SlideShare a Scribd company logo
1 of 8
AX Management:
Should an Outsourcer Complete a SSAE 16 Type II Audit?




                                                             http://www.oneneck.com
                                 Copyright © 2013 OneNeck IT Services Corporation. All rights reserved.
AX Management


Many outsourcing providers offer services for AX management, but operate without a set
standard for auditing and controls.

To be sure application management and hosting assets are handled appropriately, a provider
must follow a set standard of controls that protect each customer’s investment.


What is a SSAE 16 Type II Audit?
•Replacing SAS 70, SSAE 16 is an internationally recognized auditing standard
developed by the American Institute of Certified Public Accountants (AICPA).

•SSAE 16 performs what the SAS 70 was originally designed to do: communicate the
organization’s and auditor’s attestation on assertions made by the organization
through a structured report.

•The SOC 1/SSAE 16 incorporates many improvements upon the original guidebook,
including management attestation.




                                                                                  http://www.oneneck.com
                                                      Copyright © 2013 OneNeck IT Services Corporation. All rights reserved.
AX Management

Many outsourcing providers offer services for AX management, but operate without a set
standard for auditing and controls.

To be sure application management and hosting assets are handled appropriately, a provider
must follow a set standard of controls that protect each customer’s investment.


What is a SSAE 16 Type II Audit?

•Similar to the SAS 70, the SOC 1/SSAE 16 report may be issued in two formats:
                               Type I and Type II.

•Type I reports are a point-in-time assessment of controls in place to ensure the
stated control objectives are adequate.

•Type II reports build upon Type I reports by requiring the collection of detailed
evidence throughout a period of time.

•This evidence demonstrates the control objectives defined are not only implemented,
but being practiced throughout the audit period.


                                                                                  http://www.oneneck.com
                                                      Copyright © 2013 OneNeck IT Services Corporation. All rights reserved.
AX Management


A SSAE 16 Type II Audit Provides Necessary Insight for AX Management

To ensure the most stringent verification of controls of an outsourcing provider’s AX
management, a SSAE 16 Type II audit would be preferred.

The SOC1/SSAE 16 report now provides further insight into the people, processes and
technologies implemented to effectively achieve the control objectives outlined by
management.

The control objectives include items related to:

•Administrative Duties to ensure the outsourcing provider maintains a trustworthy
workforce for AX management.

•Physical Security to ensure the outsourcing provider’s facilities are protected by
strong policies and practices for the highest performing AX management.

•Change Management to ensure effective policies for managing changes to
infrastructure are followed.


                                                                               http://www.oneneck.com
                                                   Copyright © 2013 OneNeck IT Services Corporation. All rights reserved.
AX Management


A SSAE 16 Type II Audit Provides Necessary Insight for AX Management
 
To ensure the most stringent verification of controls of an outsourcing provider’s AX
management, a SSAE 16 Type II audit would be preferred.

The SOC1/SSAE 16 report now provides further insight into the people, processes and
technologies implemented to effectively achieve the control objectives outlined by
management.
 
The control objectives include items related to:
 
•Availability  Management  to  ensure  the  AX  management  infrastructure  is  properly 
maintained  and  the  data  center  environment  is  protected  and  conditioned  in  line 
with industry best practices.

•Incident  and  Event  Management  to  ensure  tools  are  in  place  and  personnel  are 
properly trained to address potential business impacting events.

•Request Management to ensure service requests flow through a proper life cycle.


                                                                                  http://www.oneneck.com
                                                      Copyright © 2013 OneNeck IT Services Corporation. All rights reserved.
AX Management

        A SSAE 16 Type II Audit Provides Needed Confirmations
 
When an AX management outsourcer has completed a SSAE 16 Type II audit,
customers can be assured certain claims have been verified.

In other words, the company is doing what it says it does when it comes to
operational metrics.

For example, a SSAE 16 audit confirms the data center:
 
    • Maintains Sufficient Data and Power Redundancy 

    • Maintains Appropriate Physical Security Controls
       
    • Monitors for Excessive Temperature Fluctuations

    • Reviews Alerts on a Timely Basis

    • Has Proper Fire/Water Detection and Protection


                                                                           http://www.oneneck.com
                                               Copyright © 2013 OneNeck IT Services Corporation. All rights reserved.
AX Management




When a company trusts a third party for a critical service such as AX
management, using only the highest quality providers is an option.

Selecting an outsourcing provider without proper controls can put a
business at significant risk.

Therefore, companies must ensure their outsourcing partners leverage
the most advanced technology and skilled personnel to help safeguard
their IT assets.




                                                                      http://www.oneneck.com
                                          Copyright © 2013 OneNeck IT Services Corporation. All rights reserved.
ABOUT THE AUTHOR




 Chuck Vermillion is CEO and founder of OneNeck IT
  Services, a leading provider of hosted application
   management and managed services since 1997.

 For more information about AX Management, visit
http://www.oneneck.com/Solutions.aspx today.




                                                             http://www.oneneck.com
                                 Copyright © 2013 OneNeck IT Services Corporation. All rights reserved.

More Related Content

Similar to AX Management: Should an Outsourcer Complete a SSAE 16 Type II Audit?

Service Organizational Control (SOC 2) Compliance - Kloudlearn
Service Organizational Control  (SOC 2) Compliance - KloudlearnService Organizational Control  (SOC 2) Compliance - Kloudlearn
Service Organizational Control (SOC 2) Compliance - KloudlearnKloudLearn
 
ERP - Enterprise Resource Planning.pdf
ERP - Enterprise Resource Planning.pdfERP - Enterprise Resource Planning.pdf
ERP - Enterprise Resource Planning.pdfgayatrimohite2
 
Do you have a business case for Attribute Based Access Control (ABAC)?
Do you have a business case for Attribute Based Access Control (ABAC)?Do you have a business case for Attribute Based Access Control (ABAC)?
Do you have a business case for Attribute Based Access Control (ABAC)?Finn Frisch
 
Do you have a business case for Attribute Based Access Control (ABAC)?
Do you have a business case for Attribute Based Access Control (ABAC)?Do you have a business case for Attribute Based Access Control (ABAC)?
Do you have a business case for Attribute Based Access Control (ABAC)?Finn Frisch
 
ONI_DatasheetRedesign_AssureMonitor_v3 (2)
ONI_DatasheetRedesign_AssureMonitor_v3 (2)ONI_DatasheetRedesign_AssureMonitor_v3 (2)
ONI_DatasheetRedesign_AssureMonitor_v3 (2)Carl Pollard
 
Integrated Compliance Webinar.pptx
Integrated Compliance Webinar.pptxIntegrated Compliance Webinar.pptx
Integrated Compliance Webinar.pptxControlCase
 
Oracle hfm beginner's guide part i
Oracle hfm beginner's guide  part iOracle hfm beginner's guide  part i
Oracle hfm beginner's guide part iAmit Sharma
 
Oracle hfm beginner's guide part i
Oracle hfm beginner's guide  part iOracle hfm beginner's guide  part i
Oracle hfm beginner's guide part iAmit Sharma
 
Oracle hfm beginner's guide part i
Oracle hfm beginner's guide  part iOracle hfm beginner's guide  part i
Oracle hfm beginner's guide part iAmit Sharma
 
Oracle hfm beginner's guide part i
Oracle hfm beginner's guide  part iOracle hfm beginner's guide  part i
Oracle hfm beginner's guide part iAmit Sharma
 
Oraclehfmbeginnersguideparti 100910163317-phpapp02
Oraclehfmbeginnersguideparti 100910163317-phpapp02Oraclehfmbeginnersguideparti 100910163317-phpapp02
Oraclehfmbeginnersguideparti 100910163317-phpapp02Ratnakar Kumar
 
Governance and Security Solution Patterns
Governance and Security Solution Patterns Governance and Security Solution Patterns
Governance and Security Solution Patterns WSO2
 
BUILDING SCALABLE AND ROBUST WEB APPLICATIONS: BEST PRACTICES
BUILDING SCALABLE AND ROBUST WEB APPLICATIONS: BEST PRACTICESBUILDING SCALABLE AND ROBUST WEB APPLICATIONS: BEST PRACTICES
BUILDING SCALABLE AND ROBUST WEB APPLICATIONS: BEST PRACTICESflaviusnoja1
 
More practical insights on the 20 critical controls
More practical insights on the 20 critical controlsMore practical insights on the 20 critical controls
More practical insights on the 20 critical controlsEnclaveSecurity
 
ING webcast platform
ING webcast platformING webcast platform
ING webcast platformOracleIDM
 
Account Right SOC Services brochure.pptx
Account Right SOC Services brochure.pptxAccount Right SOC Services brochure.pptx
Account Right SOC Services brochure.pptxGaneshMeenakshiSunda4
 
Blancco Management Console
Blancco Management ConsoleBlancco Management Console
Blancco Management ConsoleJemma Elliott
 
Sample audit plan
Sample audit planSample audit plan
Sample audit planMaher Manan
 

Similar to AX Management: Should an Outsourcer Complete a SSAE 16 Type II Audit? (20)

CMMC Breakdown
CMMC BreakdownCMMC Breakdown
CMMC Breakdown
 
Service Organizational Control (SOC 2) Compliance - Kloudlearn
Service Organizational Control  (SOC 2) Compliance - KloudlearnService Organizational Control  (SOC 2) Compliance - Kloudlearn
Service Organizational Control (SOC 2) Compliance - Kloudlearn
 
ERP - Enterprise Resource Planning.pdf
ERP - Enterprise Resource Planning.pdfERP - Enterprise Resource Planning.pdf
ERP - Enterprise Resource Planning.pdf
 
Do you have a business case for Attribute Based Access Control (ABAC)?
Do you have a business case for Attribute Based Access Control (ABAC)?Do you have a business case for Attribute Based Access Control (ABAC)?
Do you have a business case for Attribute Based Access Control (ABAC)?
 
Do you have a business case for Attribute Based Access Control (ABAC)?
Do you have a business case for Attribute Based Access Control (ABAC)?Do you have a business case for Attribute Based Access Control (ABAC)?
Do you have a business case for Attribute Based Access Control (ABAC)?
 
ONI_DatasheetRedesign_AssureMonitor_v3 (2)
ONI_DatasheetRedesign_AssureMonitor_v3 (2)ONI_DatasheetRedesign_AssureMonitor_v3 (2)
ONI_DatasheetRedesign_AssureMonitor_v3 (2)
 
Integrated Compliance Webinar.pptx
Integrated Compliance Webinar.pptxIntegrated Compliance Webinar.pptx
Integrated Compliance Webinar.pptx
 
Oracle hfm beginner's guide part i
Oracle hfm beginner's guide  part iOracle hfm beginner's guide  part i
Oracle hfm beginner's guide part i
 
Oracle hfm beginner's guide part i
Oracle hfm beginner's guide  part iOracle hfm beginner's guide  part i
Oracle hfm beginner's guide part i
 
Oracle hfm beginner's guide part i
Oracle hfm beginner's guide  part iOracle hfm beginner's guide  part i
Oracle hfm beginner's guide part i
 
Office-SOQe
Office-SOQeOffice-SOQe
Office-SOQe
 
Oracle hfm beginner's guide part i
Oracle hfm beginner's guide  part iOracle hfm beginner's guide  part i
Oracle hfm beginner's guide part i
 
Oraclehfmbeginnersguideparti 100910163317-phpapp02
Oraclehfmbeginnersguideparti 100910163317-phpapp02Oraclehfmbeginnersguideparti 100910163317-phpapp02
Oraclehfmbeginnersguideparti 100910163317-phpapp02
 
Governance and Security Solution Patterns
Governance and Security Solution Patterns Governance and Security Solution Patterns
Governance and Security Solution Patterns
 
BUILDING SCALABLE AND ROBUST WEB APPLICATIONS: BEST PRACTICES
BUILDING SCALABLE AND ROBUST WEB APPLICATIONS: BEST PRACTICESBUILDING SCALABLE AND ROBUST WEB APPLICATIONS: BEST PRACTICES
BUILDING SCALABLE AND ROBUST WEB APPLICATIONS: BEST PRACTICES
 
More practical insights on the 20 critical controls
More practical insights on the 20 critical controlsMore practical insights on the 20 critical controls
More practical insights on the 20 critical controls
 
ING webcast platform
ING webcast platformING webcast platform
ING webcast platform
 
Account Right SOC Services brochure.pptx
Account Right SOC Services brochure.pptxAccount Right SOC Services brochure.pptx
Account Right SOC Services brochure.pptx
 
Blancco Management Console
Blancco Management ConsoleBlancco Management Console
Blancco Management Console
 
Sample audit plan
Sample audit planSample audit plan
Sample audit plan
 

More from oneneckitservices

Why Outsource Application Management?
Why Outsource Application Management?Why Outsource Application Management?
Why Outsource Application Management?oneneckitservices
 
How to Evaluate a Managed Services Firm
How to Evaluate a Managed Services FirmHow to Evaluate a Managed Services Firm
How to Evaluate a Managed Services Firmoneneckitservices
 
What is a Liquidation Auction?
What is a Liquidation Auction?What is a Liquidation Auction?
What is a Liquidation Auction?oneneckitservices
 
IT service provider, IT outsourcing, OneNeck IT Services
IT service provider, IT outsourcing, OneNeck IT ServicesIT service provider, IT outsourcing, OneNeck IT Services
IT service provider, IT outsourcing, OneNeck IT Servicesoneneckitservices
 
Virtual Private Servers (vps)- a case study
Virtual Private Servers (vps)- a case studyVirtual Private Servers (vps)- a case study
Virtual Private Servers (vps)- a case studyoneneckitservices
 
Disaster Recovery- A Case Study
Disaster Recovery- A Case StudyDisaster Recovery- A Case Study
Disaster Recovery- A Case Studyoneneckitservices
 
IT Outsourcing- Delivering Unmatched Value
IT Outsourcing- Delivering Unmatched ValueIT Outsourcing- Delivering Unmatched Value
IT Outsourcing- Delivering Unmatched Valueoneneckitservices
 
IT Hosting- AFundamental BusinessProcess
IT Hosting- AFundamental BusinessProcessIT Hosting- AFundamental BusinessProcess
IT Hosting- AFundamental BusinessProcessoneneckitservices
 
ERP Outsourcing, Dynamics AX, and Managed Services by OneNeck IT Services
ERP Outsourcing, Dynamics AX, and Managed Services by OneNeck IT ServicesERP Outsourcing, Dynamics AX, and Managed Services by OneNeck IT Services
ERP Outsourcing, Dynamics AX, and Managed Services by OneNeck IT Servicesoneneckitservices
 
IT Outsourcing: Business Continuity by Design by OneNeck IT Services
IT Outsourcing: Business Continuity by Design by OneNeck IT ServicesIT Outsourcing: Business Continuity by Design by OneNeck IT Services
IT Outsourcing: Business Continuity by Design by OneNeck IT Servicesoneneckitservices
 

More from oneneckitservices (10)

Why Outsource Application Management?
Why Outsource Application Management?Why Outsource Application Management?
Why Outsource Application Management?
 
How to Evaluate a Managed Services Firm
How to Evaluate a Managed Services FirmHow to Evaluate a Managed Services Firm
How to Evaluate a Managed Services Firm
 
What is a Liquidation Auction?
What is a Liquidation Auction?What is a Liquidation Auction?
What is a Liquidation Auction?
 
IT service provider, IT outsourcing, OneNeck IT Services
IT service provider, IT outsourcing, OneNeck IT ServicesIT service provider, IT outsourcing, OneNeck IT Services
IT service provider, IT outsourcing, OneNeck IT Services
 
Virtual Private Servers (vps)- a case study
Virtual Private Servers (vps)- a case studyVirtual Private Servers (vps)- a case study
Virtual Private Servers (vps)- a case study
 
Disaster Recovery- A Case Study
Disaster Recovery- A Case StudyDisaster Recovery- A Case Study
Disaster Recovery- A Case Study
 
IT Outsourcing- Delivering Unmatched Value
IT Outsourcing- Delivering Unmatched ValueIT Outsourcing- Delivering Unmatched Value
IT Outsourcing- Delivering Unmatched Value
 
IT Hosting- AFundamental BusinessProcess
IT Hosting- AFundamental BusinessProcessIT Hosting- AFundamental BusinessProcess
IT Hosting- AFundamental BusinessProcess
 
ERP Outsourcing, Dynamics AX, and Managed Services by OneNeck IT Services
ERP Outsourcing, Dynamics AX, and Managed Services by OneNeck IT ServicesERP Outsourcing, Dynamics AX, and Managed Services by OneNeck IT Services
ERP Outsourcing, Dynamics AX, and Managed Services by OneNeck IT Services
 
IT Outsourcing: Business Continuity by Design by OneNeck IT Services
IT Outsourcing: Business Continuity by Design by OneNeck IT ServicesIT Outsourcing: Business Continuity by Design by OneNeck IT Services
IT Outsourcing: Business Continuity by Design by OneNeck IT Services
 

Recently uploaded

Boost the utilization of your HCL environment by reevaluating use cases and f...
Boost the utilization of your HCL environment by reevaluating use cases and f...Boost the utilization of your HCL environment by reevaluating use cases and f...
Boost the utilization of your HCL environment by reevaluating use cases and f...Roland Driesen
 
0183760ssssssssssssssssssssssssssss00101011 (27).pdf
0183760ssssssssssssssssssssssssssss00101011 (27).pdf0183760ssssssssssssssssssssssssssss00101011 (27).pdf
0183760ssssssssssssssssssssssssssss00101011 (27).pdfRenandantas16
 
Keppel Ltd. 1Q 2024 Business Update Presentation Slides
Keppel Ltd. 1Q 2024 Business Update  Presentation SlidesKeppel Ltd. 1Q 2024 Business Update  Presentation Slides
Keppel Ltd. 1Q 2024 Business Update Presentation SlidesKeppelCorporation
 
It will be International Nurses' Day on 12 May
It will be International Nurses' Day on 12 MayIt will be International Nurses' Day on 12 May
It will be International Nurses' Day on 12 MayNZSG
 
BEST ✨ Call Girls In Indirapuram Ghaziabad ✔️ 9871031762 ✔️ Escorts Service...
BEST ✨ Call Girls In  Indirapuram Ghaziabad  ✔️ 9871031762 ✔️ Escorts Service...BEST ✨ Call Girls In  Indirapuram Ghaziabad  ✔️ 9871031762 ✔️ Escorts Service...
BEST ✨ Call Girls In Indirapuram Ghaziabad ✔️ 9871031762 ✔️ Escorts Service...noida100girls
 
GD Birla and his contribution in management
GD Birla and his contribution in managementGD Birla and his contribution in management
GD Birla and his contribution in managementchhavia330
 
Yaroslav Rozhankivskyy: Три складові і три передумови максимальної продуктивн...
Yaroslav Rozhankivskyy: Три складові і три передумови максимальної продуктивн...Yaroslav Rozhankivskyy: Три складові і три передумови максимальної продуктивн...
Yaroslav Rozhankivskyy: Три складові і три передумови максимальної продуктивн...Lviv Startup Club
 
A DAY IN THE LIFE OF A SALESMAN / WOMAN
A DAY IN THE LIFE OF A  SALESMAN / WOMANA DAY IN THE LIFE OF A  SALESMAN / WOMAN
A DAY IN THE LIFE OF A SALESMAN / WOMANIlamathiKannappan
 
Value Proposition canvas- Customer needs and pains
Value Proposition canvas- Customer needs and painsValue Proposition canvas- Customer needs and pains
Value Proposition canvas- Customer needs and painsP&CO
 
The Coffee Bean & Tea Leaf(CBTL), Business strategy case study
The Coffee Bean & Tea Leaf(CBTL), Business strategy case studyThe Coffee Bean & Tea Leaf(CBTL), Business strategy case study
The Coffee Bean & Tea Leaf(CBTL), Business strategy case studyEthan lee
 
Creating Low-Code Loan Applications using the Trisotech Mortgage Feature Set
Creating Low-Code Loan Applications using the Trisotech Mortgage Feature SetCreating Low-Code Loan Applications using the Trisotech Mortgage Feature Set
Creating Low-Code Loan Applications using the Trisotech Mortgage Feature SetDenis Gagné
 
Cash Payment 9602870969 Escort Service in Udaipur Call Girls
Cash Payment 9602870969 Escort Service in Udaipur Call GirlsCash Payment 9602870969 Escort Service in Udaipur Call Girls
Cash Payment 9602870969 Escort Service in Udaipur Call GirlsApsara Of India
 
Ensure the security of your HCL environment by applying the Zero Trust princi...
Ensure the security of your HCL environment by applying the Zero Trust princi...Ensure the security of your HCL environment by applying the Zero Trust princi...
Ensure the security of your HCL environment by applying the Zero Trust princi...Roland Driesen
 
Unlocking the Secrets of Affiliate Marketing.pdf
Unlocking the Secrets of Affiliate Marketing.pdfUnlocking the Secrets of Affiliate Marketing.pdf
Unlocking the Secrets of Affiliate Marketing.pdfOnline Income Engine
 
Call Girls In DLf Gurgaon ➥99902@11544 ( Best price)100% Genuine Escort In 24...
Call Girls In DLf Gurgaon ➥99902@11544 ( Best price)100% Genuine Escort In 24...Call Girls In DLf Gurgaon ➥99902@11544 ( Best price)100% Genuine Escort In 24...
Call Girls In DLf Gurgaon ➥99902@11544 ( Best price)100% Genuine Escort In 24...lizamodels9
 
Insurers' journeys to build a mastery in the IoT usage
Insurers' journeys to build a mastery in the IoT usageInsurers' journeys to build a mastery in the IoT usage
Insurers' journeys to build a mastery in the IoT usageMatteo Carbone
 
VIP Kolkata Call Girl Howrah 👉 8250192130 Available With Room
VIP Kolkata Call Girl Howrah 👉 8250192130  Available With RoomVIP Kolkata Call Girl Howrah 👉 8250192130  Available With Room
VIP Kolkata Call Girl Howrah 👉 8250192130 Available With Roomdivyansh0kumar0
 

Recently uploaded (20)

Boost the utilization of your HCL environment by reevaluating use cases and f...
Boost the utilization of your HCL environment by reevaluating use cases and f...Boost the utilization of your HCL environment by reevaluating use cases and f...
Boost the utilization of your HCL environment by reevaluating use cases and f...
 
0183760ssssssssssssssssssssssssssss00101011 (27).pdf
0183760ssssssssssssssssssssssssssss00101011 (27).pdf0183760ssssssssssssssssssssssssssss00101011 (27).pdf
0183760ssssssssssssssssssssssssssss00101011 (27).pdf
 
Nepali Escort Girl Kakori \ 9548273370 Indian Call Girls Service Lucknow ₹,9517
Nepali Escort Girl Kakori \ 9548273370 Indian Call Girls Service Lucknow ₹,9517Nepali Escort Girl Kakori \ 9548273370 Indian Call Girls Service Lucknow ₹,9517
Nepali Escort Girl Kakori \ 9548273370 Indian Call Girls Service Lucknow ₹,9517
 
Keppel Ltd. 1Q 2024 Business Update Presentation Slides
Keppel Ltd. 1Q 2024 Business Update  Presentation SlidesKeppel Ltd. 1Q 2024 Business Update  Presentation Slides
Keppel Ltd. 1Q 2024 Business Update Presentation Slides
 
It will be International Nurses' Day on 12 May
It will be International Nurses' Day on 12 MayIt will be International Nurses' Day on 12 May
It will be International Nurses' Day on 12 May
 
VVVIP Call Girls In Greater Kailash ➡️ Delhi ➡️ 9999965857 🚀 No Advance 24HRS...
VVVIP Call Girls In Greater Kailash ➡️ Delhi ➡️ 9999965857 🚀 No Advance 24HRS...VVVIP Call Girls In Greater Kailash ➡️ Delhi ➡️ 9999965857 🚀 No Advance 24HRS...
VVVIP Call Girls In Greater Kailash ➡️ Delhi ➡️ 9999965857 🚀 No Advance 24HRS...
 
BEST ✨ Call Girls In Indirapuram Ghaziabad ✔️ 9871031762 ✔️ Escorts Service...
BEST ✨ Call Girls In  Indirapuram Ghaziabad  ✔️ 9871031762 ✔️ Escorts Service...BEST ✨ Call Girls In  Indirapuram Ghaziabad  ✔️ 9871031762 ✔️ Escorts Service...
BEST ✨ Call Girls In Indirapuram Ghaziabad ✔️ 9871031762 ✔️ Escorts Service...
 
GD Birla and his contribution in management
GD Birla and his contribution in managementGD Birla and his contribution in management
GD Birla and his contribution in management
 
Yaroslav Rozhankivskyy: Три складові і три передумови максимальної продуктивн...
Yaroslav Rozhankivskyy: Три складові і три передумови максимальної продуктивн...Yaroslav Rozhankivskyy: Три складові і три передумови максимальної продуктивн...
Yaroslav Rozhankivskyy: Три складові і три передумови максимальної продуктивн...
 
A DAY IN THE LIFE OF A SALESMAN / WOMAN
A DAY IN THE LIFE OF A  SALESMAN / WOMANA DAY IN THE LIFE OF A  SALESMAN / WOMAN
A DAY IN THE LIFE OF A SALESMAN / WOMAN
 
Value Proposition canvas- Customer needs and pains
Value Proposition canvas- Customer needs and painsValue Proposition canvas- Customer needs and pains
Value Proposition canvas- Customer needs and pains
 
The Coffee Bean & Tea Leaf(CBTL), Business strategy case study
The Coffee Bean & Tea Leaf(CBTL), Business strategy case studyThe Coffee Bean & Tea Leaf(CBTL), Business strategy case study
The Coffee Bean & Tea Leaf(CBTL), Business strategy case study
 
Creating Low-Code Loan Applications using the Trisotech Mortgage Feature Set
Creating Low-Code Loan Applications using the Trisotech Mortgage Feature SetCreating Low-Code Loan Applications using the Trisotech Mortgage Feature Set
Creating Low-Code Loan Applications using the Trisotech Mortgage Feature Set
 
Cash Payment 9602870969 Escort Service in Udaipur Call Girls
Cash Payment 9602870969 Escort Service in Udaipur Call GirlsCash Payment 9602870969 Escort Service in Udaipur Call Girls
Cash Payment 9602870969 Escort Service in Udaipur Call Girls
 
Ensure the security of your HCL environment by applying the Zero Trust princi...
Ensure the security of your HCL environment by applying the Zero Trust princi...Ensure the security of your HCL environment by applying the Zero Trust princi...
Ensure the security of your HCL environment by applying the Zero Trust princi...
 
Unlocking the Secrets of Affiliate Marketing.pdf
Unlocking the Secrets of Affiliate Marketing.pdfUnlocking the Secrets of Affiliate Marketing.pdf
Unlocking the Secrets of Affiliate Marketing.pdf
 
Forklift Operations: Safety through Cartoons
Forklift Operations: Safety through CartoonsForklift Operations: Safety through Cartoons
Forklift Operations: Safety through Cartoons
 
Call Girls In DLf Gurgaon ➥99902@11544 ( Best price)100% Genuine Escort In 24...
Call Girls In DLf Gurgaon ➥99902@11544 ( Best price)100% Genuine Escort In 24...Call Girls In DLf Gurgaon ➥99902@11544 ( Best price)100% Genuine Escort In 24...
Call Girls In DLf Gurgaon ➥99902@11544 ( Best price)100% Genuine Escort In 24...
 
Insurers' journeys to build a mastery in the IoT usage
Insurers' journeys to build a mastery in the IoT usageInsurers' journeys to build a mastery in the IoT usage
Insurers' journeys to build a mastery in the IoT usage
 
VIP Kolkata Call Girl Howrah 👉 8250192130 Available With Room
VIP Kolkata Call Girl Howrah 👉 8250192130  Available With RoomVIP Kolkata Call Girl Howrah 👉 8250192130  Available With Room
VIP Kolkata Call Girl Howrah 👉 8250192130 Available With Room
 

AX Management: Should an Outsourcer Complete a SSAE 16 Type II Audit?

  • 1. AX Management: Should an Outsourcer Complete a SSAE 16 Type II Audit? http://www.oneneck.com Copyright © 2013 OneNeck IT Services Corporation. All rights reserved.
  • 2. AX Management Many outsourcing providers offer services for AX management, but operate without a set standard for auditing and controls. To be sure application management and hosting assets are handled appropriately, a provider must follow a set standard of controls that protect each customer’s investment. What is a SSAE 16 Type II Audit? •Replacing SAS 70, SSAE 16 is an internationally recognized auditing standard developed by the American Institute of Certified Public Accountants (AICPA). •SSAE 16 performs what the SAS 70 was originally designed to do: communicate the organization’s and auditor’s attestation on assertions made by the organization through a structured report. •The SOC 1/SSAE 16 incorporates many improvements upon the original guidebook, including management attestation. http://www.oneneck.com Copyright © 2013 OneNeck IT Services Corporation. All rights reserved.
  • 3. AX Management Many outsourcing providers offer services for AX management, but operate without a set standard for auditing and controls. To be sure application management and hosting assets are handled appropriately, a provider must follow a set standard of controls that protect each customer’s investment. What is a SSAE 16 Type II Audit? •Similar to the SAS 70, the SOC 1/SSAE 16 report may be issued in two formats: Type I and Type II. •Type I reports are a point-in-time assessment of controls in place to ensure the stated control objectives are adequate. •Type II reports build upon Type I reports by requiring the collection of detailed evidence throughout a period of time. •This evidence demonstrates the control objectives defined are not only implemented, but being practiced throughout the audit period. http://www.oneneck.com Copyright © 2013 OneNeck IT Services Corporation. All rights reserved.
  • 4. AX Management A SSAE 16 Type II Audit Provides Necessary Insight for AX Management To ensure the most stringent verification of controls of an outsourcing provider’s AX management, a SSAE 16 Type II audit would be preferred. The SOC1/SSAE 16 report now provides further insight into the people, processes and technologies implemented to effectively achieve the control objectives outlined by management. The control objectives include items related to: •Administrative Duties to ensure the outsourcing provider maintains a trustworthy workforce for AX management. •Physical Security to ensure the outsourcing provider’s facilities are protected by strong policies and practices for the highest performing AX management. •Change Management to ensure effective policies for managing changes to infrastructure are followed. http://www.oneneck.com Copyright © 2013 OneNeck IT Services Corporation. All rights reserved.
  • 5. AX Management A SSAE 16 Type II Audit Provides Necessary Insight for AX Management   To ensure the most stringent verification of controls of an outsourcing provider’s AX management, a SSAE 16 Type II audit would be preferred. The SOC1/SSAE 16 report now provides further insight into the people, processes and technologies implemented to effectively achieve the control objectives outlined by management.   The control objectives include items related to:   •Availability  Management  to  ensure  the  AX  management  infrastructure  is  properly  maintained  and  the  data  center  environment  is  protected  and  conditioned  in  line  with industry best practices. •Incident  and  Event  Management  to  ensure  tools  are  in  place  and  personnel  are  properly trained to address potential business impacting events. •Request Management to ensure service requests flow through a proper life cycle. http://www.oneneck.com Copyright © 2013 OneNeck IT Services Corporation. All rights reserved.
  • 6. AX Management A SSAE 16 Type II Audit Provides Needed Confirmations   When an AX management outsourcer has completed a SSAE 16 Type II audit, customers can be assured certain claims have been verified. In other words, the company is doing what it says it does when it comes to operational metrics. For example, a SSAE 16 audit confirms the data center:   • Maintains Sufficient Data and Power Redundancy  • Maintains Appropriate Physical Security Controls   • Monitors for Excessive Temperature Fluctuations • Reviews Alerts on a Timely Basis • Has Proper Fire/Water Detection and Protection http://www.oneneck.com Copyright © 2013 OneNeck IT Services Corporation. All rights reserved.
  • 7. AX Management When a company trusts a third party for a critical service such as AX management, using only the highest quality providers is an option. Selecting an outsourcing provider without proper controls can put a business at significant risk. Therefore, companies must ensure their outsourcing partners leverage the most advanced technology and skilled personnel to help safeguard their IT assets. http://www.oneneck.com Copyright © 2013 OneNeck IT Services Corporation. All rights reserved.
  • 8. ABOUT THE AUTHOR Chuck Vermillion is CEO and founder of OneNeck IT Services, a leading provider of hosted application management and managed services since 1997. For more information about AX Management, visit http://www.oneneck.com/Solutions.aspx today. http://www.oneneck.com Copyright © 2013 OneNeck IT Services Corporation. All rights reserved.