Important Notice: Our web hosting provider recently started charging us for additional visits, which was unexpected. In response, we're seeking donations. Depending on the situation, we may explore different monetization options for our Community and Expert Contributors. It's crucial to provide more returns for their expertise and offer more Expert Validated Answers or AI Validated Answers. Learn more about our hosting issue here.

Is there a list of SAS 70 standards, control objectives, or checklists?

0
Posted

Is there a list of SAS 70 standards, control objectives, or checklists?

0

Since service organizations are responsible for describing their controls and defining their control objectives, there is no published list of SAS 70 standards. Generally, the control objectives are specific to the service organization and their customers. However, there are some great sources of control objectives and other published standards that can be used to prepare for a SAS 70 audit or another type of third party assurance. The Information Systems Audit and Control Association (ISACA) publishes a set of control objectives referred to as “CoBIT”. Information on CoBIT and how to purchase the latest editions are on the ISACA website at http://www.isaca.org. Another great source of guidance is the WebTrust Principles and Criteria and the SysTrust Principles and Criteria. Both are available from the AICPA website and can be downloaded for free at http://www.aicpa.org/assurance. Each principle has specific criteria elements and illustrative controls that can serve as a baseline for y

Related Questions

What is your question?

*Sadly, we had to bring back ads too. Hopefully more targeted.

Experts123