If this information was available to the public the name brand auditing firms might not be doing (or re-doing) so many of these. Here's some good insight on SAS70 audits.
You can look at the ISO/IEC 27002 criteria and then take things up a 20 or 30 thousand feet and you'll be at about the right level of a SAS70 audit.
Just know that you can never, ever, ever (get my point?) trust that just because you "pass" a SAS70 audit that your business is secure from the risks that matter.
Free Guide: Managing storage for virtual environments
Complete a brief survey to get a complimentary 70-page whitepaper featuring the best methods and solutions for your virtual environment, as well as hypervisor-specific management advice from TechTarget experts. Don’t miss out on this exclusive content!
Discuss This Question: 2  Replies