So what good will it do me to get a report from my Service Provider?
Well, if your company is already subject to industry standardization requirements such as PCI-DSS, Sarbanes-Oxley, or other standards, your auditors will probably make repeated requests to obtain information from your various service providers about their security procedures and policies. Having a Type I or Type II SAS 70 report on hand will allow the service provider to easily supply information to auditors in a familiar manner that should satisfy a lot of those requests which will save your auditors time and save you money.
If you are a service provider, the reverse applies to you. Having a Type I or Type II report ready to go means you can provide information to your customers that makes their lives easier and helps them get back to business.
Post a Comment