roman";} a:link, span.MsoHyperlink 	{color:blue; 	text-decoration:underline; 	text-underline:single;} a:visited, span.MsoHyperlinkFollowed 	{color:purple; 	text-decoration:underline; 	text-underline:single;} @page Section1 	{size:8.5in 11.0in; 	margin:1.0in 1.25in 1.0in 1.25in; 	mso-header-margin:.5in; 	mso-footer-margin:.5in; 	mso-paper-source:0;} div.Section1 	{page:Section1;} --> <!--[if gte mso 10]&gt;   /* Style Definitions */  table.MsoNormalTable 	{mso-style-name:"Table Normal"; 	mso-tstyle-rowband-size:0; 	mso-tstyle-colband-size:0; 	mso-style-noshow:yes; 	mso-style-parent:""; 	mso-padding-alt:0in 5.4pt 0in 5.4pt; 	mso-para-margin:0in; 	mso-para-margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:10.0pt; 	font-family:"Times New Roman"; 	mso-ansi-language:#0400; 	mso-fareast-language:#0400; 	mso-bidi-language:#0400;}  --></p>
<p class="MsoNormal">Are you reviewing you firewall rules quarterly? Have you implemented an (IDS) intrusion detection system? Are your routers set up to prevent unauthorized intruders? Do you have the latest and greatest virus protection? Are you performing a SAS70 audit every six months? Database security breaches are increasing daily and costing tremendous amounts of dollars that should have been spent on IT projects. You should at least have an emergency plan in place when data loss occurs. Without an emergency plan in place, the breach could continue and the legal costs could continue to escalate.</p>
<p class="MsoNormal"> </p>
<p><span> <a href="http://itknowledgeexchange.techtarget.com/itanswers/tag/data-center-design/" title="Data center design (18)"><span></span></a></span><a href="http://itknowledgeexchange.techtarget.com/itanswers/tag/security-program-management/" title="Security Program Management (112)"><br />
</a></p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/sas-70/what%e2%80%99s-your-data-loss-prevention-strategy-%e2%80%93-sas70/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Data Exchange and SAS70</title>
		<link>http://itknowledgeexchange.techtarget.com/sas-70/data-exchange-and-sas70/</link>
		<comments>http://itknowledgeexchange.techtarget.com/sas-70/data-exchange-and-sas70/#comments</comments>
		<pubDate>Wed, 25 Jun 2008 11:21:16 +0000</pubDate>
		<dc:creator>SAS70ExPERT</dc:creator>
				<category><![CDATA[Access control]]></category>
		<category><![CDATA[Auditing]]></category>
		<category><![CDATA[business/IT alignment]]></category>
		<category><![CDATA[CEO]]></category>
		<category><![CDATA[CFO]]></category>
		<category><![CDATA[CIO]]></category>
		<category><![CDATA[Compliance]]></category>
		<category><![CDATA[CSO]]></category>
		<category><![CDATA[DataCenter]]></category>
		<category><![CDATA[DataManagement]]></category>
		<category><![CDATA[Email]]></category>
		<category><![CDATA[Encryption]]></category>
		<category><![CDATA[Exchange]]></category>
		<category><![CDATA[FTP]]></category>
		<category><![CDATA[Identity & Access Management]]></category>
		<category><![CDATA[instant messaging]]></category>
		<category><![CDATA[Monitoring]]></category>
		<category><![CDATA[Networking]]></category>
		<category><![CDATA[routers]]></category>
		<category><![CDATA[SAS 70]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Third-party services]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/sas-70/data-exchange-and-sas70/</guid>
		<description><![CDATA[Various transport methods, such as email, instant messaging, FTP, and encryption have been implemented to share files/data between Companies. But many methods, suffer from security, manageability, and the ability to track/log the transfer of information. Increasing regulations and SAS70 audit guidelines are requiring that privacy and security of data be maintained. What data transfer method [...]]]></description>
				<content:encoded><![CDATA[<p><!--[if gte mso 9]&gt;     Normal   0         false   false   false                             MicrosoftInternetExplorer4   --><!--[if gte mso 9]&gt;     --><!--[if !mso]&gt;  st1\:*{behavior:url(#ieooui) }  --> <!--  /* Style Definitions */  p.MsoNormal, li.MsoNormal, div.MsoNormal 	{mso-style-parent:""; 	margin:0in; 	margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:12.0pt; 	font-family:"Times New Roman"; 	mso-fareast-font-family:"Times New Roman";} @page Section1 	{size:8.5in 11.0in; 	margin:1.0in 1.25in 1.0in 1.25in; 	mso-header-margin:.5in; 	mso-footer-margin:.5in; 	mso-paper-source:0;} div.Section1 	{page:Section1;} --> <!--[if gte mso 10]&gt;   /* Style Definitions */  table.MsoNormalTable 	{mso-style-name:"Table Normal"; 	mso-tstyle-rowband-size:0; 	mso-tstyle-colband-size:0; 	mso-style-noshow:yes; 	mso-style-parent:""; 	mso-padding-alt:0in 5.4pt 0in 5.4pt; 	mso-para-margin:0in; 	mso-para-margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:10.0pt; 	font-family:"Times New Roman"; 	mso-ansi-language:#0400; 	mso-fareast-language:#0400; 	mso-bidi-language:#0400;}  --></p>
<p class="MsoNormal">Various transport methods, such as email, instant messaging, FTP, and encryption have been implemented to share files/data between Companies. But many methods, suffer from security, manageability, and the ability to track/log the transfer of information. Increasing regulations and SAS70 audit guidelines are requiring that privacy and security of data be maintained. What data transfer method are you using and is it secure,manageable and auditable?</p>
<p class="MsoNormal"> </p>
<p class="MsoNormal">The types of data transfer continue to evolve and a variety of people with whom companies exchange data is also changing. For example, many companies outsource processes that they used to perform in-house. Furthermore, some even are processed overseas, especially in India. How much control do you have on your outsourced vendor? How do you know that their process to transfer data is secure and managed appropriately? SAS70ExPERT@gmail.com</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/sas-70/data-exchange-and-sas70/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
