 




<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>SAS 70 &#187; Networking</title>
	<atom:link href="http://itknowledgeexchange.techtarget.com/sas-70/tag/networking/feed/" rel="self" type="application/rss+xml" />
	<link>http://itknowledgeexchange.techtarget.com/sas-70</link>
	<description></description>
	<lastBuildDate>Tue, 23 Dec 2008 17:58:25 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	
		<item>
		<title>Have you been Clickjacking lately? SAS70</title>
		<link>http://itknowledgeexchange.techtarget.com/sas-70/have-you-been-clickjacking-lately-sas70/</link>
		<comments>http://itknowledgeexchange.techtarget.com/sas-70/have-you-been-clickjacking-lately-sas70/#comments</comments>
		<pubDate>Thu, 27 Nov 2008 16:37:07 +0000</pubDate>
		<dc:creator>SAS70ExPERT</dc:creator>
				<category><![CDATA[browsers]]></category>
		<category><![CDATA[Clickjacking]]></category>
		<category><![CDATA[firefox]]></category>
		<category><![CDATA[internet]]></category>
		<category><![CDATA[internet explorer]]></category>
		<category><![CDATA[Opera]]></category>
		<category><![CDATA[SaaS]]></category>
		<category><![CDATA[Safari]]></category>
		<category><![CDATA[SAS 70]]></category>
		<category><![CDATA[vendors]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/sas-70/have-you-been-clickjacking-lately-sas70/</guid>
		<description><![CDATA[ Clickjacking threatens all major internet browsers – internet explorer, Mozilla firefox, Safari and Opera. What is it? Clickjacking is not when your wife takes over the remote control. It is when a browser user puts his mouse on a sign button, but a tag is placed under the button that the user may not see. [...]]]></description>
				<content:encoded><![CDATA[<p><!--[if gte mso 9]&gt;     Normal   0         false   false   false                             MicrosoftInternetExplorer4   --><!--[if gte mso 9]&gt;     --> <!--  /* Style Definitions */  p.MsoNormal, li.MsoNormal, div.MsoNormal 	{mso-style-parent:""; 	margin:0in; 	margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:12.0pt; 	font-family:"Times New Roman"; 	mso-fareast-font-family:"Times New Roman";} @page Section1 	{size:8.5in 11.0in; 	margin:1.0in 1.25in 1.0in 1.25in; 	mso-header-margin:.5in; 	mso-footer-margin:.5in; 	mso-paper-source:0;} div.Section1 	{page:Section1;} --> <!--[if gte mso 10]&gt;   /* Style Definitions */  table.MsoNormalTable 	{mso-style-name:"Table Normal"; 	mso-tstyle-rowband-size:0; 	mso-tstyle-colband-size:0; 	mso-style-noshow:yes; 	mso-style-parent:""; 	mso-padding-alt:0in 5.4pt 0in 5.4pt; 	mso-para-margin:0in; 	mso-para-margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:10.0pt; 	font-family:"Times New Roman"; 	mso-ansi-language:#0400; 	mso-fareast-language:#0400; 	mso-bidi-language:#0400;}  --></p>
<p class="MsoNormal"> Clickjacking threatens all major internet browsers – internet explorer, Mozilla firefox, Safari and Opera. What is it? Clickjacking is not when your wife takes over the remote control. It is when a browser user puts his mouse on a sign button, but a tag is placed under the button that the user may not see. When the user clicks, he then sends information to an unauthorized source. This could destroy the legitimacy of your web application or you SaaS.</p>
<p class="MsoNormal"> </p>
<p class="MsoNormal">There are several possible solutions to this hacker attack, but only with updates by the browser vendors. Firefox has a stop-gap solution in place – “no-script.” It is a technical solution and not for everyone. If you process credit card information, your SAS 70 auditor will look to see what precautions you have taken. What measures do you have in place? Sas70expert@gmail.com</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/sas-70/have-you-been-clickjacking-lately-sas70/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SaaS and SAS70 – SAS70ExPERT</title>
		<link>http://itknowledgeexchange.techtarget.com/sas-70/saas-and-sas70-%e2%80%93-sas70expert/</link>
		<comments>http://itknowledgeexchange.techtarget.com/sas-70/saas-and-sas70-%e2%80%93-sas70expert/#comments</comments>
		<pubDate>Mon, 17 Nov 2008 23:23:03 +0000</pubDate>
		<dc:creator>SAS70ExPERT</dc:creator>
				<category><![CDATA[Access control]]></category>
		<category><![CDATA[Data center operations]]></category>
		<category><![CDATA[Management]]></category>
		<category><![CDATA[Network]]></category>
		<category><![CDATA[SaaS]]></category>
		<category><![CDATA[SAS 70]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/sas-70/saas-and-sas70-%e2%80%93-sas70expert/</guid>
		<description><![CDATA[As more outsourcing of applications takes place in this economy by using SaaS(software-as-a-service), is Management producing costs savings? and how many SAS70&#8242;s will you be required to collect? From the Data Center operations, the IT support vendor, and the application provider?   When you perform your cost-benefit analysis items to consider are Who will benefit [...]]]></description>
				<content:encoded><![CDATA[<p><span></span><span>As more outsourcing of applications takes place in this economy by using SaaS(software-as-a-service), is Management producing costs savings? and how many SAS70&#8242;s will you be required to collect? From the Data Center operations, the IT support vendor, and the application provider?</span></p>
<p><span> </span></p>
<p><span>When you perform your cost-benefit analysis items to consider are </span></p>
<ul>
<li><span>Who will benefit from access control for your application</span></li>
<li><span>From where will your visitors/employees/customers be connecting to your information, vpn network, cellphone or pda, or other web enabled device</span></li>
<li><span>Obtain more control over your licensing costs</span><span><br />
</span></li>
</ul>
<p><span>As you develop a strategic plan to use SaaS, build fundamental close relationships with your vendors and define them carefully in your contracts. Constantly update your contracts or service level agreements to match your needs and develop tools to monitor the success of your vendor meeting your requirements.</span></p>
<p><span> </span></p>
<p><span>SAS70 must be performed on your SaaS vendor to provide you with the reliability, confidentiality and integrity of service to be provided to you and your customers. Control objectives may be similar or different, but careful examination of the audit report should be performed in order to determine that your data is secure. SAS70ExPERT.biz</span></p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/sas-70/saas-and-sas70-%e2%80%93-sas70expert/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Back to basics – Security awareness and education – SAS70</title>
		<link>http://itknowledgeexchange.techtarget.com/sas-70/back-to-basics-%e2%80%93-security-awareness-and-education-%e2%80%93-sas70/</link>
		<comments>http://itknowledgeexchange.techtarget.com/sas-70/back-to-basics-%e2%80%93-security-awareness-and-education-%e2%80%93-sas70/#comments</comments>
		<pubDate>Wed, 01 Oct 2008 04:26:14 +0000</pubDate>
		<dc:creator>SAS70ExPERT</dc:creator>
				<category><![CDATA[CIO]]></category>
		<category><![CDATA[Incident response]]></category>
		<category><![CDATA[Network]]></category>
		<category><![CDATA[Network security]]></category>
		<category><![CDATA[SAS 70]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Security Program Management]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/sas-70/back-to-basics-%e2%80%93-security-awareness-and-education-%e2%80%93-sas70/</guid>
		<description><![CDATA[For any security program, you must start at the basics and begin with a information security plan. In a SAS 70 audit, an auditor will examine a CIO&#8217;s operations to determine that you have security program management, incident response, and that appropriate training is provided to your employees. Your security plan should include at least [...]]]></description>
				<content:encoded><![CDATA[<p><!--[if gte mso 9]&gt;     Normal   0         false   false   false                             MicrosoftInternetExplorer4   --><!--[if gte mso 9]&gt;     --> <!--  /* Font Definitions */  @font-face 	{font-family:Wingdings; 	panose-1:5 0 0 0 0 0 0 0 0 0; 	mso-font-charset:2; 	mso-generic-font-family:auto; 	mso-font-pitch:variable; 	mso-font-signature:0 268435456 0 0 -2147483648 0;} @font-face 	{font-family:Verdana; 	panose-1:2 11 6 4 3 5 4 4 2 4; 	mso-font-charset:0; 	mso-generic-font-family:swiss; 	mso-font-pitch:variable; 	mso-font-signature:536871559 0 0 0 415 0;}  /* Style Definitions */  p.MsoNormal, li.MsoNormal, div.MsoNormal 	{mso-style-parent:""; 	margin:0in; 	margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:12.0pt; 	font-family:"Times New Roman"; 	mso-fareast-font-family:"Times New Roman";} @page Section1 	{size:8.5in 11.0in; 	margin:1.0in 1.25in 1.0in 1.25in; 	mso-header-margin:.5in; 	mso-footer-margin:.5in; 	mso-paper-source:0;} div.Section1 	{page:Section1;}  /* List Definitions */  @list l0 	{mso-list-id:1959330536; 	mso-list-type:hybrid; 	mso-list-template-ids:1424621910 67698689 67698691 67698693 67698689 67698691 67698693 67698689 67698691 67698693;} @list l0:level1 	{mso-level-number-format:bullet; 	mso-level-text:; 	mso-level-tab-stop:.5in; 	mso-level-number-position:left; 	text-indent:-.25in; 	font-family:Symbol;} ol 	{margin-bottom:0in;} ul 	{margin-bottom:0in;} --> <!--[if gte mso 10]&gt;   /* Style Definitions */  table.MsoNormalTable 	{mso-style-name:"Table Normal"; 	mso-tstyle-rowband-size:0; 	mso-tstyle-colband-size:0; 	mso-style-noshow:yes; 	mso-style-parent:""; 	mso-padding-alt:0in 5.4pt 0in 5.4pt; 	mso-para-margin:0in; 	mso-para-margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:10.0pt; 	font-family:"Times New Roman"; 	mso-ansi-language:#0400; 	mso-fareast-language:#0400; 	mso-bidi-language:#0400;}  --><em><span></span></em></p>
<p class="MsoNormal"><span>For any security program, you must start at the basics and begin with a information security plan. In a SAS 70 audit, an auditor will examine a CIO&#8217;s operations to determine that you have security program management, incident response, and that appropriate training is provided to your employees. Your security plan should include at least include: </span></p>
<p class="MsoNormal"><!--[if !supportLists]--><span><span>·<span>          </span></span></span><!--[endif]--><span>Procedures to protect and provide access to IT systems and applications</span></p>
<p class="MsoNormal"><!--[if !supportLists]--><span><span>·<span>          </span></span></span><!--[endif]--><span>Procedures to report incidents when they occur</span></p>
<p class="MsoNormal"><!--[if !supportLists]--><span><span>·<span>          </span></span></span><!--[endif]--><span>Investigation practices required to prevent future incidents</span></p>
<p class="MsoNormal"><!--[if !supportLists]--><span><span>·<span>          </span></span></span><!--[endif]--><span>The right to revoke any user access at anytime</span></p>
<p class="MsoNormal"><span> </span></p>
<p class="MsoNormal"><span>Training should occur regularly for all employees and no employee should be granted access to your systems without taking your company’s network security training. Do you have a plan in place? If so, send me a generic sample and I will share it with our readers. Sas70expert@gmail.com</span></p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/sas-70/back-to-basics-%e2%80%93-security-awareness-and-education-%e2%80%93-sas70/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Security is essential for all new technology investments? SAS70</title>
		<link>http://itknowledgeexchange.techtarget.com/sas-70/security-is-essential-for-all-new-technology-investments-sas70/</link>
		<comments>http://itknowledgeexchange.techtarget.com/sas-70/security-is-essential-for-all-new-technology-investments-sas70/#comments</comments>
		<pubDate>Sun, 21 Sep 2008 21:22:21 +0000</pubDate>
		<dc:creator>SAS70ExPERT</dc:creator>
				<category><![CDATA[Auditing]]></category>
		<category><![CDATA[Management]]></category>
		<category><![CDATA[Network]]></category>
		<category><![CDATA[SAS 70]]></category>
		<category><![CDATA[Security management]]></category>
		<category><![CDATA[Third-party services]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/sas-70/security-is-essential-for-all-new-technology-investments-sas70/</guid>
		<description><![CDATA[Which new technologies are you adopting? With Web 2.0, social networking, wikis, and blogs – oh mY! With so many new avenues to penetrate your market, the decisions you make today can effect the success of your SAS 70 audit. When evaluating new technology, always first determine your company objectives as we previously discussed. In [...]]]></description>
				<content:encoded><![CDATA[<p><!--[if gte mso 9]&gt;     Normal   0         false   false   false                             MicrosoftInternetExplorer4   --><!--[if gte mso 9]&gt;     --> <!--  /* Font Definitions */  @font-face 	{font-family:Bembo; 	panose-1:0 0 0 0 0 0 0 0 0 0; 	mso-font-charset:0; 	mso-generic-font-family:roman; 	mso-font-format:other; 	mso-font-pitch:auto; 	mso-font-signature:3 0 0 0 1 0;}  /* Style Definitions */  p.MsoNormal, li.MsoNormal, div.MsoNormal 	{mso-style-parent:""; 	margin:0in; 	margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:12.0pt; 	font-family:"Times New Roman"; 	mso-fareast-font-family:"Times New Roman";} @page Section1 	{size:8.5in 11.0in; 	margin:1.0in 1.25in 1.0in 1.25in; 	mso-header-margin:.5in; 	mso-footer-margin:.5in; 	mso-paper-source:0;} div.Section1 	{page:Section1;} --> <!--[if gte mso 10]&gt;   /* Style Definitions */  table.MsoNormalTable 	{mso-style-name:"Table Normal"; 	mso-tstyle-rowband-size:0; 	mso-tstyle-colband-size:0; 	mso-style-noshow:yes; 	mso-style-parent:""; 	mso-padding-alt:0in 5.4pt 0in 5.4pt; 	mso-para-margin:0in; 	mso-para-margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:10.0pt; 	font-family:"Times New Roman"; 	mso-ansi-language:#0400; 	mso-fareast-language:#0400; 	mso-bidi-language:#0400;}  --></p>
<p class="MsoNormal"><span>Which new technologies are you adopting? With Web 2.0, social networking, wikis, and blogs – oh mY! With so many new avenues to penetrate your market, the decisions you make today can effect the success of your SAS 70 audit. When evaluating new technology, always first determine your company objectives as we previously discussed. In addition, you will need to remember to consider what new security features must be implemented in your computing environment to prevent downtime. It is essential early in the process that you identify the threats, the risks, and then create a plan.</span></p>
<p class="MsoNormal"><span> </span></p>
<p class="MsoNormal"><span><span> </span></span><span>In identifying threats, the assessment team must consider who or what could compromise a target system’s components such that the system’s security attributes would be jeopardized. You should focus on how the information assets and components differ from what you already have. In identifying the security risks, consider what will th total potential impact on the organization. When your system is compromised – and it will be – how would you handle the loss of critical data?</span></p>
<p class="MsoNormal"><span> </span></p>
<p class="MsoNormal"><span>To address technology security risks, requires a documented plan and you must train your employees on how to enact the plan. The SAS70 audit will require you to have a plan in place and it will examine who are the participants in the plan. The plan should include not only IT, but operations and senior management. Where is your security plan? SAS70ExPERT@gmail.com</span></p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/sas-70/security-is-essential-for-all-new-technology-investments-sas70/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Risk Assessments and the SAS 70 audit</title>
		<link>http://itknowledgeexchange.techtarget.com/sas-70/risk-assessments-and-the-sas-70-audit/</link>
		<comments>http://itknowledgeexchange.techtarget.com/sas-70/risk-assessments-and-the-sas-70-audit/#comments</comments>
		<pubDate>Wed, 17 Sep 2008 15:35:03 +0000</pubDate>
		<dc:creator>SAS70ExPERT</dc:creator>
				<category><![CDATA[Access]]></category>
		<category><![CDATA[Auditing]]></category>
		<category><![CDATA[CIO]]></category>
		<category><![CDATA[COBIT]]></category>
		<category><![CDATA[Management]]></category>
		<category><![CDATA[Monitoring]]></category>
		<category><![CDATA[Network]]></category>
		<category><![CDATA[Risk management]]></category>
		<category><![CDATA[SAS 70]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/sas-70/risk-assessments-and-the-sas-70-audit/</guid>
		<description><![CDATA[Management’s risk assessment process is required to be audited in a SAS70 examination; however, in my experience, most auditors do not adequately review Management’s risk assessment process. Without adequate auditing experience, most auditors would not have a basis to determine if Management had reviewed the control risk universe. In addition, Management mostly does not formally [...]]]></description>
				<content:encoded><![CDATA[<p><!--[if !mso]&gt;  v\:* {behavior:url(#default#VML);} o\:* {behavior:url(#default#VML);} w\:* {behavior:url(#default#VML);} .shape {behavior:url(#default#VML);}  --><!--[if gte mso 9]&gt;     Normal   0         false   false   false                             MicrosoftInternetExplorer4   --><!--[if gte mso 9]&gt;     --> <!--  /* Font Definitions */  @font-face 	{font-family:"Arial Narrow"; 	panose-1:2 11 5 6 2 2 2 3 2 4; 	mso-font-charset:0; 	mso-generic-font-family:swiss; 	mso-font-pitch:variable; 	mso-font-signature:647 0 0 0 159 0;}  /* Style Definitions */  p.MsoNormal, li.MsoNormal, div.MsoNormal 	{mso-style-parent:""; 	margin:0in; 	margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:12.0pt; 	font-family:"Times New Roman"; 	mso-fareast-font-family:"Times New Roman";} a:link, span.MsoHyperlink 	{color:blue; 	text-decoration:underline; 	text-underline:single;} a:visited, span.MsoHyperlinkFollowed 	{color:purple; 	text-decoration:underline; 	text-underline:single;} @page Section1 	{size:8.5in 11.0in; 	margin:1.0in 1.25in 1.0in 1.25in; 	mso-header-margin:.5in; 	mso-footer-margin:.5in; 	mso-paper-source:0;} div.Section1 	{page:Section1;} --> <!--[if gte mso 10]&gt;   /* Style Definitions */  table.MsoNormalTable 	{mso-style-name:"Table Normal"; 	mso-tstyle-rowband-size:0; 	mso-tstyle-colband-size:0; 	mso-style-noshow:yes; 	mso-style-parent:""; 	mso-padding-alt:0in 5.4pt 0in 5.4pt; 	mso-para-margin:0in; 	mso-para-margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:10.0pt; 	font-family:"Times New Roman"; 	mso-ansi-language:#0400; 	mso-fareast-language:#0400; 	mso-bidi-language:#0400;}  --><!--[if gte mso 9]&gt;   --><!--[if gte mso 9]&gt;       --><span></span></p>
<p class="MsoNormal"><span>Management’s risk assessment process is required to be audited in a SAS70 examination; however, in my experience, most auditors do not adequately review Management’s risk assessment process. Without adequate auditing experience, most auditors would not have a basis to determine if Management had reviewed the control risk universe. In addition, Management mostly does not formally document risks, but they are discussed only in Board meeting with among C-level executive’s. The COBIT risk assessment framework can provide Management with the criteria and the details that an inexperienced auditor may use as a guide to examine their risk assessment process</span></p>
<p class="MsoNormal"><span> </span></p>
<p class="MsoNormal"><span>COBIT consists</span><span> of information that is required to help achieve business objectives. You must first begin with a vulnerability analysis of your business operations. Then determine the threats to these vulnerabilities For example, your greatest risk may be related to the legal liabilities due to incorrect financial statements….. or something more simpler, like loss of a backup tape which contained your customers social security numbers. Third, determine the impact of this threat. Is it a million dollar monetary fine, or could your license to conduct business be taken away. The conclusion is an action plan after which the cycle can start again. </span></p>
<p class="MsoNormal"><span> </span></p>
<p class="MsoNormal"><span>When the SAS 70 auditor discusses your risk assessment process, don’t be afraid to say that you have it all stored in your brain. Without risk documentation, an experience auditing firm will assist you in forming a roadmap of risks that lead to your business success. Mr. CIO, have you determine what are your business risks or your information technology risks today? Have you formally discussed and evaluated them with other c-level executives or with your peers and association’s within your industry. Note from the diagram below the a formal risk assessment process. Next time we will discuss each of these layers in detail. <a href="mailto:SAS70ExPERT@gmail.com">SAS70ExPERT@gmail.com</a> </span></p>
<p class="MsoNormal"><span> </span></p>
<p class="MsoNormal"><!--[if mso &amp; !supportInlineShapes &amp; supportFields]&gt;<span><span></span><span> </span>SHAPE<span>  </span>\* MERGEFORMAT <span></span></span>&#8211;><span><!--[if gte vml 1]&gt;-->                                                                                       </p>
<table cellpadding="0" cellspacing="0" width="100%">
<tr>
<td>
<div>
<p class="MsoNormal" align="center"><span>Asset</span></p>
<p class="MsoNormal" align="center"><span>Identification</span></p>
<p class="MsoNormal" align="center"><span>and Valuation</span></p>
</div>
</td>
</tr>
</table>
<table cellpadding="0" cellspacing="0" width="100%">
<tr>
<td>
<div>
<p class="MsoNormal"><span>Vulnerability</span></p>
<p class="MsoNormal"><span>&nbsp;</span></p>
</div>
</td>
</tr>
</table>
<table cellpadding="0" cellspacing="0" width="100%">
<tr>
<td>
<div>
<p class="MsoNormal"><span><span> </span>Assessment</span></p>
</div>
</td>
</tr>
</table>
<table cellpadding="0" cellspacing="0" width="100%">
<tr>
<td>
<div>
<p class="MsoNormal"><span><span>   </span>Threat</span></p>
<p class="MsoNormal"><span>&nbsp;</span></p>
</div>
</td>
</tr>
</table>
<table cellpadding="0" cellspacing="0" width="100%">
<tr>
<td>
<div>
<p class="MsoNormal"><span>Assessment</span></p>
</div>
</td>
</tr>
</table>
<table cellpadding="0" cellspacing="0" width="100%">
<tr>
<td>
<div>
<p class="MsoNormal"><span><span>    </span>Risk</span></p>
<p class="MsoNormal"><span>&nbsp;</span></p>
</div>
</td>
</tr>
</table>
<table cellpadding="0" cellspacing="0" width="100%">
<tr>
<td>
<div>
<p class="MsoNormal"><span>Assessment</span></p>
</div>
</td>
</tr>
</table>
<table cellpadding="0" cellspacing="0" width="100%">
<tr>
<td>
<div>
<p class="MsoNormal"><span><span> </span>Counter-</span></p>
<p class="MsoNormal"><span>&nbsp;</span></p>
</div>
</td>
</tr>
</table>
<table cellpadding="0" cellspacing="0" width="100%">
<tr>
<td>
<div>
<p class="MsoNormal"><span><span> </span>measures</span></p>
</div>
</td>
</tr>
</table>
<table cellpadding="0" cellspacing="0" width="100%">
<tr>
<td>
<div>
<p class="MsoNormal"><span><span> </span></span><span>Control</span></p>
<p class="MsoNormal"><span>&nbsp;</span></p>
</div>
</td>
</tr>
</table>
<table cellpadding="0" cellspacing="0" width="100%">
<tr>
<td>
<div>
<p class="MsoNormal"><span>Evaluation</span></p>
</div>
</td>
</tr>
</table>
<table cellpadding="0" cellspacing="0" width="100%">
<tr>
<td>
<div>
<p class="MsoNormal"><span>Residual</span></p>
<p class="MsoNormal"><span>&nbsp;</span></p>
</div>
</td>
</tr>
</table>
<table cellpadding="0" cellspacing="0" width="100%">
<tr>
<td>
<div>
<p class="MsoNormal"><span>Risk</span></p>
</div>
</td>
</tr>
</table>
<table cellpadding="0" cellspacing="0" width="100%">
<tr>
<td>
<div>
<p class="MsoNormal"><span>Action</span></p>
<p class="MsoNormal"><span>&nbsp;</span></p>
</div>
</td>
</tr>
</table>
<table cellpadding="0" cellspacing="0" width="100%">
<tr>
<td>
<div>
<p class="MsoNormal"><span><span>  </span>Plan</span></p>
</div>
</td>
</tr>
</table>
<p>                                                                                                                                                  <!--[if !vml]--><br />
<!--[endif]--></span><!--[if mso &amp; !supportInlineShapes &amp; supportFields]&gt;<span>   <span></span></span>&#8211;><span></span></p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/sas-70/risk-assessments-and-the-sas-70-audit/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Encrypting for Security &#8211; SAS70</title>
		<link>http://itknowledgeexchange.techtarget.com/sas-70/encrypting-for-security-sas70/</link>
		<comments>http://itknowledgeexchange.techtarget.com/sas-70/encrypting-for-security-sas70/#comments</comments>
		<pubDate>Sun, 14 Sep 2008 23:17:20 +0000</pubDate>
		<dc:creator>SAS70ExPERT</dc:creator>
				<category><![CDATA[Auditing]]></category>
		<category><![CDATA[Development]]></category>
		<category><![CDATA[Encryption]]></category>
		<category><![CDATA[Identity & Access Management]]></category>
		<category><![CDATA[Network]]></category>
		<category><![CDATA[Network monitoring]]></category>
		<category><![CDATA[Networking]]></category>
		<category><![CDATA[routers]]></category>
		<category><![CDATA[Security Program Management]]></category>
		<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/sas-70/encrypting-for-security-sas70/</guid>
		<description><![CDATA[SAS 70 audits review the not only the security of your networks but of the data that is transported across your networks and on the security of your data that remains on your servers and laptops. Before choosing an encryption vendor, there are factors you consider: What administrative actions are required? Can keys be changed [...]]]></description>
				<content:encoded><![CDATA[<p><!--[if gte mso 9]&gt;     Normal   0         false   false   false                             MicrosoftInternetExplorer4   --><!--[if gte mso 9]&gt;     --> <!--  /* Font Definitions */  @font-face 	{font-family:Wingdings; 	panose-1:5 0 0 0 0 0 0 0 0 0; 	mso-font-charset:2; 	mso-generic-font-family:auto; 	mso-font-pitch:variable; 	mso-font-signature:0 268435456 0 0 -2147483648 0;}  /* Style Definitions */  p.MsoNormal, li.MsoNormal, div.MsoNormal 	{mso-style-parent:""; 	margin:0in; 	margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:12.0pt; 	font-family:"Times New Roman"; 	mso-fareast-font-family:"Times New Roman";} @page Section1 	{size:8.5in 11.0in; 	margin:1.0in 1.25in 1.0in 1.25in; 	mso-header-margin:.5in; 	mso-footer-margin:.5in; 	mso-paper-source:0;} div.Section1 	{page:Section1;}  /* List Definitions */  @list l0 	{mso-list-id:1752039948; 	mso-list-type:hybrid; 	mso-list-template-ids:-1997385244 67698689 67698691 67698693 67698689 67698691 67698693 67698689 67698691 67698693;} @list l0:level1 	{mso-level-number-format:bullet; 	mso-level-text:; 	mso-level-tab-stop:.5in; 	mso-level-number-position:left; 	text-indent:-.25in; 	font-family:Symbol;} ol 	{margin-bottom:0in;} ul 	{margin-bottom:0in;} --> <!--[if gte mso 10]&gt;   /* Style Definitions */  table.MsoNormalTable 	{mso-style-name:"Table Normal"; 	mso-tstyle-rowband-size:0; 	mso-tstyle-colband-size:0; 	mso-style-noshow:yes; 	mso-style-parent:""; 	mso-padding-alt:0in 5.4pt 0in 5.4pt; 	mso-para-margin:0in; 	mso-para-margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:10.0pt; 	font-family:"Times New Roman"; 	mso-ansi-language:#0400; 	mso-fareast-language:#0400; 	mso-bidi-language:#0400;}  --></p>
<p class="MsoNormal"><span>SAS 70 audits review the not only the security of your networks but of the data that is transported across your networks and on the security of your data that remains on your servers and laptops. Before choosing an encryption vendor, there are factors you consider:</span></p>
<ul>
<li class="MsoNormal"><span>What administrative actions are      required? Can keys be changed and modified by the user or does your      network administrator have to take action? What if the key is compromised,      can it be changed at will? If the key is changed, how do you remember it? </span></li>
<li class="MsoNormal"><span>What steps are taken to manage keys? Are      keys kept in a secure database or are they managed individually?      Independent solutions allow you more flexibility, but independent users      may not always follow the company standards which may give hackers an opportunity.</span></li>
<li class="MsoNormal"><span>Are multiple keys supported and can you      create a master? The more critical and sensitive the data, the tougher the      key should be crack.<span>  </span></span></li>
<li class="MsoNormal"><span>Is there PKI in corporation? Does the      encryption product integrate with an existing PKI production ro des it      require software in order to function? Any vendor solution should be able      too. SAS70ExPERT@gmail.com</span></li>
</ul>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/sas-70/encrypting-for-security-sas70/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>CIO’s deserve respect? Are you respectable and what are these characteristics? SAS70</title>
		<link>http://itknowledgeexchange.techtarget.com/sas-70/cio%e2%80%99s-deserve-respect-are-you-respectable-and-what-are-these-characteristics-sas70/</link>
		<comments>http://itknowledgeexchange.techtarget.com/sas-70/cio%e2%80%99s-deserve-respect-are-you-respectable-and-what-are-these-characteristics-sas70/#comments</comments>
		<pubDate>Fri, 12 Sep 2008 05:17:50 +0000</pubDate>
		<dc:creator>SAS70ExPERT</dc:creator>
				<category><![CDATA[Auditing]]></category>
		<category><![CDATA[CIO]]></category>
		<category><![CDATA[Compliance]]></category>
		<category><![CDATA[CSO]]></category>
		<category><![CDATA[Network]]></category>
		<category><![CDATA[SAS 70]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/sas-70/cio%e2%80%99s-deserve-respect-are-you-respectable-and-what-are-these-characteristics-sas70/</guid>
		<description><![CDATA[SAS 70 audits focus on COSO controls and examine the leadership experience of executives and training. CIO’s and CSO’s march to the executive suite takes many paths. Opportunities to lead in the C-Level suite come in many forms….some are perhaps luck, others are from angels, but what job titles lead to the CIO or CSO [...]]]></description>
				<content:encoded><![CDATA[<p><!--[if gte mso 9]&gt;     Normal   0         false   false   false                             MicrosoftInternetExplorer4   --><!--[if gte mso 9]&gt;     --> <!--  /* Style Definitions */  p.MsoNormal, li.MsoNormal, div.MsoNormal 	{mso-style-parent:""; 	margin:0in; 	margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:12.0pt; 	font-family:"Times New Roman"; 	mso-fareast-font-family:"Times New Roman";} @page Section1 	{size:8.5in 11.0in; 	margin:1.0in 1.25in 1.0in 1.25in; 	mso-header-margin:.5in; 	mso-footer-margin:.5in; 	mso-paper-source:0;} div.Section1 	{page:Section1;} --> <!--[if gte mso 10]&gt;   /* Style Definitions */  table.MsoNormalTable 	{mso-style-name:"Table Normal"; 	mso-tstyle-rowband-size:0; 	mso-tstyle-colband-size:0; 	mso-style-noshow:yes; 	mso-style-parent:""; 	mso-padding-alt:0in 5.4pt 0in 5.4pt; 	mso-para-margin:0in; 	mso-para-margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:10.0pt; 	font-family:"Times New Roman"; 	mso-ansi-language:#0400; 	mso-fareast-language:#0400; 	mso-bidi-language:#0400;}  --></p>
<p class="MsoNormal">SAS 70 audits focus on COSO controls and examine the leadership experience of executives and training. CIO’s and CSO’s march to the executive suite takes many paths. Opportunities to lead in the C-Level suite come in many forms….some are perhaps luck, others are from angels, but what job titles lead to the CIO or CSO role? According to a recent survey, most CIO’s have a background primarily in IT. In recent, weeks, I have begun to question this polling as I have met several well-respected CIO’s who understand strategy and operations, but do not have a clue as to operating systems, applications or how networks function. In this same poll, only 15% of CIO’s and CSO’ came from areas outside of IT. What side of the fence do you stand on? Do you think an extensive background and training in information technology makes a difference as a c-level executive? As I consider myself a hybrid with a little knowledge and experience on both sides of the fence, I wonder what is respectable? SAS70ExPERT@gmail.com</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/sas-70/cio%e2%80%99s-deserve-respect-are-you-respectable-and-what-are-these-characteristics-sas70/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Successful traits of a CIO equal successful SAS70 audits (Part 5) – SAS 70</title>
		<link>http://itknowledgeexchange.techtarget.com/sas-70/successful-traits-of-a-cio-equal-successful-sas70-audits-part-5-%e2%80%93-sas-70/</link>
		<comments>http://itknowledgeexchange.techtarget.com/sas-70/successful-traits-of-a-cio-equal-successful-sas70-audits-part-5-%e2%80%93-sas-70/#comments</comments>
		<pubDate>Fri, 05 Sep 2008 07:19:40 +0000</pubDate>
		<dc:creator>SAS70ExPERT</dc:creator>
				<category><![CDATA[Auditing]]></category>
		<category><![CDATA[CIO]]></category>
		<category><![CDATA[Compliance]]></category>
		<category><![CDATA[Financials]]></category>
		<category><![CDATA[Network]]></category>
		<category><![CDATA[SAS 70]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/sas-70/successful-traits-of-a-cio-equal-successful-sas70-audits-part-5-%e2%80%93-sas-70/</guid>
		<description><![CDATA[SAS 70 SAS70 Do you have 3 mainframes systems and one stand alone application that you use for recording financial results? Do any of these systems talk to one another? Are you starting to use Saas applications to better manage your data? Knowing how to leverage technologies, old or new, is key to being an [...]]]></description>
				<content:encoded><![CDATA[<p><TITLE>SAS 70 SAS70 </TITLE></p>
<p><!--[if gte mso 9]&gt;     Normal   0         false   false   false                             MicrosoftInternetExplorer4   --><!--[if gte mso 9]&gt;     --><!--[if !mso]&gt;  st1\:*{behavior:url(#ieooui) }  --> <!--  /* Style Definitions */  p.MsoNormal, li.MsoNormal, div.MsoNormal 	{mso-style-parent:""; 	margin:0in; 	margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:12.0pt; 	font-family:"Times New Roman"; 	mso-fareast-font-family:"Times New Roman";} @page Section1 	{size:8.5in 11.0in; 	margin:1.0in 1.25in 1.0in 1.25in; 	mso-header-margin:.5in; 	mso-footer-margin:.5in; 	mso-paper-source:0;} div.Section1 	{page:Section1;} --> <!--[if gte mso 10]&gt;   /* Style Definitions */  table.MsoNormalTable 	{mso-style-name:"Table Normal"; 	mso-tstyle-rowband-size:0; 	mso-tstyle-colband-size:0; 	mso-style-noshow:yes; 	mso-style-parent:""; 	mso-padding-alt:0in 5.4pt 0in 5.4pt; 	mso-para-margin:0in; 	mso-para-margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:10.0pt; 	font-family:"Times New Roman"; 	mso-ansi-language:#0400; 	mso-fareast-language:#0400; 	mso-bidi-language:#0400;}  --></p>
<p class="MsoNormal">Do you have 3 mainframes systems and one stand alone application that you use for recording financial results? Do any of these systems talk to one another? Are you starting to use Saas applications to better manage your data? Knowing how to leverage technologies, old or new, is key to being an effective CIO.</p>
<p class="MsoNormal"> </p>
<p class="MsoNormal">During a SAS70 audit, it is critical that you have an deep understanding of your systems and how they work together. If you are able to provide documentation, such as network diagrams, and data hierarchies to your auditor, then they will be more efficient when determining the controls necessary to be tested within your organization. An effective CIO cannot leverage technologies within corporate walls or as outsourced solutions without having a complete understanding of IT networks, applications, and operating systems. What helps you know how to leverage your company technologies? Or to predict what technologies will work best within your company? sas70expert@gmail.com</p>
<p class="MsoNormal"> </p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/sas-70/successful-traits-of-a-cio-equal-successful-sas70-audits-part-5-%e2%80%93-sas-70/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Is pre-boot authentication required? SAS70</title>
		<link>http://itknowledgeexchange.techtarget.com/sas-70/is-pre-boot-authentication-required-sas70/</link>
		<comments>http://itknowledgeexchange.techtarget.com/sas-70/is-pre-boot-authentication-required-sas70/#comments</comments>
		<pubDate>Wed, 20 Aug 2008 04:26:41 +0000</pubDate>
		<dc:creator>SAS70ExPERT</dc:creator>
				<category><![CDATA[Access]]></category>
		<category><![CDATA[Access control]]></category>
		<category><![CDATA[Management]]></category>
		<category><![CDATA[Network]]></category>
		<category><![CDATA[SAS 70]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/sas-70/is-pre-boot-authentication-required-sas70/</guid>
		<description><![CDATA[SAS 70 audits review the authentication procedures required to access computer equipment, including the pre-boot authentication (PBA) procedure.  If pre-boot authentication is not required, then the risks of gaining access to your Company data is very high. What is PBA? Pre-boot authentication is a process that requires a user to authenticate to the operating system [...]]]></description>
				<content:encoded><![CDATA[<p>SAS 70 audits review the authentication procedures required to access computer equipment, including the pre-boot authentication (PBA) procedure.  If pre-boot authentication is not required, then the risks of gaining access to your Company data is very high.</p>
<p>What is PBA? Pre-boot authentication is a process that requires a user to authenticate to the operating system prior to loading of the application software. The user must enter his credentials &#8211; a username and password before the system load begins. Once authenticated, then Windows or Linux operating system is loaded. If the correct user name and password are not entered, the pre-boot authentication process will not load the operating system and the computer will lock down.</p>
<p>Pre-boot authentication prevents a criminal hacker from gaining access to your data by not loading the operating system. Since the bypass tools load after the operating system, then a hacker want get a chance to try to gain entry or use the Windows XP or Vista emergency disks.  SAS70ExPERT@gmail.com</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/sas-70/is-pre-boot-authentication-required-sas70/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Telecommuting as a SAS70 audit control? – SAS70ExPERT</title>
		<link>http://itknowledgeexchange.techtarget.com/sas-70/telecommuting-as-a-sas70-audit-control-%e2%80%93-sas70expert/</link>
		<comments>http://itknowledgeexchange.techtarget.com/sas-70/telecommuting-as-a-sas70-audit-control-%e2%80%93-sas70expert/#comments</comments>
		<pubDate>Sun, 10 Aug 2008 19:54:58 +0000</pubDate>
		<dc:creator>SAS70ExPERT</dc:creator>
				<category><![CDATA[Access control]]></category>
		<category><![CDATA[Auditing]]></category>
		<category><![CDATA[CIO]]></category>
		<category><![CDATA[Compliance]]></category>
		<category><![CDATA[Network]]></category>
		<category><![CDATA[SAS 70]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Telecommuting]]></category>
		<category><![CDATA[Third-party services]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/sas-70/telecommuting-as-a-sas70-audit-control-%e2%80%93-sas70expert/</guid>
		<description><![CDATA[As transportation costs continue to skyrocket over the summer, telework/telecommuting is becoming the new trend among office environments. Basically, we have been doing a form of telework by outsourcing all of our jobs overseas, so this premise is not really new, it’s just new for American workers. 92 percent of workers said their work could [...]]]></description>
				<content:encoded><![CDATA[<p><!--[if gte mso 9]&gt;     Normal   0         false   false   false                             MicrosoftInternetExplorer4   --><!--[if gte mso 9]&gt;     --><!--[if !mso]&gt;  st1\:*{behavior:url(#ieooui) }  --> <!--  /* Style Definitions */  p.MsoNormal, li.MsoNormal, div.MsoNormal 	{mso-style-parent:""; 	margin:0in; 	margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:12.0pt; 	font-family:"Times New Roman"; 	mso-fareast-font-family:"Times New Roman";} @page Section1 	{size:8.5in 11.0in; 	margin:1.0in 1.25in 1.0in 1.25in; 	mso-header-margin:.5in; 	mso-footer-margin:.5in; 	mso-paper-source:0;} div.Section1 	{page:Section1;}  /* List Definitions */  @list l0 	{mso-list-id:1625775100; 	mso-list-type:hybrid; 	mso-list-template-ids:-1362885200 67698705 67698713 67698715 67698703 67698713 67698715 67698703 67698713 67698715;} @list l0:level1 	{mso-level-text:"%1\)"; 	mso-level-tab-stop:.5in; 	mso-level-number-position:left; 	text-indent:-.25in;} ol 	{margin-bottom:0in;} ul 	{margin-bottom:0in;} --> <!--[if gte mso 10]&gt;   /* Style Definitions */  table.MsoNormalTable 	{mso-style-name:"Table Normal"; 	mso-tstyle-rowband-size:0; 	mso-tstyle-colband-size:0; 	mso-style-noshow:yes; 	mso-style-parent:""; 	mso-padding-alt:0in 5.4pt 0in 5.4pt; 	mso-para-margin:0in; 	mso-para-margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:10.0pt; 	font-family:"Times New Roman"; 	mso-ansi-language:#0400; 	mso-fareast-language:#0400; 	mso-bidi-language:#0400;}  --></p>
<p class="MsoNormal">As transportation costs continue to skyrocket over the summer, telework/telecommuting is becoming the new trend among office environments. Basically, we have been doing a form of telework by outsourcing all of our jobs overseas, so this premise is not really new, it’s just new for American workers. 92 percent of workers said their work could be performed from home according to a recent survey by advocacy group Telework Exchange. I agree that operating expenses could be reduced by:</p>
<p class="MsoNormal"><!--[if !supportLists]--><span>1)<span>      </span></span><!--[endif]-->less office space per employee</p>
<p class="MsoNormal"><!--[if !supportLists]--><span>2)<span>      </span></span><!--[endif]-->transportation costs are reduced from commuting to work</p>
<p class="MsoNormal"><!--[if !supportLists]--><span>3)<span>      </span></span><!--[endif]-->reduction in computer hardware expenses</p>
<p class="MsoNormal"> </p>
<p class="MsoNormal">But what is the downside of a remote workforce and what effect will that have on company information assets? These information assets are now stored at a families home on First Avenue, in a 3 bedroom, 2 bath, instead of your 5 story office building. These telecommuting risks will need to examined by management and should be considered in a SAS70 audit.</p>
<p class="MsoNormal"> </p>
<p class="MsoNormal">Consider that most employee homes will not have extended physical or environmental security – only garage door locks and an air conditioner. Their computer office could be located next to their children’s bathroom – which is a likely water hazard, in an open space by a garden window. How easy would it be for a burgular to reach in and knock your coffee cup over, and grab your computer from your first floor home office?Really EASY, as I think many homes today still have yet to have a home alarm system on their windows.Critical company information now could be sold on the internet.</p>
<p class="MsoNormal">&nbsp;</p>
<p class="MsoNormal">In addition, what network security are you assured that they have on their home computer? Do they have the latest virus preventing application? Is their firewall always up and running or might it be turned off to watch a movie?</p>
<p class="MsoNormal">&nbsp;</p>
<p class="MsoNormal">Is your IT staff prepared to make housecalls? Your company information assets now resids at your employees home. It is now not on the second floor of your office, but could be 20-30 miles to First Avenue home. You now must manage users that are at locations that are spread miles apart? This may be okay if 15% of your workforce is remote, but what if it is 92%? Is your IT staff trained accordingly? If they have to make housecalls, do transportation costs truly decrease? Who is managing the network while your IT Administrator is stuck in traffic on his way to the Marketing Director&#8217;s home to fix his computer?</p>
<p class="MsoNormal">&nbsp;</p>
<p class="MsoNormal">Any third party vendor must complete a SAS70 audit to assure it customer that their data is secure. Are you ready to expand your company floor space beyond the office perimeter? Telecommuting risks must be considered in the SAS70 audit process. What are some of the risks you have identified? Do you even have any policies in place at your company which specifically discuss the do’s and don’t’s of a telecommuter? SAS70ExPERT@gmail.com</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/sas-70/telecommuting-as-a-sas70-audit-control-%e2%80%93-sas70expert/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
