 




<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>SAS 70 &#187; Third-party services</title>
	<atom:link href="http://itknowledgeexchange.techtarget.com/sas-70/tag/third-party-services/feed/" rel="self" type="application/rss+xml" />
	<link>http://itknowledgeexchange.techtarget.com/sas-70</link>
	<description></description>
	<lastBuildDate>Tue, 23 Dec 2008 17:58:25 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	
		<item>
		<title>Third party services and SAS70 audit</title>
		<link>http://itknowledgeexchange.techtarget.com/sas-70/third-party-services-and-sas70-audit/</link>
		<comments>http://itknowledgeexchange.techtarget.com/sas-70/third-party-services-and-sas70-audit/#comments</comments>
		<pubDate>Tue, 09 Dec 2008 01:16:46 +0000</pubDate>
		<dc:creator>SAS70ExPERT</dc:creator>
				<category><![CDATA[Management]]></category>
		<category><![CDATA[SAS 70]]></category>
		<category><![CDATA[Third-party services]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/sas-70/third-party-services-and-sas70-audit/</guid>
		<description><![CDATA[During a SAS 70 audit, an auditor may examine any relationships with third parties.  Any third party agreements or service level agreements should contain:   1.       procedures to protect all outsourced data, applications or hardware 2.       a description of the services provided and the target level of services 3.       the establishment of an escalation process [...]]]></description>
				<content:encoded><![CDATA[<p><!--[if gte mso 9]&gt;     Normal   0         false   false   false                             MicrosoftInternetExplorer4   --><!--[if gte mso 9]&gt;     --> <!--  /* Font Definitions */  @font-face 	{font-family:Verdana; 	panose-1:2 11 6 4 3 5 4 4 2 4; 	mso-font-charset:0; 	mso-generic-font-family:swiss; 	mso-font-pitch:variable; 	mso-font-signature:536871559 0 0 0 415 0;}  /* Style Definitions */  p.MsoNormal, li.MsoNormal, div.MsoNormal 	{mso-style-parent:""; 	margin:0in; 	margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:12.0pt; 	font-family:"Times New Roman"; 	mso-fareast-font-family:"Times New Roman";} a:link, span.MsoHyperlink 	{color:blue; 	text-decoration:underline; 	text-underline:single;} a:visited, span.MsoHyperlinkFollowed 	{color:purple; 	text-decoration:underline; 	text-underline:single;} @page Section1 	{size:8.5in 11.0in; 	margin:1.0in 1.25in 1.0in 1.25in; 	mso-header-margin:.5in; 	mso-footer-margin:.5in; 	mso-paper-source:0;} div.Section1 	{page:Section1;}  /* List Definitions */  @list l0 	{mso-list-id:1011951001; 	mso-list-type:hybrid; 	mso-list-template-ids:777698078 67698703 67698713 67698715 67698703 67698713 67698715 67698703 67698713 67698715;} @list l0:level1 	{mso-level-tab-stop:.5in; 	mso-level-number-position:left; 	text-indent:-.25in;} ol 	{margin-bottom:0in;} ul 	{margin-bottom:0in;} --> <!--[if gte mso 10]&gt;   /* Style Definitions */  table.MsoNormalTable 	{mso-style-name:"Table Normal"; 	mso-tstyle-rowband-size:0; 	mso-tstyle-colband-size:0; 	mso-style-noshow:yes; 	mso-style-parent:""; 	mso-padding-alt:0in 5.4pt 0in 5.4pt; 	mso-para-margin:0in; 	mso-para-margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:10.0pt; 	font-family:"Times New Roman"; 	mso-ansi-language:#0400; 	mso-fareast-language:#0400; 	mso-bidi-language:#0400;}  --><em><span></span></em></p>
<p class="MsoNormal"><span>During a SAS 70 audit, an auditor may examine any relationships with third parties.<span>  </span>Any third party agreements or service level agreements should contain:</span></p>
<p class="MsoNormal"><span> </span></p>
<p class="MsoNormal"><!--[if !supportLists]--><span><span>1.<span>       </span></span></span><!--[endif]--><span>procedures to protect all outsourced data, applications or hardware</span></p>
<p class="MsoNormal"><!--[if !supportLists]--><span><span>2.<span>       </span></span></span><!--[endif]--><span>a description of the services provided and the target level of services</span></p>
<p class="MsoNormal"><!--[if !supportLists]--><span><span>3.<span>       </span></span></span><!--[endif]--><span>the establishment of an escalation process should an incident occur</span></p>
<p class="MsoNormal"><!--[if !supportLists]--><span><span>4.<span>       </span></span></span><!--[endif]--><span>the right to audit and determine that they are adhering to your agreement</span></p>
<p class="MsoNormal"><!--[if !supportLists]--><span><span>5.<span>       </span></span></span><!--[endif]--><span>the respective liabilities of both parties should an incident occur.</span></p>
<p class="MsoNormal"><span> </span></p>
<p class="MsoNormal"><span>During a SAS70 audit, you have a choice to exclude your outsourced services or include them in the examination. I would recommend you include them, especially if they are essential to the services you are providing to your customers. <a href="mailto:SAS70ExPERT@gmail.com">SAS70ExPERT@gmail.com</a></span></p>
<p class="MsoNormal"><span> </span></p>
<p class="MsoNormal"><em><span> </span></em></p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/sas-70/third-party-services-and-sas70-audit/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Outsource with a Plan &#8211; SAS70</title>
		<link>http://itknowledgeexchange.techtarget.com/sas-70/outsource-with-a-plan-sas70/</link>
		<comments>http://itknowledgeexchange.techtarget.com/sas-70/outsource-with-a-plan-sas70/#comments</comments>
		<pubDate>Thu, 27 Nov 2008 01:40:56 +0000</pubDate>
		<dc:creator>SAS70ExPERT</dc:creator>
				<category><![CDATA[Disaster Recovery]]></category>
		<category><![CDATA[Monitoring]]></category>
		<category><![CDATA[SaaS]]></category>
		<category><![CDATA[SAS 70]]></category>
		<category><![CDATA[Third-party services]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/sas-70/outsource-with-a-plan-sas70/</guid>
		<description><![CDATA[As more businesses outsource IT to third-party services, data privacy and integrity are paramount to the success of your operations. The SaaS small and medium businesses have a responsibility to ensure your data is processed correctly and that it is kept safe. SAS 70 audits are requirement. Before outsourcing to save funds, make sure you [...]]]></description>
				<content:encoded><![CDATA[<p>As more businesses outsource IT to third-party services, data privacy and integrity are paramount to the success of your operations. The SaaS small and medium businesses have a responsibility to ensure your data is processed correctly and that it is kept safe. SAS 70 audits are requirement.</p>
<p>Before outsourcing to save funds, make sure you have a defined plan. Without it, one small security breach of a politicians&#8217; social security number can destroy your company reputation and your ability to generate new business. This plan should included:</p>
<p>1)definitions related to service levels. You will require your vendor to have uptime of at least 99%.</p>
<p>2) the ability to process your information quickly. Customers accesses your company website and purchasing items should occur relatively fast.</p>
<p>3) reporting functions which allow you monitoring capability and to  capture your data and analyze.</p>
<p>4) a Disaster Recovery plan, a single hardware failure can result in the loss of business.</p>
<p>SAS70expert@gmail.com</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/sas-70/outsource-with-a-plan-sas70/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Third party agreements and SAS70 audit &#8211; SAS 70</title>
		<link>http://itknowledgeexchange.techtarget.com/sas-70/third-party-agreements-and-sas70-audit-sas-70/</link>
		<comments>http://itknowledgeexchange.techtarget.com/sas-70/third-party-agreements-and-sas70-audit-sas-70/#comments</comments>
		<pubDate>Wed, 22 Oct 2008 02:26:05 +0000</pubDate>
		<dc:creator>SAS70ExPERT</dc:creator>
				<category><![CDATA[Management]]></category>
		<category><![CDATA[Monitoring]]></category>
		<category><![CDATA[SAS 70]]></category>
		<category><![CDATA[Third-party services]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/sas-70/third-party-agreements-and-sas70-audit-sas-70/</guid>
		<description><![CDATA[  During a SAS70 audit, an auditor may examine any relationships with third parties.  Any third party agreements or service level agreements should contain:   1.       procedures to protect all outsourced data, applications or hardware 2.       a description of the services provided and the target level of services 3.       the establishment of an escalation process [...]]]></description>
				<content:encoded><![CDATA[<p><!--[if gte mso 9]&gt;     Normal   0         false   false   false                             MicrosoftInternetExplorer4   --><!--[if gte mso 9]&gt;     --> <!--  /* Font Definitions */  @font-face 	{font-family:Verdana; 	panose-1:2 11 6 4 3 5 4 4 2 4; 	mso-font-charset:0; 	mso-generic-font-family:swiss; 	mso-font-pitch:variable; 	mso-font-signature:536871559 0 0 0 415 0;}  /* Style Definitions */  p.MsoNormal, li.MsoNormal, div.MsoNormal 	{mso-style-parent:""; 	margin:0in; 	margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:12.0pt; 	font-family:"Times New Roman"; 	mso-fareast-font-family:"Times New Roman";} a:link, span.MsoHyperlink 	{color:blue; 	text-decoration:underline; 	text-underline:single;} a:visited, span.MsoHyperlinkFollowed 	{color:purple; 	text-decoration:underline; 	text-underline:single;} @page Section1 	{size:8.5in 11.0in; 	margin:1.0in 1.25in 1.0in 1.25in; 	mso-header-margin:.5in; 	mso-footer-margin:.5in; 	mso-paper-source:0;} div.Section1 	{page:Section1;}  /* List Definitions */  @list l0 	{mso-list-id:1011951001; 	mso-list-type:hybrid; 	mso-list-template-ids:777698078 67698703 67698713 67698715 67698703 67698713 67698715 67698703 67698713 67698715;} @list l0:level1 	{mso-level-tab-stop:.5in; 	mso-level-number-position:left; 	text-indent:-.25in;} ol 	{margin-bottom:0in;} ul 	{margin-bottom:0in;} --> <!--[if gte mso 10]&gt;   /* Style Definitions */  table.MsoNormalTable 	{mso-style-name:"Table Normal"; 	mso-tstyle-rowband-size:0; 	mso-tstyle-colband-size:0; 	mso-style-noshow:yes; 	mso-style-parent:""; 	mso-padding-alt:0in 5.4pt 0in 5.4pt; 	mso-para-margin:0in; 	mso-para-margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:10.0pt; 	font-family:"Times New Roman"; 	mso-ansi-language:#0400; 	mso-fareast-language:#0400; 	mso-bidi-language:#0400;}  --><em><span> </span></em></p>
<p class="MsoNormal"><span>During a SAS70 audit, an auditor may examine any relationships with third parties.<span>  </span>Any third party agreements or service level agreements should contain:</span></p>
<p class="MsoNormal"><span> </span></p>
<p class="MsoNormal"><!--[if !supportLists]--><span><span>1.<span>       </span></span></span><!--[endif]--><span>procedures to protect all outsourced data, applications or hardware</span></p>
<p class="MsoNormal"><!--[if !supportLists]--><span><span>2.<span>       </span></span></span><!--[endif]--><span>a description of the services provided and the target level of services</span></p>
<p class="MsoNormal"><!--[if !supportLists]--><span><span>3.<span>       </span></span></span><!--[endif]--><span>the establishment of an escalation process should an incident occur</span></p>
<p class="MsoNormal"><!--[if !supportLists]--><span><span>4.<span>       </span></span></span><!--[endif]--><span>the right to audit and determine that they are adhering to your agreement</span></p>
<p class="MsoNormal"><!--[if !supportLists]--><span><span>5.<span>       </span></span></span><!--[endif]--><span>the respective liabilities of both parties should an incident occur.</span></p>
<p class="MsoNormal"><span> </span></p>
<p class="MsoNormal"><span>During a SAS70 audit, you have a choice to exclude your outsourced services or include them in the examination. I would recommend you include them, especially if they are essential to the services you are providing to your customers. <a href="mailto:SAS70ExPERT@gmail.com">SAS70ExPERT@gmail.com</a></span></p>
<p class="MsoNormal"><span> </span></p>
<p class="MsoNormal"><em><span> </span></em></p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/sas-70/third-party-agreements-and-sas70-audit-sas-70/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Access Rights and SAS70 audit</title>
		<link>http://itknowledgeexchange.techtarget.com/sas-70/access-rights-and-sas70-audit/</link>
		<comments>http://itknowledgeexchange.techtarget.com/sas-70/access-rights-and-sas70-audit/#comments</comments>
		<pubDate>Tue, 21 Oct 2008 00:07:41 +0000</pubDate>
		<dc:creator>SAS70ExPERT</dc:creator>
				<category><![CDATA[Access]]></category>
		<category><![CDATA[Access control]]></category>
		<category><![CDATA[Auditing]]></category>
		<category><![CDATA[SAS 70]]></category>
		<category><![CDATA[Third-party services]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/sas-70/access-rights-and-sas70-audit/</guid>
		<description><![CDATA[Access rights for current employees are essential for the completion of a successful audit. Your company should have a hiring and firing policy that is followed to the letter of the law. When an employee is hired or fired they should have an authorization process to add or delete from company systems or applications. It [...]]]></description>
				<content:encoded><![CDATA[<p><!--[if gte mso 9]&gt;         11.5606   --><!--[if gte mso 9]&gt;     Normal   0         false   false   false                             MicrosoftInternetExplorer4   --><!--[if gte mso 9]&gt;     --> <!--  /* Font Definitions */  @font-face 	{font-family:Verdana; 	panose-1:2 11 6 4 3 5 4 4 2 4; 	mso-font-charset:0; 	mso-generic-font-family:swiss; 	mso-font-pitch:variable; 	mso-font-signature:536871559 0 0 0 415 0;}  /* Style Definitions */  p.MsoNormal, li.MsoNormal, div.MsoNormal 	{mso-style-parent:""; 	margin:0in; 	margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:12.0pt; 	font-family:"Times New Roman"; 	mso-fareast-font-family:"Times New Roman";} @page Section1 	{size:8.5in 11.0in; 	margin:1.0in 1.25in 1.0in 1.25in; 	mso-header-margin:.5in; 	mso-footer-margin:.5in; 	mso-paper-source:0;} div.Section1 	{page:Section1;}  /* List Definitions */  @list l0 	{mso-list-id:421072928; 	mso-list-type:hybrid; 	mso-list-template-ids:-1261133280 67698703 67698713 67698715 67698703 67698713 67698715 67698703 67698713 67698715;} @list l0:level1 	{mso-level-tab-stop:.5in; 	mso-level-number-position:left; 	text-indent:-.25in;} ol 	{margin-bottom:0in;} ul 	{margin-bottom:0in;} --> <!--[if gte mso 10]&gt;   /* Style Definitions */  table.MsoNormalTable 	{mso-style-name:"Table Normal"; 	mso-tstyle-rowband-size:0; 	mso-tstyle-colband-size:0; 	mso-style-noshow:yes; 	mso-style-parent:""; 	mso-padding-alt:0in 5.4pt 0in 5.4pt; 	mso-para-margin:0in; 	mso-para-margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:10.0pt; 	font-family:"Times New Roman"; 	mso-ansi-language:#0400; 	mso-fareast-language:#0400; 	mso-bidi-language:#0400;}  --><em><span></span></em></p>
<p class="MsoNormal"><span>Access rights for current employees are essential for the completion of a successful audit. Your company should have a hiring and firing policy that is followed to the letter of the law. When an employee is hired or fired they should have an authorization process to add or delete from company systems or applications. It is essential that you educate your current employees, contractors, an third party users on this process on a continual basis.</span></p>
<p class="MsoNormal"><span> </span></p>
<p class="MsoNormal"><span>Your company should company not only operating systems or applications, but physical access to company assets. Shared passwords or usernames should be immediately deactivated once an employee or third party leaves. When developing a policy for hiring or terminating consider:</span></p>
<p class="MsoNormal"><span> </span></p>
<p class="MsoNormal"><!--[if !supportLists]--><span><span>1.<span>       </span></span></span><!--[endif]--><span>whether the termination or change of employment will be initiated by your or a third party</span></p>
<p class="MsoNormal"><!--[if !supportLists]--><span><span>2.<span>       </span></span></span><!--[endif]--><span>the current responsibilities of the employee</span></p>
<p class="MsoNormal"><!--[if !supportLists]--><span><span>3.<span>       </span></span></span><!--[endif]--><span>the value of the company assets or data that the employee has access too.</span></p>
<p class="MsoNormal"><span> </span></p>
<p class="MsoNormal"><span>Without a good termination policy or checklist, you will have exceptions within your SAS 70 audit. SAS70ExPERT@gmail.com</span></p>
<p class="MsoNormal"><em><span> </span></em></p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/sas-70/access-rights-and-sas70-audit/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Outsourcing your data backup process – SAS70</title>
		<link>http://itknowledgeexchange.techtarget.com/sas-70/outsourcing-your-data-backup-process-%e2%80%93-sas70/</link>
		<comments>http://itknowledgeexchange.techtarget.com/sas-70/outsourcing-your-data-backup-process-%e2%80%93-sas70/#comments</comments>
		<pubDate>Thu, 25 Sep 2008 11:06:55 +0000</pubDate>
		<dc:creator>SAS70ExPERT</dc:creator>
				<category><![CDATA[Backup]]></category>
		<category><![CDATA[Management]]></category>
		<category><![CDATA[SAS 70]]></category>
		<category><![CDATA[Third-party services]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/sas-70/outsourcing-your-data-backup-process-%e2%80%93-sas70/</guid>
		<description><![CDATA[During the SAS70 audit, an examination will be performed on your data backup process. If you have outsourced this to a local vendor, you are still responsible for making sure that your data is kept safe, secure, and is backed up properly. Hosted or online backup processes are very attractive for small to medium size [...]]]></description>
				<content:encoded><![CDATA[<p><!--[if gte mso 9]&gt;     Normal   0         false   false   false                             MicrosoftInternetExplorer4   --><!--[if gte mso 9]&gt;     --> <!--  /* Font Definitions */  @font-face 	{font-family:Verdana; 	panose-1:2 11 6 4 3 5 4 4 2 4; 	mso-font-charset:0; 	mso-generic-font-family:swiss; 	mso-font-pitch:variable; 	mso-font-signature:536871559 0 0 0 415 0;}  /* Style Definitions */  p.MsoNormal, li.MsoNormal, div.MsoNormal 	{mso-style-parent:""; 	margin:0in; 	margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:12.0pt; 	font-family:"Times New Roman"; 	mso-fareast-font-family:"Times New Roman";} @page Section1 	{size:8.5in 11.0in; 	margin:1.0in 1.25in 1.0in 1.25in; 	mso-header-margin:.5in; 	mso-footer-margin:.5in; 	mso-paper-source:0;} div.Section1 	{page:Section1;} --> <!--[if gte mso 10]&gt;   /* Style Definitions */  table.MsoNormalTable 	{mso-style-name:"Table Normal"; 	mso-tstyle-rowband-size:0; 	mso-tstyle-colband-size:0; 	mso-style-noshow:yes; 	mso-style-parent:""; 	mso-padding-alt:0in 5.4pt 0in 5.4pt; 	mso-para-margin:0in; 	mso-para-margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:10.0pt; 	font-family:"Times New Roman"; 	mso-ansi-language:#0400; 	mso-fareast-language:#0400; 	mso-bidi-language:#0400;}  --></p>
<p class="MsoNormal">
<!--[if gte mso 9]&gt;     Normal   0         false   false   false                             MicrosoftInternetExplorer4   --><!--[if gte mso 9]&gt;     --> <!--  /* Font Definitions */  @font-face 	{font-family:Verdana; 	panose-1:2 11 6 4 3 5 4 4 2 4; 	mso-font-charset:0; 	mso-generic-font-family:swiss; 	mso-font-pitch:variable; 	mso-font-signature:536871559 0 0 0 415 0;}  /* Style Definitions */  p.MsoNormal, li.MsoNormal, div.MsoNormal 	{mso-style-parent:""; 	margin:0in; 	margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:12.0pt; 	font-family:"Times New Roman"; 	mso-fareast-font-family:"Times New Roman";} @page Section1 	{size:8.5in 11.0in; 	margin:1.0in 1.25in 1.0in 1.25in; 	mso-header-margin:.5in; 	mso-footer-margin:.5in; 	mso-paper-source:0;} div.Section1 	{page:Section1;} --> <!--[if gte mso 10]&gt;   /* Style Definitions */  table.MsoNormalTable 	{mso-style-name:"Table Normal"; 	mso-tstyle-rowband-size:0; 	mso-tstyle-colband-size:0; 	mso-style-noshow:yes; 	mso-style-parent:""; 	mso-padding-alt:0in 5.4pt 0in 5.4pt; 	mso-para-margin:0in; 	mso-para-margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:10.0pt; 	font-family:"Times New Roman"; 	mso-ansi-language:#0400; 	mso-fareast-language:#0400; 	mso-bidi-language:#0400;}  --><span></span></p>
<p class="MsoNormal"><span>During the SAS70 audit, an examination will be performed on your data backup process. If you have outsourced this to a local vendor, you are still responsible for making sure that your data is kept safe, secure, and is backed up properly. Hosted or online backup processes are very attractive for small to medium size businesses. Why? They don’t have to maintain the expertise internally and the IT equipment is expensive.</span></p>
<p class="MsoNormal"><span> </span></p>
<p class="MsoNormal"><span>How best do you manage your backup provider? Be sure to have a service level agreement in place. The service level agreement should provide you response times for when you need help. And you will! When you need to find that lost report that is due for your presentation today, you will want the file restored today – <em>NOT</em> in 24-36 hours. In addition, review your own internet connection as you will need a fast one to transfer your data. Does your outsourced vendor take care of your needs? SAS70ExPERT@gmail.com</span></p>
<p class="MsoNormal"><span> </span></p>
<p><em><span>Outsourcing your data backup process – SAS70</span></em></p>
<p class="MsoNormal"><span> </span></p>
<p class="MsoNormal"><span>During the SAS70 audit, an examination will be performed on your data backup process. If you have outsourced this to a local vendor, you are still responsible for making sure that your data is kept safe, secure, and is backed up properly. Hosted or online backup processes are very attractive for small to medium size businesses. Why? They don’t have to maintain the expertise internally and the IT equipment is expensive.</span></p>
<p class="MsoNormal"><span> </span></p>
<p class="MsoNormal"><span>How best do you manage your backup provider? Be sure to have a service level agreement in place. The service level agreement should provide you response times for when you need help. And you will! When you need to find that lost report that is due for your presentation today, you will want the file restored today – <em>NOT</em> in 24-36 hours. In addition, review your own internet connection as you will need a fast one to transfer your data. Does your outsourced vendor take care of your needs? SAS70ExPERT@gmail.com</span></p>
<p class="MsoNormal"><span> </span></p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/sas-70/outsourcing-your-data-backup-process-%e2%80%93-sas70/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Security is essential for all new technology investments? SAS70</title>
		<link>http://itknowledgeexchange.techtarget.com/sas-70/security-is-essential-for-all-new-technology-investments-sas70/</link>
		<comments>http://itknowledgeexchange.techtarget.com/sas-70/security-is-essential-for-all-new-technology-investments-sas70/#comments</comments>
		<pubDate>Sun, 21 Sep 2008 21:22:21 +0000</pubDate>
		<dc:creator>SAS70ExPERT</dc:creator>
				<category><![CDATA[Auditing]]></category>
		<category><![CDATA[Management]]></category>
		<category><![CDATA[Network]]></category>
		<category><![CDATA[SAS 70]]></category>
		<category><![CDATA[Security management]]></category>
		<category><![CDATA[Third-party services]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/sas-70/security-is-essential-for-all-new-technology-investments-sas70/</guid>
		<description><![CDATA[Which new technologies are you adopting? With Web 2.0, social networking, wikis, and blogs – oh mY! With so many new avenues to penetrate your market, the decisions you make today can effect the success of your SAS 70 audit. When evaluating new technology, always first determine your company objectives as we previously discussed. In [...]]]></description>
				<content:encoded><![CDATA[<p><!--[if gte mso 9]&gt;     Normal   0         false   false   false                             MicrosoftInternetExplorer4   --><!--[if gte mso 9]&gt;     --> <!--  /* Font Definitions */  @font-face 	{font-family:Bembo; 	panose-1:0 0 0 0 0 0 0 0 0 0; 	mso-font-charset:0; 	mso-generic-font-family:roman; 	mso-font-format:other; 	mso-font-pitch:auto; 	mso-font-signature:3 0 0 0 1 0;}  /* Style Definitions */  p.MsoNormal, li.MsoNormal, div.MsoNormal 	{mso-style-parent:""; 	margin:0in; 	margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:12.0pt; 	font-family:"Times New Roman"; 	mso-fareast-font-family:"Times New Roman";} @page Section1 	{size:8.5in 11.0in; 	margin:1.0in 1.25in 1.0in 1.25in; 	mso-header-margin:.5in; 	mso-footer-margin:.5in; 	mso-paper-source:0;} div.Section1 	{page:Section1;} --> <!--[if gte mso 10]&gt;   /* Style Definitions */  table.MsoNormalTable 	{mso-style-name:"Table Normal"; 	mso-tstyle-rowband-size:0; 	mso-tstyle-colband-size:0; 	mso-style-noshow:yes; 	mso-style-parent:""; 	mso-padding-alt:0in 5.4pt 0in 5.4pt; 	mso-para-margin:0in; 	mso-para-margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:10.0pt; 	font-family:"Times New Roman"; 	mso-ansi-language:#0400; 	mso-fareast-language:#0400; 	mso-bidi-language:#0400;}  --></p>
<p class="MsoNormal"><span>Which new technologies are you adopting? With Web 2.0, social networking, wikis, and blogs – oh mY! With so many new avenues to penetrate your market, the decisions you make today can effect the success of your SAS 70 audit. When evaluating new technology, always first determine your company objectives as we previously discussed. In addition, you will need to remember to consider what new security features must be implemented in your computing environment to prevent downtime. It is essential early in the process that you identify the threats, the risks, and then create a plan.</span></p>
<p class="MsoNormal"><span> </span></p>
<p class="MsoNormal"><span><span> </span></span><span>In identifying threats, the assessment team must consider who or what could compromise a target system’s components such that the system’s security attributes would be jeopardized. You should focus on how the information assets and components differ from what you already have. In identifying the security risks, consider what will th total potential impact on the organization. When your system is compromised – and it will be – how would you handle the loss of critical data?</span></p>
<p class="MsoNormal"><span> </span></p>
<p class="MsoNormal"><span>To address technology security risks, requires a documented plan and you must train your employees on how to enact the plan. The SAS70 audit will require you to have a plan in place and it will examine who are the participants in the plan. The plan should include not only IT, but operations and senior management. Where is your security plan? SAS70ExPERT@gmail.com</span></p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/sas-70/security-is-essential-for-all-new-technology-investments-sas70/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Making the Outsourcing Decision &#8211; SAS 70</title>
		<link>http://itknowledgeexchange.techtarget.com/sas-70/making-the-outsourcing-decision-sas-70/</link>
		<comments>http://itknowledgeexchange.techtarget.com/sas-70/making-the-outsourcing-decision-sas-70/#comments</comments>
		<pubDate>Wed, 17 Sep 2008 23:06:47 +0000</pubDate>
		<dc:creator>SAS70ExPERT</dc:creator>
				<category><![CDATA[Management]]></category>
		<category><![CDATA[management software]]></category>
		<category><![CDATA[SAS 70]]></category>
		<category><![CDATA[Third-party services]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/sas-70/making-the-outsourcing-decision-sas-70/</guid>
		<description><![CDATA[When deciding to outsource information technology to third-party services, Executive management should conduct an analysis to evaluate available options and determine if the vendor capabilities aligns with corporate objectives. First, determine what the driving factors that require you to outsource are – is it simple economics, as cost of technology for your industry is beyond [...]]]></description>
				<content:encoded><![CDATA[<p><!--[if gte mso 9]&gt;     Normal   0         false   false   false                             MicrosoftInternetExplorer4   --><!--[if gte mso 9]&gt;     --> <!--  /* Font Definitions */  @font-face 	{font-family:TimesNewRoman; 	panose-1:0 0 0 0 0 0 0 0 0 0; 	mso-font-charset:0; 	mso-generic-font-family:auto; 	mso-font-format:other; 	mso-font-pitch:auto; 	mso-font-signature:3 0 0 0 1 0;}  /* Style Definitions */  p.MsoNormal, li.MsoNormal, div.MsoNormal 	{mso-style-parent:""; 	margin:0in; 	margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:12.0pt; 	font-family:"Times New Roman"; 	mso-fareast-font-family:"Times New Roman";} @page Section1 	{size:8.5in 11.0in; 	margin:1.0in 1.25in 1.0in 1.25in; 	mso-header-margin:.5in; 	mso-footer-margin:.5in; 	mso-paper-source:0;} div.Section1 	{page:Section1;} --> <!--[if gte mso 10]&gt;   /* Style Definitions */  table.MsoNormalTable 	{mso-style-name:"Table Normal"; 	mso-tstyle-rowband-size:0; 	mso-tstyle-colband-size:0; 	mso-style-noshow:yes; 	mso-style-parent:""; 	mso-padding-alt:0in 5.4pt 0in 5.4pt; 	mso-para-margin:0in; 	mso-para-margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:10.0pt; 	font-family:"Times New Roman"; 	mso-ansi-language:#0400; 	mso-fareast-language:#0400; 	mso-bidi-language:#0400;}  --><span></span><span>When deciding to outsource information technology to third-party services, Executive management should conduct an analysis to evaluate available options and determine if the vendor capabilities aligns with corporate objectives. First, determine what the driving factors that require you to outsource are – is it simple economics, as cost of technology for your industry is beyond your reach, or do you not have the internal talent to manage an entire network infrastructure. By identifying the company specific strategic drivers for outsourcing, you will be able to quickly weed away the inept vendors.</span></p>
<p class="MsoNormal" align="center"><span> </span></p>
<p class="MsoNormal"><span>When selecting the outsourced vendor, carefully screen each vendor to determine if they have the necessary expertise to perform on time and after hours when emergencies occur. Don’t just go to lunch with the local sales representative and expect him to be there when an emergency occurs. Be sure to get all guarantees in writing, and a service level agreement is required. Due diligence is required to </span><span>understand and compare the capabilities in order to meet corporate objectives. sas70expert@gmail.com</span><span></span></p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/sas-70/making-the-outsourcing-decision-sas-70/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Successful traits of a CIO equal successful SAS70 audits (Part 3) – SAS 70</title>
		<link>http://itknowledgeexchange.techtarget.com/sas-70/successful-traits-of-a-cio-equal-successful-sas70-audits-part-3-%e2%80%93-sas-70/</link>
		<comments>http://itknowledgeexchange.techtarget.com/sas-70/successful-traits-of-a-cio-equal-successful-sas70-audits-part-3-%e2%80%93-sas-70/#comments</comments>
		<pubDate>Wed, 27 Aug 2008 14:30:02 +0000</pubDate>
		<dc:creator>SAS70ExPERT</dc:creator>
				<category><![CDATA[Auditing]]></category>
		<category><![CDATA[CEO]]></category>
		<category><![CDATA[CIO]]></category>
		<category><![CDATA[Compliance]]></category>
		<category><![CDATA[Management]]></category>
		<category><![CDATA[Monitoring]]></category>
		<category><![CDATA[SAS 70]]></category>
		<category><![CDATA[Third-party services]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/sas-70/successful-traits-of-a-cio-equal-successful-sas70-audits-part-3-%e2%80%93-sas-70/</guid>
		<description><![CDATA[  At 5pm, the CEO returned to his office with a cup of coffee and a very unpleasant frown. He barked out a few orders to his administrative assistant. I knew then that ….it was all going to roll down hill. Apparently, an IT Director signed a vendor contract with some very unfavorable terms. Luckily, [...]]]></description>
				<content:encoded><![CDATA[<p><!--[if gte mso 9]&gt;     Normal   0         false   false   false                             MicrosoftInternetExplorer4   --><!--[if gte mso 9]&gt;     --> <!--  /* Style Definitions */  p.MsoNormal, li.MsoNormal, div.MsoNormal 	{mso-style-parent:""; 	margin:0in; 	margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:12.0pt; 	font-family:"Times New Roman"; 	mso-fareast-font-family:"Times New Roman";} @page Section1 	{size:8.5in 11.0in; 	margin:1.0in 1.25in 1.0in 1.25in; 	mso-header-margin:.5in; 	mso-footer-margin:.5in; 	mso-paper-source:0;} div.Section1 	{page:Section1;} --> <!--[if gte mso 10]&gt;   /* Style Definitions */  table.MsoNormalTable 	{mso-style-name:"Table Normal"; 	mso-tstyle-rowband-size:0; 	mso-tstyle-colband-size:0; 	mso-style-noshow:yes; 	mso-style-parent:""; 	mso-padding-alt:0in 5.4pt 0in 5.4pt; 	mso-para-margin:0in; 	mso-para-margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:10.0pt; 	font-family:"Times New Roman"; 	mso-ansi-language:#0400; 	mso-fareast-language:#0400; 	mso-bidi-language:#0400;}  --></p>
<p class="MsoNormal"> <br />
<!--[if gte mso 9]&gt;     Normal   0         false   false   false                             MicrosoftInternetExplorer4   --><!--[if gte mso 9]&gt;     --> <!--  /* Style Definitions */  p.MsoNormal, li.MsoNormal, div.MsoNormal 	{mso-style-parent:""; 	margin:0in; 	margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:12.0pt; 	font-family:"Times New Roman"; 	mso-fareast-font-family:"Times New Roman";} @page Section1 	{size:8.5in 11.0in; 	margin:1.0in 1.25in 1.0in 1.25in; 	mso-header-margin:.5in; 	mso-footer-margin:.5in; 	mso-paper-source:0;} div.Section1 	{page:Section1;} --> <!--[if gte mso 10]&gt;   /* Style Definitions */  table.MsoNormalTable 	{mso-style-name:"Table Normal"; 	mso-tstyle-rowband-size:0; 	mso-tstyle-colband-size:0; 	mso-style-noshow:yes; 	mso-style-parent:""; 	mso-padding-alt:0in 5.4pt 0in 5.4pt; 	mso-para-margin:0in; 	mso-para-margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:10.0pt; 	font-family:"Times New Roman"; 	mso-ansi-language:#0400; 	mso-fareast-language:#0400; 	mso-bidi-language:#0400;}  --><span></span></p>
<p class="MsoNormal"><span></span></p>
<p class="MsoNormal">At 5pm, the CEO returned to his office with a cup of coffee and a very unpleasant frown. He barked out a few orders to his administrative assistant. I knew then that ….it was all going to roll down hill. Apparently, an IT Director signed a vendor contract with some very unfavorable terms. Luckily, the IT Director was no longer with the Company, therefore, the CIO, was the one who would be assigned the cleanup work.</p>
<p class="MsoNormal"> </p>
<p class="MsoNormal">In order to deal with this situation, the CIO would have to quickly understand the requirements of the CEO and the expectations of the vendor. If he failed at delivering for either of them, then the effects could have serious consequences on IT operations. These types of political maneuvers happen everyday and it takes a skillful politician as a CIO to produce favorable results.</p>
<p class="MsoNormal"> </p>
<p class="MsoNormal">A CIO can use her political skills to effectively deal with a SAS70 audit. When an auditor identifies an audit exception, the CIO may fully agree with the auditor; however, the description of the audit exception may need to be qualified in order to maintain a close relationship with the CEO. Sometimes, negotiations are even held over simple words, such as “sometimes” as they can make a big difference in the eyes of the Board of Directors or Audit Committee. What are some of the circumstances that you may have been involved in? Were you successful in avoiding pitfalls? What worked best for you?</p>
<p class="MsoNormal">Sas70expert@gmail.com</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/sas-70/successful-traits-of-a-cio-equal-successful-sas70-audits-part-3-%e2%80%93-sas-70/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>CIO and the SDLC success story – SAS70ExPERT</title>
		<link>http://itknowledgeexchange.techtarget.com/sas-70/cio-and-the-sdlc-success-story-%e2%80%93-sas70expert/</link>
		<comments>http://itknowledgeexchange.techtarget.com/sas-70/cio-and-the-sdlc-success-story-%e2%80%93-sas70expert/#comments</comments>
		<pubDate>Mon, 11 Aug 2008 20:17:30 +0000</pubDate>
		<dc:creator>SAS70ExPERT</dc:creator>
				<category><![CDATA[Auditing]]></category>
		<category><![CDATA[CIO]]></category>
		<category><![CDATA[Compliance]]></category>
		<category><![CDATA[SAS 70]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Third-party services]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/sas-70/cio-and-the-sdlc-success-story-%e2%80%93-sas70expert/</guid>
		<description><![CDATA[What’s your plan as a new CIO to make IT operations a success? Consider Jack Ben, newly appointed CIO. In his new role, he assumes the management and performance of the financial statement application and has to complete a SAS70 audit in six months.. This application has been in use for over 7 years, and [...]]]></description>
				<content:encoded><![CDATA[<p><!--[if gte mso 9]&gt;     Normal   0         false   false   false                             MicrosoftInternetExplorer4   --><!--[if gte mso 9]&gt;     --><!--[if !mso]&gt;  st1\:*{behavior:url(#ieooui) }  --> <!--  /* Style Definitions */  p.MsoNormal, li.MsoNormal, div.MsoNormal 	{mso-style-parent:""; 	margin:0in; 	margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:12.0pt; 	font-family:"Times New Roman"; 	mso-fareast-font-family:"Times New Roman";} @page Section1 	{size:8.5in 11.0in; 	margin:1.0in 1.25in 1.0in 1.25in; 	mso-header-margin:.5in; 	mso-footer-margin:.5in; 	mso-paper-source:0;} div.Section1 	{page:Section1;}  /* List Definitions */  @list l0 	{mso-list-id:218905183; 	mso-list-type:hybrid; 	mso-list-template-ids:1503939528 67698705 67698713 67698715 67698703 67698713 67698715 67698703 67698713 67698715;} @list l0:level1 	{mso-level-text:"%1\)"; 	mso-level-tab-stop:.5in; 	mso-level-number-position:left; 	text-indent:-.25in;} ol 	{margin-bottom:0in;} ul 	{margin-bottom:0in;} --> <!--[if gte mso 10]&gt;   /* Style Definitions */  table.MsoNormalTable 	{mso-style-name:"Table Normal"; 	mso-tstyle-rowband-size:0; 	mso-tstyle-colband-size:0; 	mso-style-noshow:yes; 	mso-style-parent:""; 	mso-padding-alt:0in 5.4pt 0in 5.4pt; 	mso-para-margin:0in; 	mso-para-margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:10.0pt; 	font-family:"Times New Roman"; 	mso-ansi-language:#0400; 	mso-fareast-language:#0400; 	mso-bidi-language:#0400;}  --></p>
<p class="MsoNormal">What’s your plan as a new CIO to make IT operations a success? Consider Jack Ben, newly appointed CIO. In his new role, he assumes the management and performance of the financial statement application and has to complete a SAS70 audit in six months.. This application has been in use for over 7 years, and much of the customization, reporting, and user access management is performed by a third party vendor. What roadblocks do you face to meeting strategic objectives and making your bonus plan?</p>
<p class="MsoNormal"> </p>
<p class="MsoNormal">Consider the following:</p>
<p class="MsoNormal"><!--[if !supportLists]--><span>1)<span>      </span></span><!--[endif]-->If your vendor performs customization, then the specialized knowledge to maintain new software upgrades, enhancements and reports remain at the vendor. This could wrestle your CIO title to the ground, unless you require the vendor to supply you with instruction manuals, executive level briefing and/or detailed on-line help features.</p>
<p class="MsoNormal"><!--[if !supportLists]--><span>2)<span>      </span></span><!--[endif]-->In addition, is the software code in escrow? In your vendor contract, you should have a requirement that your vendor maintain the source code in a safe and secure lockbox. Even if your vendor doesn’t survive the economy, your source code will! In addition, you could hire your vendor’s coders to work for you.</p>
<p class="MsoNormal"> </p>
<p class="MsoNormal">In a SAS70 audit, if your sole operating system application is managed by an outsourced vendor, the auditor will request that they have a SAS70 audit performed. In addition, they will require that controls that secure your control of the application. What steps have you put in place to manage your outsourced systems? Do you have a comprehensive SLA? Do you have a project leader that monitors your outsourced vendor and your application? sas70expert@gmail.com</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/sas-70/cio-and-the-sdlc-success-story-%e2%80%93-sas70expert/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Telecommuting as a SAS70 audit control? – SAS70ExPERT</title>
		<link>http://itknowledgeexchange.techtarget.com/sas-70/telecommuting-as-a-sas70-audit-control-%e2%80%93-sas70expert/</link>
		<comments>http://itknowledgeexchange.techtarget.com/sas-70/telecommuting-as-a-sas70-audit-control-%e2%80%93-sas70expert/#comments</comments>
		<pubDate>Sun, 10 Aug 2008 19:54:58 +0000</pubDate>
		<dc:creator>SAS70ExPERT</dc:creator>
				<category><![CDATA[Access control]]></category>
		<category><![CDATA[Auditing]]></category>
		<category><![CDATA[CIO]]></category>
		<category><![CDATA[Compliance]]></category>
		<category><![CDATA[Network]]></category>
		<category><![CDATA[SAS 70]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Telecommuting]]></category>
		<category><![CDATA[Third-party services]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/sas-70/telecommuting-as-a-sas70-audit-control-%e2%80%93-sas70expert/</guid>
		<description><![CDATA[As transportation costs continue to skyrocket over the summer, telework/telecommuting is becoming the new trend among office environments. Basically, we have been doing a form of telework by outsourcing all of our jobs overseas, so this premise is not really new, it’s just new for American workers. 92 percent of workers said their work could [...]]]></description>
				<content:encoded><![CDATA[<p><!--[if gte mso 9]&gt;     Normal   0         false   false   false                             MicrosoftInternetExplorer4   --><!--[if gte mso 9]&gt;     --><!--[if !mso]&gt;  st1\:*{behavior:url(#ieooui) }  --> <!--  /* Style Definitions */  p.MsoNormal, li.MsoNormal, div.MsoNormal 	{mso-style-parent:""; 	margin:0in; 	margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:12.0pt; 	font-family:"Times New Roman"; 	mso-fareast-font-family:"Times New Roman";} @page Section1 	{size:8.5in 11.0in; 	margin:1.0in 1.25in 1.0in 1.25in; 	mso-header-margin:.5in; 	mso-footer-margin:.5in; 	mso-paper-source:0;} div.Section1 	{page:Section1;}  /* List Definitions */  @list l0 	{mso-list-id:1625775100; 	mso-list-type:hybrid; 	mso-list-template-ids:-1362885200 67698705 67698713 67698715 67698703 67698713 67698715 67698703 67698713 67698715;} @list l0:level1 	{mso-level-text:"%1\)"; 	mso-level-tab-stop:.5in; 	mso-level-number-position:left; 	text-indent:-.25in;} ol 	{margin-bottom:0in;} ul 	{margin-bottom:0in;} --> <!--[if gte mso 10]&gt;   /* Style Definitions */  table.MsoNormalTable 	{mso-style-name:"Table Normal"; 	mso-tstyle-rowband-size:0; 	mso-tstyle-colband-size:0; 	mso-style-noshow:yes; 	mso-style-parent:""; 	mso-padding-alt:0in 5.4pt 0in 5.4pt; 	mso-para-margin:0in; 	mso-para-margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:10.0pt; 	font-family:"Times New Roman"; 	mso-ansi-language:#0400; 	mso-fareast-language:#0400; 	mso-bidi-language:#0400;}  --></p>
<p class="MsoNormal">As transportation costs continue to skyrocket over the summer, telework/telecommuting is becoming the new trend among office environments. Basically, we have been doing a form of telework by outsourcing all of our jobs overseas, so this premise is not really new, it’s just new for American workers. 92 percent of workers said their work could be performed from home according to a recent survey by advocacy group Telework Exchange. I agree that operating expenses could be reduced by:</p>
<p class="MsoNormal"><!--[if !supportLists]--><span>1)<span>      </span></span><!--[endif]-->less office space per employee</p>
<p class="MsoNormal"><!--[if !supportLists]--><span>2)<span>      </span></span><!--[endif]-->transportation costs are reduced from commuting to work</p>
<p class="MsoNormal"><!--[if !supportLists]--><span>3)<span>      </span></span><!--[endif]-->reduction in computer hardware expenses</p>
<p class="MsoNormal"> </p>
<p class="MsoNormal">But what is the downside of a remote workforce and what effect will that have on company information assets? These information assets are now stored at a families home on First Avenue, in a 3 bedroom, 2 bath, instead of your 5 story office building. These telecommuting risks will need to examined by management and should be considered in a SAS70 audit.</p>
<p class="MsoNormal"> </p>
<p class="MsoNormal">Consider that most employee homes will not have extended physical or environmental security – only garage door locks and an air conditioner. Their computer office could be located next to their children’s bathroom – which is a likely water hazard, in an open space by a garden window. How easy would it be for a burgular to reach in and knock your coffee cup over, and grab your computer from your first floor home office?Really EASY, as I think many homes today still have yet to have a home alarm system on their windows.Critical company information now could be sold on the internet.</p>
<p class="MsoNormal">&nbsp;</p>
<p class="MsoNormal">In addition, what network security are you assured that they have on their home computer? Do they have the latest virus preventing application? Is their firewall always up and running or might it be turned off to watch a movie?</p>
<p class="MsoNormal">&nbsp;</p>
<p class="MsoNormal">Is your IT staff prepared to make housecalls? Your company information assets now resids at your employees home. It is now not on the second floor of your office, but could be 20-30 miles to First Avenue home. You now must manage users that are at locations that are spread miles apart? This may be okay if 15% of your workforce is remote, but what if it is 92%? Is your IT staff trained accordingly? If they have to make housecalls, do transportation costs truly decrease? Who is managing the network while your IT Administrator is stuck in traffic on his way to the Marketing Director&#8217;s home to fix his computer?</p>
<p class="MsoNormal">&nbsp;</p>
<p class="MsoNormal">Any third party vendor must complete a SAS70 audit to assure it customer that their data is secure. Are you ready to expand your company floor space beyond the office perimeter? Telecommuting risks must be considered in the SAS70 audit process. What are some of the risks you have identified? Do you even have any policies in place at your company which specifically discuss the do’s and don’t’s of a telecommuter? SAS70ExPERT@gmail.com</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/sas-70/telecommuting-as-a-sas70-audit-control-%e2%80%93-sas70expert/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
