So what is the bottom line to my company?
If you are a service provider, having a SAS 70 report ready can mean a shortcut for your company to help its customers with their auditing and compliance needs. It can help your company to maintain security and policy awareness, which will build your ability to perform in an ever more risk-adverse financial world. Likewise, such certifications are growing increasingly attractive to potential clients and can make or break a deal.
An SAS 70 audit can be a real walk in the park if you are confident that your policies are well documented, and properly followed by your employees. This is something you need to do anyway to ensure the viability of your company as a service provider. As long as you are already implementing policies and procedures and following them correctly, your audit should be a painless and interesting process which will help you get an outside person’s view into your daily workflow.
If you have service providers you do business with and need to make sure they are staying compliant with their own policies, an SAS 70 report can help your company to feel more secure about the providers you do business with. Additionally, if you need to comply with industry standardization requirements or policy requirements internally, you can save your company and your auditors’ time and money by having an SAS 70 report on hand from each of your major service providers.
Comments
found your site on del.icio.us today and really liked it.. i bookmarked it and will be back to check it out some more later
If only more people would read this..
If only more people could hear about this..
If only more than 24 people would hear about this..
Super great writing! Honestly.
If only more people could read about this.
If only I had a nickel for each time I came to http://www.sas70wiki.com! Amazing article.
If only more people would read about this!
Post a Comment