SlideShare uma empresa Scribd logo
1 de 34
Baixar para ler offline
SAS 70
In A Post- Sarbanes-
Oxley, SaaS World


Francine McKenna
McKenna Partners LLC,
for SpearMC Consulting (Booth
#308)
Agenda
   What is SaaS?
   What is SAS 70?
   Today’s environment
   Security risks in a SaaS environment
   ITGC
   Q&A
Who is McKenna Partners LLC?
 McKenna Partners LLC is a specialized
  boutique consulting firm, with expertise
  in Mexico and Latin America.
 We focus on serving other professional
  services firms and industry in the area
  of internal control, IT governance. and
  compliance initiatives.
 Francine McKenna, President, is also
  the author of the blog, re: The Auditors
Who is SpearMC?
 SpearMC is a full-service consulting
  and technology services firm.
 We focus on Oracle/PeopleSoft suite of
  applications.
 The company was founded in 2001 by
  KPMG / BearingPoint alumni
In growing world of SaaS multi-tenancy
and virtualized/shared computing
resources, how are SAS 70 issues getting
resolved?
It’s a bit out of date to just get a traditional
data center SAS 70 certification when
resources are being co-mingled across
customers, and often hosted at a sub-
contracted vendor...
Depending on SAS 70s for a real level of
assurance in a SaaS environment is
shortsighted.
Do your applications have the controls
needed to insure the integrity of financial
reporting as well as support complex
business needs?
Statement on Auditing
Standards No. 70 (SAS 70)
• An international auditing standard that
  enables businesses that provide
  services to other organizations to
  provide an independent, trustworthy
  account of their internal control
  practices.
Oracle and SaaS
• Leading vendors have adopted the Oracle SaaS
  Platform for developing and delivering secure,
  scalable and easy to integrate Software as a Service
  offerings.
• The move to SaaS or On-Demand presents several
  technical challenges for software vendors and
  hosting service providers.
• ISVs have to support multi-tenancy, integration and
  customization.
• Hosting service providers have to support scalability,
  performance, security, patching, service level
  management and billing.
SaaS vs. On-Demand
• SaaS architectures generally can be
  classified as belonging to one of four
  quot;maturity levels,quot; whose key attributes
  are configurability, multi-tenant
  efficiency, and scalability.
• SaaS means software.
• On-Demand can mean anything -
  (bandwidth, computing power, storage,
  etc.)
Pre-SaaS
•   Level 1 - Ad-Hoc/Custom: Each customer has its own
    customized version of the hosted application and runs its own
    instance of the application on the host's servers. Reduces
    operating costs by consolidating server hardware and
    administration. (ASP model)
•   Level 2 - Configurable: Provides greater program flexibility
    through configurable metadata, so that many customers can use
    separate instances of the same application code. Vendor meets
    different needs of each customer through detailed configuration
    options, while simplifying maintenance and updating of a
    common code base. (Modified ASP)
•   Level 3 - Configurable, Multi-Tenant-Efficient: Adds multi-
    tenancy to the second level, so that a single program instance
    serves all customers. This approach enables more efficient use
    of server resources without any apparent difference to the end
    user, but ultimately is limited in its scalability. (Standardized
    ASP or Software On-Demand)
True SaaS
• Level 4 - Scalable, Configurable, Multi-
  Tenant-Efficient: At the fourth and final SaaS
  maturity level, scalability is added through a
  multi-tier architecture supporting a load-
  balanced farm of identical application
  instances, running on a variable number of
  servers. The system's capacity can be
  increased or decreased to match demand by
  adding or removing servers, without the need
  for any further alteration of application
  software architecture.
What is the implication for SAS
70?
• In an ASP, the vendor hosts your
  application controls in their ITGC
  environment. Do they maintain your app
  controls and meet your standards on
  ITGC?
• In a pure SaaS with standardized
  instance, you accept the vendor’s
  application and ITGC and controls. Do
  they meet your standards?
Who performs a SAS 70 “audit”
• A SAS 70 audit is performed by an
  independent auditor and results in a
  SAS 70 report, provided by service
  provider to its customers and clients for
  use when they themselves are audited.
Current uses and objectives of
SAS 70s
• SAS 70 is not a law, but an auditing and
  disclosure standards in various
  jurisdictions around the world such as
  Sarbanes-Oxley in the United States.
  This means up-to-date SAS 70 reports
  are a de facto requirement for any
  business that provides IT services to
  other businesses.
Due diligence therefore requires that you
not only request a SAS 70 report from a
prospective SaaS provider, but that you
examine it thoroughly to determine
whether the provider will be able to
comply with your own internal standards
for privacy, data security, and so on.

The earlier you start this conversation,
the better.
What purpose does a SAS 70
report serve?
• All SaaS providers should be prepared to
  provide SAS 70 reports.
• Not a stamp of approval.
• No minimum standards.
• A SAS 70 report documents internal control
  practices of an organization, without offering
  any judgment as to whether they are
  satisfactory. This is up to the user
  organization.
Customers must tell providers
which controls are important and
what standards are expected.
• Example: If local privacy laws require
  your customers' personal financial data
  be stored in encrypted form at all
  times, a SAS 70 report will document
  whether the provider's own data-
  storage practices will enable the
  customer to be in compliance with the
  law.
SaaS providers should be prepared to
answer questions from potential
customers during demos/evaluations.
They often point to controls to be
expected later and attested to by SaaS
provider’s auditor.
IT General Controls - The
Auditors Bottom Line
• The COBIT framework may be used to assist with
  SOX compliance, although COBIT is considerably
  wider in scope.
• 2007 SOX guidance from the PCAOB and SEC state
  that IT controls should only be part of the SOX 404
  assessment to the extent that specific financial risks
  are addressed.
• Scoping decision part of entity's SOx top-down risk
  assessment. Statements on Auditing Standards 109
  (SAS109) discusses the IT risks and control
  objectives pertinent to a financial audit.
IT General Controls
•   Control Environment, or those controls designed to shape the
    corporate culture or quot;tone at the top.”
•   Change management procedures - controls designed to ensure
    changes meet business requirements and are authorized.
•   Source code/document version control procedures - controls
    designed to protect the integrity of program code
•   Software development life cycle standards - controls designed
    to ensure IT projects are effectively managed.
•   Security policies, standards and processes - controls designed
    to secure access based on business need.
More IT General Controls
•   Incident management policies and procedures - controls
    designed to address operational processing errors.
•   Technical support policies and procedures - policies to help
    users perform more efficiently and report problems.
•   Hardware/software configuration, installation, testing,
    management standards, policies and procedures.
•   Disaster recovery/backup and recovery procedures, to enable
    continued processing despite adverse conditions.
Where’s my data?
•Due to compliance and data privacy
laws in many countries, knowing data
locality is critically important to meeting
compliance requirements.
•With cloud computing and Saas, issue is
a challenge. You often don’t know where
data is being stored or where application
is really being run.
•“Don’t worry. Be happy.”
Separate but equal - data
segregation
• Multi-tenancy is a SaaS advantage, but
  mixing my data with my competitors is
  icky.
• Users must never see data they are not
  authorized to see.
• My data should never be seen by other
  customers, especially competitors.
Right user, right time - Data
access
• You know how to protect data from
  unauthorized access within your organization.
  Roles, responsibilities, access, and
  authorization policies and procedures
  controlled within most IT organizations.
• Saas providers must be able to reassure
  regarding access, authorization, activity
  monitoring and segregation of duties.
Who is watching and how?
• Log management and security information
  and event management solutions readily
  available for internal IT.
• Access logs are critical to compliance,
  operations and security. SaaS providers
  should provide logs as part of normal service.
Who are you? Why are you
here? Authentication and
authorization.
•Many companies have designed IT infrastructure so
all authentication, goes through single application
such as Active Directory.
•If user credentials stored in SaaS provider
databases, controls must be in place for
removing/disabling/editing accounts.
•Could insist on delegation of authentication process
to your LDAP/AD server to maintain control if
provider’s controls not up to internal standard.
Too much of a good thing? Web
Application Security
•SaaS applications have to be used and
managed over the web (in a browser.) How
secure is your provider’s web application from
breaches such as hacking?
•Verizon says 59% of breaches are due to
hacking. Maybe SaaS providers should start
considering providing something similar to
what PCI DSS has required of merchants.
The Enemy Within - Data
breaches from insiders
•Responsibility for segregation of duties and
access authorization still falls on customers,
not providers when data is on the cloud.
•Take into consideration provider employees.
They have access to even more info and a
single incident exposes info from many
customers.
•Example: Soc Gen - All IT controls
implemented by IT management, but no one
was monitoring.
PCI DSS - Not Optional
•SaaS providers must be compliant
with PCI DSS in order to host
merchants that are required to
comply.
•Similar non-negotiable requirements
for other industries such as financial
services or health care.
Sources
• Tough Security Questions For SaaS
  Providers Part 1 and 2 at the Blog for
  Loglogic.com
• Wikipedia Information Technology Controls
  entry (from COBit)
• Wikipedia entry on Software as a Service
• ISACA - The Information Systems Audit and
  Control Association
Questions
SpearMC Education Sessions:
 Now that SOX is behind us. What about SAS70?
   – Session 52070 on Thursday 12/4/08
   – Utopia D from 8:30 – 9:30
 Project Costing and Workflow at Transunion
   – Session 51850 on Thursday 12/4/08
   – Nirvana B from 1:30 – 2:30
 Advanced PeopleSoft Financial Security Reporting
   – Session 52060 on Friday 12/5/08
   – Nirvana B from 8:30 – 9:30
Contact Information
 Francine McKenna, President, McKenna Partners
  LLC
  fmckenna@mckennapartners.com
 Marcus Bode, Principal, SpearMC
  mbode@spearmc.com
 David Pigman, Tech Specialist, SpearMC
   dpigman@spearmc.com
 Millie Babicz, Financials Specialist, SpearMC
   mbabicz@spearmc.com

Mais conteúdo relacionado

Mais procurados

Brotight China - Professional Service
Brotight China - Professional ServiceBrotight China - Professional Service
Brotight China - Professional ServiceAllen He
 
Fiori and S/4 authorizations: What are the biggest challenges, and where do t...
Fiori and S/4 authorizations: What are the biggest challenges, and where do t...Fiori and S/4 authorizations: What are the biggest challenges, and where do t...
Fiori and S/4 authorizations: What are the biggest challenges, and where do t...akquinet enterprise solutions GmbH
 
Ramp Consulting Hosted & Managed Services Solutions
Ramp Consulting Hosted & Managed Services SolutionsRamp Consulting Hosted & Managed Services Solutions
Ramp Consulting Hosted & Managed Services SolutionsBrian McCarthy
 
Mindshare Hosting Presentation
Mindshare Hosting PresentationMindshare Hosting Presentation
Mindshare Hosting PresentationChristian_A_Breaux
 
Crafting an End-to-End Pharma GRC Strategy
Crafting an End-to-End Pharma GRC StrategyCrafting an End-to-End Pharma GRC Strategy
Crafting an End-to-End Pharma GRC StrategyCognizant
 
SAP Authoziations: RENK AG tests out SAST's new self-adjusting SAP roles. [We...
SAP Authoziations: RENK AG tests out SAST's new self-adjusting SAP roles. [We...SAP Authoziations: RENK AG tests out SAST's new self-adjusting SAP roles. [We...
SAP Authoziations: RENK AG tests out SAST's new self-adjusting SAP roles. [We...akquinet enterprise solutions GmbH
 
SOX Cloud Criteria Cloud Hosted Accounting
SOX Cloud Criteria Cloud Hosted AccountingSOX Cloud Criteria Cloud Hosted Accounting
SOX Cloud Criteria Cloud Hosted AccountingRoseASP
 
IT Trends Set to Shape Software Asset Management (IBSMA SAM Summit June 2015)
IT Trends Set to Shape Software Asset Management (IBSMA SAM Summit June 2015)IT Trends Set to Shape Software Asset Management (IBSMA SAM Summit June 2015)
IT Trends Set to Shape Software Asset Management (IBSMA SAM Summit June 2015)Jon Stevens-Hall
 
081712 isaca-atl-auditing sap-grc
081712 isaca-atl-auditing sap-grc081712 isaca-atl-auditing sap-grc
081712 isaca-atl-auditing sap-grchkodali
 
XsXprt, a User Access Compliance and License Management tool for SAP
XsXprt, a User Access Compliance and License Management tool for SAPXsXprt, a User Access Compliance and License Management tool for SAP
XsXprt, a User Access Compliance and License Management tool for SAPGourav Ladha
 
FedRAMP Certification & FedRAMP Marketplace
FedRAMP Certification & FedRAMP MarketplaceFedRAMP Certification & FedRAMP Marketplace
FedRAMP Certification & FedRAMP MarketplaceControlCase
 
Enterprise Governance Risk and Compliance (GRC) Management Solution in India
Enterprise Governance Risk and Compliance (GRC) Management Solution in IndiaEnterprise Governance Risk and Compliance (GRC) Management Solution in India
Enterprise Governance Risk and Compliance (GRC) Management Solution in IndiaLexComply
 
smart-net-total-care-data-sheet
smart-net-total-care-data-sheetsmart-net-total-care-data-sheet
smart-net-total-care-data-sheetGabrielle Curtis
 
PCI PIN Security & Key Management Compliance
PCI PIN Security & Key Management CompliancePCI PIN Security & Key Management Compliance
PCI PIN Security & Key Management ComplianceControlCase
 
Docker and Container Compliance
Docker and Container ComplianceDocker and Container Compliance
Docker and Container ComplianceControlCase
 

Mais procurados (20)

SAP GRC
SAP GRC SAP GRC
SAP GRC
 
Brotight China - Professional Service
Brotight China - Professional ServiceBrotight China - Professional Service
Brotight China - Professional Service
 
Fiori and S/4 authorizations: What are the biggest challenges, and where do t...
Fiori and S/4 authorizations: What are the biggest challenges, and where do t...Fiori and S/4 authorizations: What are the biggest challenges, and where do t...
Fiori and S/4 authorizations: What are the biggest challenges, and where do t...
 
Ramp Consulting Hosted & Managed Services Solutions
Ramp Consulting Hosted & Managed Services SolutionsRamp Consulting Hosted & Managed Services Solutions
Ramp Consulting Hosted & Managed Services Solutions
 
SAP grc
SAP grc SAP grc
SAP grc
 
Mindshare Hosting Presentation
Mindshare Hosting PresentationMindshare Hosting Presentation
Mindshare Hosting Presentation
 
Crafting an End-to-End Pharma GRC Strategy
Crafting an End-to-End Pharma GRC StrategyCrafting an End-to-End Pharma GRC Strategy
Crafting an End-to-End Pharma GRC Strategy
 
K3 Hosting Brochure
K3 Hosting BrochureK3 Hosting Brochure
K3 Hosting Brochure
 
SAP Authoziations: RENK AG tests out SAST's new self-adjusting SAP roles. [We...
SAP Authoziations: RENK AG tests out SAST's new self-adjusting SAP roles. [We...SAP Authoziations: RENK AG tests out SAST's new self-adjusting SAP roles. [We...
SAP Authoziations: RENK AG tests out SAST's new self-adjusting SAP roles. [We...
 
Towards new shores with cross-system SoD analyses. [Webinar]
Towards new shores with cross-system SoD analyses. [Webinar]Towards new shores with cross-system SoD analyses. [Webinar]
Towards new shores with cross-system SoD analyses. [Webinar]
 
SOX Cloud Criteria Cloud Hosted Accounting
SOX Cloud Criteria Cloud Hosted AccountingSOX Cloud Criteria Cloud Hosted Accounting
SOX Cloud Criteria Cloud Hosted Accounting
 
IT Trends Set to Shape Software Asset Management (IBSMA SAM Summit June 2015)
IT Trends Set to Shape Software Asset Management (IBSMA SAM Summit June 2015)IT Trends Set to Shape Software Asset Management (IBSMA SAM Summit June 2015)
IT Trends Set to Shape Software Asset Management (IBSMA SAM Summit June 2015)
 
081712 isaca-atl-auditing sap-grc
081712 isaca-atl-auditing sap-grc081712 isaca-atl-auditing sap-grc
081712 isaca-atl-auditing sap-grc
 
XsXprt, a User Access Compliance and License Management tool for SAP
XsXprt, a User Access Compliance and License Management tool for SAPXsXprt, a User Access Compliance and License Management tool for SAP
XsXprt, a User Access Compliance and License Management tool for SAP
 
FedRAMP Certification & FedRAMP Marketplace
FedRAMP Certification & FedRAMP MarketplaceFedRAMP Certification & FedRAMP Marketplace
FedRAMP Certification & FedRAMP Marketplace
 
Enterprise Governance Risk and Compliance (GRC) Management Solution in India
Enterprise Governance Risk and Compliance (GRC) Management Solution in IndiaEnterprise Governance Risk and Compliance (GRC) Management Solution in India
Enterprise Governance Risk and Compliance (GRC) Management Solution in India
 
smart-net-total-care-data-sheet
smart-net-total-care-data-sheetsmart-net-total-care-data-sheet
smart-net-total-care-data-sheet
 
Business Intelligenze Corporate
Business Intelligenze CorporateBusiness Intelligenze Corporate
Business Intelligenze Corporate
 
PCI PIN Security & Key Management Compliance
PCI PIN Security & Key Management CompliancePCI PIN Security & Key Management Compliance
PCI PIN Security & Key Management Compliance
 
Docker and Container Compliance
Docker and Container ComplianceDocker and Container Compliance
Docker and Container Compliance
 

Destaque

PostgreSQL em projetos de Business Analytics e Big Data Analytics com Pentaho
PostgreSQL em projetos de Business Analytics e Big Data Analytics com PentahoPostgreSQL em projetos de Business Analytics e Big Data Analytics com Pentaho
PostgreSQL em projetos de Business Analytics e Big Data Analytics com PentahoAmbiente Livre
 
Logitech journey to the Cloud - next generation data warehousing
Logitech journey to the Cloud - next generation data warehousingLogitech journey to the Cloud - next generation data warehousing
Logitech journey to the Cloud - next generation data warehousingAvinash Deshpande
 
SteveMo Webinar: Hit a Home Run with Formula & Analytics Tricks
SteveMo Webinar: Hit a Home Run with Formula & Analytics TricksSteveMo Webinar: Hit a Home Run with Formula & Analytics Tricks
SteveMo Webinar: Hit a Home Run with Formula & Analytics TricksPanaya
 
A Journey through the Spatial Data Mining and Geographic Knowledge Discover J...
A Journey through the Spatial Data Mining and Geographic Knowledge Discover J...A Journey through the Spatial Data Mining and Geographic Knowledge Discover J...
A Journey through the Spatial Data Mining and Geographic Knowledge Discover J...SAS Asia Pacific
 
Instantly & Visually Explore Big Data with Powerful Analytics
Instantly & Visually Explore Big Data with Powerful AnalyticsInstantly & Visually Explore Big Data with Powerful Analytics
Instantly & Visually Explore Big Data with Powerful AnalyticsSAS Asia Pacific
 
Selling in global markets - Taking your business to the US
Selling in global markets - Taking your business to the USSelling in global markets - Taking your business to the US
Selling in global markets - Taking your business to the USTiE Bangalore
 
Globals Reporting mit Pentaho Business Analytics
Globals Reporting mit Pentaho Business AnalyticsGlobals Reporting mit Pentaho Business Analytics
Globals Reporting mit Pentaho Business Analyticsinovex GmbH
 
Migrate from Terma Software Jaws to CA Workload Automation iDash for Enhanced...
Migrate from Terma Software Jaws to CA Workload Automation iDash for Enhanced...Migrate from Terma Software Jaws to CA Workload Automation iDash for Enhanced...
Migrate from Terma Software Jaws to CA Workload Automation iDash for Enhanced...CA Technologies
 
SAS/Cognos Integration Approaches
SAS/Cognos Integration ApproachesSAS/Cognos Integration Approaches
SAS/Cognos Integration ApproachesPatrick Spedding
 
Top 20 Vendors - Business Insight from IT Monitoring
Top 20 Vendors - Business Insight from IT MonitoringTop 20 Vendors - Business Insight from IT Monitoring
Top 20 Vendors - Business Insight from IT MonitoringDigital Enterprise Journal
 
Numerify IT Asset Analytics for ServiceNow
Numerify IT Asset Analytics for ServiceNowNumerify IT Asset Analytics for ServiceNow
Numerify IT Asset Analytics for ServiceNowNumerify
 
Using analytics to drive app health
Using analytics to drive app healthUsing analytics to drive app health
Using analytics to drive app healthNumerify
 
HDI 2016 five innovations in analytics
HDI 2016 five innovations in analyticsHDI 2016 five innovations in analytics
HDI 2016 five innovations in analyticsNumerify
 
Numerify IT Service Analytics for ServiceNow
Numerify IT Service Analytics for ServiceNowNumerify IT Service Analytics for ServiceNow
Numerify IT Service Analytics for ServiceNowNumerify
 
Pink Elephant: Realizing business value with IT analytics
Pink Elephant: Realizing business value with IT analyticsPink Elephant: Realizing business value with IT analytics
Pink Elephant: Realizing business value with IT analyticsNumerify
 
Take a look behind the scenes at TOPdesk - itSMF Conference Belgium march 2013
Take a look behind the scenes at TOPdesk - itSMF Conference Belgium march 2013Take a look behind the scenes at TOPdesk - itSMF Conference Belgium march 2013
Take a look behind the scenes at TOPdesk - itSMF Conference Belgium march 2013TOPdesk
 
Understanding Lean Analytics (and how analytics helps businesses win)
Understanding Lean Analytics (and how analytics helps businesses win)Understanding Lean Analytics (and how analytics helps businesses win)
Understanding Lean Analytics (and how analytics helps businesses win)Lean Analytics
 

Destaque (19)

PostgreSQL em projetos de Business Analytics e Big Data Analytics com Pentaho
PostgreSQL em projetos de Business Analytics e Big Data Analytics com PentahoPostgreSQL em projetos de Business Analytics e Big Data Analytics com Pentaho
PostgreSQL em projetos de Business Analytics e Big Data Analytics com Pentaho
 
Vision2015-CBS-1148-Final
Vision2015-CBS-1148-FinalVision2015-CBS-1148-Final
Vision2015-CBS-1148-Final
 
Cloud Security Overview
Cloud Security OverviewCloud Security Overview
Cloud Security Overview
 
Logitech journey to the Cloud - next generation data warehousing
Logitech journey to the Cloud - next generation data warehousingLogitech journey to the Cloud - next generation data warehousing
Logitech journey to the Cloud - next generation data warehousing
 
SteveMo Webinar: Hit a Home Run with Formula & Analytics Tricks
SteveMo Webinar: Hit a Home Run with Formula & Analytics TricksSteveMo Webinar: Hit a Home Run with Formula & Analytics Tricks
SteveMo Webinar: Hit a Home Run with Formula & Analytics Tricks
 
A Journey through the Spatial Data Mining and Geographic Knowledge Discover J...
A Journey through the Spatial Data Mining and Geographic Knowledge Discover J...A Journey through the Spatial Data Mining and Geographic Knowledge Discover J...
A Journey through the Spatial Data Mining and Geographic Knowledge Discover J...
 
Instantly & Visually Explore Big Data with Powerful Analytics
Instantly & Visually Explore Big Data with Powerful AnalyticsInstantly & Visually Explore Big Data with Powerful Analytics
Instantly & Visually Explore Big Data with Powerful Analytics
 
Selling in global markets - Taking your business to the US
Selling in global markets - Taking your business to the USSelling in global markets - Taking your business to the US
Selling in global markets - Taking your business to the US
 
Globals Reporting mit Pentaho Business Analytics
Globals Reporting mit Pentaho Business AnalyticsGlobals Reporting mit Pentaho Business Analytics
Globals Reporting mit Pentaho Business Analytics
 
Migrate from Terma Software Jaws to CA Workload Automation iDash for Enhanced...
Migrate from Terma Software Jaws to CA Workload Automation iDash for Enhanced...Migrate from Terma Software Jaws to CA Workload Automation iDash for Enhanced...
Migrate from Terma Software Jaws to CA Workload Automation iDash for Enhanced...
 
SAS/Cognos Integration Approaches
SAS/Cognos Integration ApproachesSAS/Cognos Integration Approaches
SAS/Cognos Integration Approaches
 
Top 20 Vendors - Business Insight from IT Monitoring
Top 20 Vendors - Business Insight from IT MonitoringTop 20 Vendors - Business Insight from IT Monitoring
Top 20 Vendors - Business Insight from IT Monitoring
 
Numerify IT Asset Analytics for ServiceNow
Numerify IT Asset Analytics for ServiceNowNumerify IT Asset Analytics for ServiceNow
Numerify IT Asset Analytics for ServiceNow
 
Using analytics to drive app health
Using analytics to drive app healthUsing analytics to drive app health
Using analytics to drive app health
 
HDI 2016 five innovations in analytics
HDI 2016 five innovations in analyticsHDI 2016 five innovations in analytics
HDI 2016 five innovations in analytics
 
Numerify IT Service Analytics for ServiceNow
Numerify IT Service Analytics for ServiceNowNumerify IT Service Analytics for ServiceNow
Numerify IT Service Analytics for ServiceNow
 
Pink Elephant: Realizing business value with IT analytics
Pink Elephant: Realizing business value with IT analyticsPink Elephant: Realizing business value with IT analytics
Pink Elephant: Realizing business value with IT analytics
 
Take a look behind the scenes at TOPdesk - itSMF Conference Belgium march 2013
Take a look behind the scenes at TOPdesk - itSMF Conference Belgium march 2013Take a look behind the scenes at TOPdesk - itSMF Conference Belgium march 2013
Take a look behind the scenes at TOPdesk - itSMF Conference Belgium march 2013
 
Understanding Lean Analytics (and how analytics helps businesses win)
Understanding Lean Analytics (and how analytics helps businesses win)Understanding Lean Analytics (and how analytics helps businesses win)
Understanding Lean Analytics (and how analytics helps businesses win)
 

Semelhante a SAS 70 in a Post-Sarbanes, SaaS World: Quest Session 52070

Finance Technologies: Buy or Rent
Finance Technologies: Buy or RentFinance Technologies: Buy or Rent
Finance Technologies: Buy or RentScottMadden, Inc.
 
Improve_Application_Availability_and_Performance_Sales_Crib_Sheet.pdf
Improve_Application_Availability_and_Performance_Sales_Crib_Sheet.pdfImprove_Application_Availability_and_Performance_Sales_Crib_Sheet.pdf
Improve_Application_Availability_and_Performance_Sales_Crib_Sheet.pdfمنیزہ ہاشمی
 
Concorde Solutions ITAM Review Tools Day
Concorde Solutions ITAM Review Tools Day Concorde Solutions ITAM Review Tools Day
Concorde Solutions ITAM Review Tools Day Martin Thompson
 
Espion and SureSkills Presentation - Your Journey To A Secure Cloud
Espion and SureSkills Presentation - Your Journey To A Secure CloudEspion and SureSkills Presentation - Your Journey To A Secure Cloud
Espion and SureSkills Presentation - Your Journey To A Secure CloudGoogle
 
Ovations AWS pop-up loft 2019 Business presentation
Ovations AWS pop-up loft 2019 Business presentationOvations AWS pop-up loft 2019 Business presentation
Ovations AWS pop-up loft 2019 Business presentationGeanBoegman
 
Whitepaper: Moving to Clouds? Simplify your approach to understand the risks ...
Whitepaper: Moving to Clouds? Simplify your approach to understand the risks ...Whitepaper: Moving to Clouds? Simplify your approach to understand the risks ...
Whitepaper: Moving to Clouds? Simplify your approach to understand the risks ...Happiest Minds Technologies
 
M.S. Dissertation in Salesforce on Force.com
M.S. Dissertation in Salesforce on Force.comM.S. Dissertation in Salesforce on Force.com
M.S. Dissertation in Salesforce on Force.comArun Somu Panneerselvam
 
SaaS, MaaS, Cloud Capability
SaaS, MaaS, Cloud CapabilitySaaS, MaaS, Cloud Capability
SaaS, MaaS, Cloud Capabilitymobiangle
 
IRJET- Cloud Based Warehouse Management Firm
IRJET- Cloud Based Warehouse Management FirmIRJET- Cloud Based Warehouse Management Firm
IRJET- Cloud Based Warehouse Management FirmIRJET Journal
 
Cyber Security in The Cloud
Cyber Security in The CloudCyber Security in The Cloud
Cyber Security in The CloudPECB
 
Cloud investment buyers guide
Cloud investment buyers guideCloud investment buyers guide
Cloud investment buyers guideKaizenlogcom
 
Cloud investment buyers guide
Cloud investment buyers guideCloud investment buyers guide
Cloud investment buyers guideKaizenlogcom
 
VMworld 2013: Create a Key Metrics-based Actionable Roadmap to Deliver IT as ...
VMworld 2013: Create a Key Metrics-based Actionable Roadmap to Deliver IT as ...VMworld 2013: Create a Key Metrics-based Actionable Roadmap to Deliver IT as ...
VMworld 2013: Create a Key Metrics-based Actionable Roadmap to Deliver IT as ...VMworld
 
Simplify Your Approach To_Assess The Risks Of Moving Into The Cloud
Simplify Your Approach To_Assess The Risks Of Moving Into The CloudSimplify Your Approach To_Assess The Risks Of Moving Into The Cloud
Simplify Your Approach To_Assess The Risks Of Moving Into The CloudHappiest Minds Technologies
 
Pre-Con Ed: Software Asset Management Jump Start: Ingredients to Success
Pre-Con Ed: Software Asset Management Jump Start: Ingredients to SuccessPre-Con Ed: Software Asset Management Jump Start: Ingredients to Success
Pre-Con Ed: Software Asset Management Jump Start: Ingredients to SuccessCA Technologies
 
Pre-Con Ed: Software Asset Management: Working in the Trenches
Pre-Con Ed: Software Asset Management: Working in the TrenchesPre-Con Ed: Software Asset Management: Working in the Trenches
Pre-Con Ed: Software Asset Management: Working in the TrenchesCA Technologies
 
BusinessIntelligenze - MaaS & SaaS
BusinessIntelligenze - MaaS & SaaSBusinessIntelligenze - MaaS & SaaS
BusinessIntelligenze - MaaS & SaaSBusinessIntelligenze
 
SAP Leonardo Blockchain Services and Use-Cases
SAP Leonardo Blockchain Services and Use-CasesSAP Leonardo Blockchain Services and Use-Cases
SAP Leonardo Blockchain Services and Use-CasesNagesh Caparthy
 
Modernising the Enterprise: An Evening with the AWS Enterprise User Group
Modernising the Enterprise: An Evening with the AWS Enterprise User GroupModernising the Enterprise: An Evening with the AWS Enterprise User Group
Modernising the Enterprise: An Evening with the AWS Enterprise User GroupHarley Young
 

Semelhante a SAS 70 in a Post-Sarbanes, SaaS World: Quest Session 52070 (20)

SAP License Cost
SAP License CostSAP License Cost
SAP License Cost
 
Finance Technologies: Buy or Rent
Finance Technologies: Buy or RentFinance Technologies: Buy or Rent
Finance Technologies: Buy or Rent
 
Improve_Application_Availability_and_Performance_Sales_Crib_Sheet.pdf
Improve_Application_Availability_and_Performance_Sales_Crib_Sheet.pdfImprove_Application_Availability_and_Performance_Sales_Crib_Sheet.pdf
Improve_Application_Availability_and_Performance_Sales_Crib_Sheet.pdf
 
Concorde Solutions ITAM Review Tools Day
Concorde Solutions ITAM Review Tools Day Concorde Solutions ITAM Review Tools Day
Concorde Solutions ITAM Review Tools Day
 
Espion and SureSkills Presentation - Your Journey To A Secure Cloud
Espion and SureSkills Presentation - Your Journey To A Secure CloudEspion and SureSkills Presentation - Your Journey To A Secure Cloud
Espion and SureSkills Presentation - Your Journey To A Secure Cloud
 
Ovations AWS pop-up loft 2019 Business presentation
Ovations AWS pop-up loft 2019 Business presentationOvations AWS pop-up loft 2019 Business presentation
Ovations AWS pop-up loft 2019 Business presentation
 
Whitepaper: Moving to Clouds? Simplify your approach to understand the risks ...
Whitepaper: Moving to Clouds? Simplify your approach to understand the risks ...Whitepaper: Moving to Clouds? Simplify your approach to understand the risks ...
Whitepaper: Moving to Clouds? Simplify your approach to understand the risks ...
 
M.S. Dissertation in Salesforce on Force.com
M.S. Dissertation in Salesforce on Force.comM.S. Dissertation in Salesforce on Force.com
M.S. Dissertation in Salesforce on Force.com
 
SaaS, MaaS, Cloud Capability
SaaS, MaaS, Cloud CapabilitySaaS, MaaS, Cloud Capability
SaaS, MaaS, Cloud Capability
 
IRJET- Cloud Based Warehouse Management Firm
IRJET- Cloud Based Warehouse Management FirmIRJET- Cloud Based Warehouse Management Firm
IRJET- Cloud Based Warehouse Management Firm
 
Cyber Security in The Cloud
Cyber Security in The CloudCyber Security in The Cloud
Cyber Security in The Cloud
 
Cloud investment buyers guide
Cloud investment buyers guideCloud investment buyers guide
Cloud investment buyers guide
 
Cloud investment buyers guide
Cloud investment buyers guideCloud investment buyers guide
Cloud investment buyers guide
 
VMworld 2013: Create a Key Metrics-based Actionable Roadmap to Deliver IT as ...
VMworld 2013: Create a Key Metrics-based Actionable Roadmap to Deliver IT as ...VMworld 2013: Create a Key Metrics-based Actionable Roadmap to Deliver IT as ...
VMworld 2013: Create a Key Metrics-based Actionable Roadmap to Deliver IT as ...
 
Simplify Your Approach To_Assess The Risks Of Moving Into The Cloud
Simplify Your Approach To_Assess The Risks Of Moving Into The CloudSimplify Your Approach To_Assess The Risks Of Moving Into The Cloud
Simplify Your Approach To_Assess The Risks Of Moving Into The Cloud
 
Pre-Con Ed: Software Asset Management Jump Start: Ingredients to Success
Pre-Con Ed: Software Asset Management Jump Start: Ingredients to SuccessPre-Con Ed: Software Asset Management Jump Start: Ingredients to Success
Pre-Con Ed: Software Asset Management Jump Start: Ingredients to Success
 
Pre-Con Ed: Software Asset Management: Working in the Trenches
Pre-Con Ed: Software Asset Management: Working in the TrenchesPre-Con Ed: Software Asset Management: Working in the Trenches
Pre-Con Ed: Software Asset Management: Working in the Trenches
 
BusinessIntelligenze - MaaS & SaaS
BusinessIntelligenze - MaaS & SaaSBusinessIntelligenze - MaaS & SaaS
BusinessIntelligenze - MaaS & SaaS
 
SAP Leonardo Blockchain Services and Use-Cases
SAP Leonardo Blockchain Services and Use-CasesSAP Leonardo Blockchain Services and Use-Cases
SAP Leonardo Blockchain Services and Use-Cases
 
Modernising the Enterprise: An Evening with the AWS Enterprise User Group
Modernising the Enterprise: An Evening with the AWS Enterprise User GroupModernising the Enterprise: An Evening with the AWS Enterprise User Group
Modernising the Enterprise: An Evening with the AWS Enterprise User Group
 

Último

"LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks...
"LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks..."LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks...
"LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks...Fwdays
 
Search Engine Optimization SEO PDF for 2024.pdf
Search Engine Optimization SEO PDF for 2024.pdfSearch Engine Optimization SEO PDF for 2024.pdf
Search Engine Optimization SEO PDF for 2024.pdfRankYa
 
Powerpoint exploring the locations used in television show Time Clash
Powerpoint exploring the locations used in television show Time ClashPowerpoint exploring the locations used in television show Time Clash
Powerpoint exploring the locations used in television show Time Clashcharlottematthew16
 
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmatics
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmaticsKotlin Multiplatform & Compose Multiplatform - Starter kit for pragmatics
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmaticscarlostorres15106
 
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024BookNet Canada
 
"Debugging python applications inside k8s environment", Andrii Soldatenko
"Debugging python applications inside k8s environment", Andrii Soldatenko"Debugging python applications inside k8s environment", Andrii Soldatenko
"Debugging python applications inside k8s environment", Andrii SoldatenkoFwdays
 
Unraveling Multimodality with Large Language Models.pdf
Unraveling Multimodality with Large Language Models.pdfUnraveling Multimodality with Large Language Models.pdf
Unraveling Multimodality with Large Language Models.pdfAlex Barbosa Coqueiro
 
Leverage Zilliz Serverless - Up to 50X Saving for Your Vector Storage Cost
Leverage Zilliz Serverless - Up to 50X Saving for Your Vector Storage CostLeverage Zilliz Serverless - Up to 50X Saving for Your Vector Storage Cost
Leverage Zilliz Serverless - Up to 50X Saving for Your Vector Storage CostZilliz
 
Story boards and shot lists for my a level piece
Story boards and shot lists for my a level pieceStory boards and shot lists for my a level piece
Story boards and shot lists for my a level piececharlottematthew16
 
Bun (KitWorks Team Study 노별마루 발표 2024.4.22)
Bun (KitWorks Team Study 노별마루 발표 2024.4.22)Bun (KitWorks Team Study 노별마루 발표 2024.4.22)
Bun (KitWorks Team Study 노별마루 발표 2024.4.22)Wonjun Hwang
 
SIP trunking in Janus @ Kamailio World 2024
SIP trunking in Janus @ Kamailio World 2024SIP trunking in Janus @ Kamailio World 2024
SIP trunking in Janus @ Kamailio World 2024Lorenzo Miniero
 
Install Stable Diffusion in windows machine
Install Stable Diffusion in windows machineInstall Stable Diffusion in windows machine
Install Stable Diffusion in windows machinePadma Pradeep
 
Nell’iperspazio con Rocket: il Framework Web di Rust!
Nell’iperspazio con Rocket: il Framework Web di Rust!Nell’iperspazio con Rocket: il Framework Web di Rust!
Nell’iperspazio con Rocket: il Framework Web di Rust!Commit University
 
Gen AI in Business - Global Trends Report 2024.pdf
Gen AI in Business - Global Trends Report 2024.pdfGen AI in Business - Global Trends Report 2024.pdf
Gen AI in Business - Global Trends Report 2024.pdfAddepto
 
Vertex AI Gemini Prompt Engineering Tips
Vertex AI Gemini Prompt Engineering TipsVertex AI Gemini Prompt Engineering Tips
Vertex AI Gemini Prompt Engineering TipsMiki Katsuragi
 
My INSURER PTE LTD - Insurtech Innovation Award 2024
My INSURER PTE LTD - Insurtech Innovation Award 2024My INSURER PTE LTD - Insurtech Innovation Award 2024
My INSURER PTE LTD - Insurtech Innovation Award 2024The Digital Insurer
 
Scanning the Internet for External Cloud Exposures via SSL Certs
Scanning the Internet for External Cloud Exposures via SSL CertsScanning the Internet for External Cloud Exposures via SSL Certs
Scanning the Internet for External Cloud Exposures via SSL CertsRizwan Syed
 
Developer Data Modeling Mistakes: From Postgres to NoSQL
Developer Data Modeling Mistakes: From Postgres to NoSQLDeveloper Data Modeling Mistakes: From Postgres to NoSQL
Developer Data Modeling Mistakes: From Postgres to NoSQLScyllaDB
 
The Future of Software Development - Devin AI Innovative Approach.pdf
The Future of Software Development - Devin AI Innovative Approach.pdfThe Future of Software Development - Devin AI Innovative Approach.pdf
The Future of Software Development - Devin AI Innovative Approach.pdfSeasiaInfotech2
 

Último (20)

"LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks...
"LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks..."LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks...
"LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks...
 
Search Engine Optimization SEO PDF for 2024.pdf
Search Engine Optimization SEO PDF for 2024.pdfSearch Engine Optimization SEO PDF for 2024.pdf
Search Engine Optimization SEO PDF for 2024.pdf
 
Powerpoint exploring the locations used in television show Time Clash
Powerpoint exploring the locations used in television show Time ClashPowerpoint exploring the locations used in television show Time Clash
Powerpoint exploring the locations used in television show Time Clash
 
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmatics
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmaticsKotlin Multiplatform & Compose Multiplatform - Starter kit for pragmatics
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmatics
 
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
 
DMCC Future of Trade Web3 - Special Edition
DMCC Future of Trade Web3 - Special EditionDMCC Future of Trade Web3 - Special Edition
DMCC Future of Trade Web3 - Special Edition
 
"Debugging python applications inside k8s environment", Andrii Soldatenko
"Debugging python applications inside k8s environment", Andrii Soldatenko"Debugging python applications inside k8s environment", Andrii Soldatenko
"Debugging python applications inside k8s environment", Andrii Soldatenko
 
Unraveling Multimodality with Large Language Models.pdf
Unraveling Multimodality with Large Language Models.pdfUnraveling Multimodality with Large Language Models.pdf
Unraveling Multimodality with Large Language Models.pdf
 
Leverage Zilliz Serverless - Up to 50X Saving for Your Vector Storage Cost
Leverage Zilliz Serverless - Up to 50X Saving for Your Vector Storage CostLeverage Zilliz Serverless - Up to 50X Saving for Your Vector Storage Cost
Leverage Zilliz Serverless - Up to 50X Saving for Your Vector Storage Cost
 
Story boards and shot lists for my a level piece
Story boards and shot lists for my a level pieceStory boards and shot lists for my a level piece
Story boards and shot lists for my a level piece
 
Bun (KitWorks Team Study 노별마루 발표 2024.4.22)
Bun (KitWorks Team Study 노별마루 발표 2024.4.22)Bun (KitWorks Team Study 노별마루 발표 2024.4.22)
Bun (KitWorks Team Study 노별마루 발표 2024.4.22)
 
SIP trunking in Janus @ Kamailio World 2024
SIP trunking in Janus @ Kamailio World 2024SIP trunking in Janus @ Kamailio World 2024
SIP trunking in Janus @ Kamailio World 2024
 
Install Stable Diffusion in windows machine
Install Stable Diffusion in windows machineInstall Stable Diffusion in windows machine
Install Stable Diffusion in windows machine
 
Nell’iperspazio con Rocket: il Framework Web di Rust!
Nell’iperspazio con Rocket: il Framework Web di Rust!Nell’iperspazio con Rocket: il Framework Web di Rust!
Nell’iperspazio con Rocket: il Framework Web di Rust!
 
Gen AI in Business - Global Trends Report 2024.pdf
Gen AI in Business - Global Trends Report 2024.pdfGen AI in Business - Global Trends Report 2024.pdf
Gen AI in Business - Global Trends Report 2024.pdf
 
Vertex AI Gemini Prompt Engineering Tips
Vertex AI Gemini Prompt Engineering TipsVertex AI Gemini Prompt Engineering Tips
Vertex AI Gemini Prompt Engineering Tips
 
My INSURER PTE LTD - Insurtech Innovation Award 2024
My INSURER PTE LTD - Insurtech Innovation Award 2024My INSURER PTE LTD - Insurtech Innovation Award 2024
My INSURER PTE LTD - Insurtech Innovation Award 2024
 
Scanning the Internet for External Cloud Exposures via SSL Certs
Scanning the Internet for External Cloud Exposures via SSL CertsScanning the Internet for External Cloud Exposures via SSL Certs
Scanning the Internet for External Cloud Exposures via SSL Certs
 
Developer Data Modeling Mistakes: From Postgres to NoSQL
Developer Data Modeling Mistakes: From Postgres to NoSQLDeveloper Data Modeling Mistakes: From Postgres to NoSQL
Developer Data Modeling Mistakes: From Postgres to NoSQL
 
The Future of Software Development - Devin AI Innovative Approach.pdf
The Future of Software Development - Devin AI Innovative Approach.pdfThe Future of Software Development - Devin AI Innovative Approach.pdf
The Future of Software Development - Devin AI Innovative Approach.pdf
 

SAS 70 in a Post-Sarbanes, SaaS World: Quest Session 52070

  • 1. SAS 70 In A Post- Sarbanes- Oxley, SaaS World Francine McKenna McKenna Partners LLC, for SpearMC Consulting (Booth #308)
  • 2. Agenda  What is SaaS?  What is SAS 70?  Today’s environment  Security risks in a SaaS environment  ITGC  Q&A
  • 3. Who is McKenna Partners LLC?  McKenna Partners LLC is a specialized boutique consulting firm, with expertise in Mexico and Latin America.  We focus on serving other professional services firms and industry in the area of internal control, IT governance. and compliance initiatives.  Francine McKenna, President, is also the author of the blog, re: The Auditors
  • 4. Who is SpearMC?  SpearMC is a full-service consulting and technology services firm.  We focus on Oracle/PeopleSoft suite of applications.  The company was founded in 2001 by KPMG / BearingPoint alumni
  • 5. In growing world of SaaS multi-tenancy and virtualized/shared computing resources, how are SAS 70 issues getting resolved?
  • 6. It’s a bit out of date to just get a traditional data center SAS 70 certification when resources are being co-mingled across customers, and often hosted at a sub- contracted vendor...
  • 7. Depending on SAS 70s for a real level of assurance in a SaaS environment is shortsighted. Do your applications have the controls needed to insure the integrity of financial reporting as well as support complex business needs?
  • 8. Statement on Auditing Standards No. 70 (SAS 70) • An international auditing standard that enables businesses that provide services to other organizations to provide an independent, trustworthy account of their internal control practices.
  • 9. Oracle and SaaS • Leading vendors have adopted the Oracle SaaS Platform for developing and delivering secure, scalable and easy to integrate Software as a Service offerings. • The move to SaaS or On-Demand presents several technical challenges for software vendors and hosting service providers. • ISVs have to support multi-tenancy, integration and customization. • Hosting service providers have to support scalability, performance, security, patching, service level management and billing.
  • 10. SaaS vs. On-Demand • SaaS architectures generally can be classified as belonging to one of four quot;maturity levels,quot; whose key attributes are configurability, multi-tenant efficiency, and scalability. • SaaS means software. • On-Demand can mean anything - (bandwidth, computing power, storage, etc.)
  • 11. Pre-SaaS • Level 1 - Ad-Hoc/Custom: Each customer has its own customized version of the hosted application and runs its own instance of the application on the host's servers. Reduces operating costs by consolidating server hardware and administration. (ASP model) • Level 2 - Configurable: Provides greater program flexibility through configurable metadata, so that many customers can use separate instances of the same application code. Vendor meets different needs of each customer through detailed configuration options, while simplifying maintenance and updating of a common code base. (Modified ASP) • Level 3 - Configurable, Multi-Tenant-Efficient: Adds multi- tenancy to the second level, so that a single program instance serves all customers. This approach enables more efficient use of server resources without any apparent difference to the end user, but ultimately is limited in its scalability. (Standardized ASP or Software On-Demand)
  • 12. True SaaS • Level 4 - Scalable, Configurable, Multi- Tenant-Efficient: At the fourth and final SaaS maturity level, scalability is added through a multi-tier architecture supporting a load- balanced farm of identical application instances, running on a variable number of servers. The system's capacity can be increased or decreased to match demand by adding or removing servers, without the need for any further alteration of application software architecture.
  • 13. What is the implication for SAS 70? • In an ASP, the vendor hosts your application controls in their ITGC environment. Do they maintain your app controls and meet your standards on ITGC? • In a pure SaaS with standardized instance, you accept the vendor’s application and ITGC and controls. Do they meet your standards?
  • 14. Who performs a SAS 70 “audit” • A SAS 70 audit is performed by an independent auditor and results in a SAS 70 report, provided by service provider to its customers and clients for use when they themselves are audited.
  • 15. Current uses and objectives of SAS 70s • SAS 70 is not a law, but an auditing and disclosure standards in various jurisdictions around the world such as Sarbanes-Oxley in the United States. This means up-to-date SAS 70 reports are a de facto requirement for any business that provides IT services to other businesses.
  • 16. Due diligence therefore requires that you not only request a SAS 70 report from a prospective SaaS provider, but that you examine it thoroughly to determine whether the provider will be able to comply with your own internal standards for privacy, data security, and so on. The earlier you start this conversation, the better.
  • 17. What purpose does a SAS 70 report serve? • All SaaS providers should be prepared to provide SAS 70 reports. • Not a stamp of approval. • No minimum standards. • A SAS 70 report documents internal control practices of an organization, without offering any judgment as to whether they are satisfactory. This is up to the user organization.
  • 18. Customers must tell providers which controls are important and what standards are expected. • Example: If local privacy laws require your customers' personal financial data be stored in encrypted form at all times, a SAS 70 report will document whether the provider's own data- storage practices will enable the customer to be in compliance with the law.
  • 19. SaaS providers should be prepared to answer questions from potential customers during demos/evaluations. They often point to controls to be expected later and attested to by SaaS provider’s auditor.
  • 20. IT General Controls - The Auditors Bottom Line • The COBIT framework may be used to assist with SOX compliance, although COBIT is considerably wider in scope. • 2007 SOX guidance from the PCAOB and SEC state that IT controls should only be part of the SOX 404 assessment to the extent that specific financial risks are addressed. • Scoping decision part of entity's SOx top-down risk assessment. Statements on Auditing Standards 109 (SAS109) discusses the IT risks and control objectives pertinent to a financial audit.
  • 21. IT General Controls • Control Environment, or those controls designed to shape the corporate culture or quot;tone at the top.” • Change management procedures - controls designed to ensure changes meet business requirements and are authorized. • Source code/document version control procedures - controls designed to protect the integrity of program code • Software development life cycle standards - controls designed to ensure IT projects are effectively managed. • Security policies, standards and processes - controls designed to secure access based on business need.
  • 22. More IT General Controls • Incident management policies and procedures - controls designed to address operational processing errors. • Technical support policies and procedures - policies to help users perform more efficiently and report problems. • Hardware/software configuration, installation, testing, management standards, policies and procedures. • Disaster recovery/backup and recovery procedures, to enable continued processing despite adverse conditions.
  • 23. Where’s my data? •Due to compliance and data privacy laws in many countries, knowing data locality is critically important to meeting compliance requirements. •With cloud computing and Saas, issue is a challenge. You often don’t know where data is being stored or where application is really being run. •“Don’t worry. Be happy.”
  • 24. Separate but equal - data segregation • Multi-tenancy is a SaaS advantage, but mixing my data with my competitors is icky. • Users must never see data they are not authorized to see. • My data should never be seen by other customers, especially competitors.
  • 25. Right user, right time - Data access • You know how to protect data from unauthorized access within your organization. Roles, responsibilities, access, and authorization policies and procedures controlled within most IT organizations. • Saas providers must be able to reassure regarding access, authorization, activity monitoring and segregation of duties.
  • 26. Who is watching and how? • Log management and security information and event management solutions readily available for internal IT. • Access logs are critical to compliance, operations and security. SaaS providers should provide logs as part of normal service.
  • 27. Who are you? Why are you here? Authentication and authorization. •Many companies have designed IT infrastructure so all authentication, goes through single application such as Active Directory. •If user credentials stored in SaaS provider databases, controls must be in place for removing/disabling/editing accounts. •Could insist on delegation of authentication process to your LDAP/AD server to maintain control if provider’s controls not up to internal standard.
  • 28. Too much of a good thing? Web Application Security •SaaS applications have to be used and managed over the web (in a browser.) How secure is your provider’s web application from breaches such as hacking? •Verizon says 59% of breaches are due to hacking. Maybe SaaS providers should start considering providing something similar to what PCI DSS has required of merchants.
  • 29. The Enemy Within - Data breaches from insiders •Responsibility for segregation of duties and access authorization still falls on customers, not providers when data is on the cloud. •Take into consideration provider employees. They have access to even more info and a single incident exposes info from many customers. •Example: Soc Gen - All IT controls implemented by IT management, but no one was monitoring.
  • 30. PCI DSS - Not Optional •SaaS providers must be compliant with PCI DSS in order to host merchants that are required to comply. •Similar non-negotiable requirements for other industries such as financial services or health care.
  • 31. Sources • Tough Security Questions For SaaS Providers Part 1 and 2 at the Blog for Loglogic.com • Wikipedia Information Technology Controls entry (from COBit) • Wikipedia entry on Software as a Service • ISACA - The Information Systems Audit and Control Association
  • 33. SpearMC Education Sessions:  Now that SOX is behind us. What about SAS70? – Session 52070 on Thursday 12/4/08 – Utopia D from 8:30 – 9:30  Project Costing and Workflow at Transunion – Session 51850 on Thursday 12/4/08 – Nirvana B from 1:30 – 2:30  Advanced PeopleSoft Financial Security Reporting – Session 52060 on Friday 12/5/08 – Nirvana B from 8:30 – 9:30
  • 34. Contact Information  Francine McKenna, President, McKenna Partners LLC fmckenna@mckennapartners.com  Marcus Bode, Principal, SpearMC mbode@spearmc.com  David Pigman, Tech Specialist, SpearMC dpigman@spearmc.com  Millie Babicz, Financials Specialist, SpearMC mbabicz@spearmc.com