-
10
pages
-
English
-
Documents
Description
Does a SAS 70 Audit Leave you at Risk of a Security Exposure or Failure to Comply with FISMA? A brief overview of security requirements for Federal government agencies applicable to contracted IT services, applications and outsourced business processes. This paper examines the use of a common industry assessment method to reveal differences in scope and intent with that of FISMA and NIST. These differences result in gaps that impact both Federal Government agencies and the solutions and services providers that serve them. Does the SAS 70 Audit Meet the Requirements of FISMA and NIST? Executive Summary This whitepaper examines the requirements of Federal Information Security Management Act (FISMA) and associated NIST security standards that define the Federal Government information security framework. When Government uses outsourcing, managed services or software as a service (SaaS) approaches for business services or technology solutions, commercial providers must meet government security standards. A common industry assessment standard used is known as the Statement of Auditing Standards (SAS) No. 70. The objective of this paper is to contrast the SAS 70 assessment method to the FISMA requirements and NIST standards to highlight the differences and gaps which Federal government agencies must be aware and solution providers must address. Background The E-Government Act (Public Law 107-347) of 2002, Title III ...
-
Publié par
-
Langue
English