Installment #4: So what good will a SAS 70 report do me?

So what good will it do me to get a report from my Service Provider?

Well, if your company is already subject to industry standardization requirements such as PCI-DSS, Sarbanes-Oxley, or other standards, your auditors will probably make repeated requests to obtain information from your various service providers about their security procedures and policies. Having a Type I or Type II SAS 70 report on hand will allow the service provider to easily supply information to auditors in a familiar manner that should satisfy a lot of those requests which will save your auditors time and save you money.

If you are a service provider, the reverse applies to you. Having a Type I or Type II report ready to go means you can provide information to your customers that makes their lives easier and helps them get back to business.

Post a comment or leave a trackback: Trackback URL.

Post a Comment

Required fields are marked *

*

*