If
you work for a service provider, odds are you are familiar with the
requirements of SAS 70 (AICPA’s Statement of Auditing Standards Number
70). Essentially, service organizations or service providers must
demonstrate that they have adequate controls and safeguards when they
host or process data belonging to their clients. Largely driven by in
recent years by compliance initiatives like Sarbanes-Oxley (SOX),
Gramm Leach Bliley (GLBA), the Health Insurance Portability and
Accountability Act (HIPAA), and other regulatory requirements; the SAS
70 requires certification by registered public accounting firm.
Before calling a CPA firm to do the audit, it is critical to make sure
you are ready. Vonya Global offers its clients a streamlined SAS 70
readiness
assessment. Whether a Software as a Service Company (SaaS), Insurance
Company, or outsourcing company, Vonya Global has the experience to
help you comply with minimal costs.
To help you get started, the following control areas could be within
scope:
-
Organization and Administration-Executive Tone
- Organization and Administration-Human Resources
- Systems Development Life Cycle
- Incident Management
- Change Management
- Logical Security
- Network Security
- Physical Security
- Environmental Security
- Computer Operations
- Business Continuity and Disaster Recovery
Spend a
few
minutes with us to find out how we have helped our clients.