SAS 70

SAS 70, the auditing standard, is finding its way onto CSOs' desks. Used correctly, it's a nice start on verifying business partners' security controls. Unfortunately, some people aren't using it correctly.

» View Article

READER FEEDBACK
Preview
K. M. Harbin
Tue, 2008-06-17 22:22

Readers should be aware that SAS-70's are applicable only to service organizations that process transactions (i.e., they are not appropriate for companies that do not host data). Secondly, SAS-70's are expected to be superseded by international standard ISAE3402 (which should be published by IFAC in 2009), and by SSAE (expected to be published by AICPA in 2010).

reply
Dave
Wed, 2008-08-13 16:04

Is it accurate to state that SAS70, COBIT, and BS7799 (ISO7799) are all just basic "control templates?" In other words, assuming I'm a hosting provider taking transactions, why would I choose SAS70 over a subset of COBIT?

reply
Post a comment
The content of this field is kept private and will not be shown publicly.
  • Allowed HTML tags: <a> <em> <strong> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd>
  • Lines and paragraphs break automatically.