This is an audio version of a blog article.
The original article was published here:
https://www.riskinsights.com.au/blog-1/sas70-certification-and-other-soc-report-myths
SAS70 certification and other common SOC report myths
If you use or plan to use a cloud/SaaS/hosted solution, how do you ensure that the service provider is protecting your systems and data?
Rely on their SAS70 reports, right?
Not quite.
In this article, we explain why this is not the right answer and explore a few other common myths.
Background
System and Organization Controls (SOC) reports used to be conducted in accordance with "SAS70" in the US.
A few years ago, SAS70 was replaced by:
- In the US: SSAE18, now replaced by SSAE18.
- Globally: ISAE3402.
- In Australia: ASAE3402.
For audits that are conducted in accordance with these standards, a SOC report is produced.
SOC 1 Myths
1. Certification or compliance - Myth: The outsourced service provider is certified or compliant.
2. Qualified Opinions - Myth: A qualified SOC report is the same as qualified financials, which is bad.
3. Use of SOC 1 reports - Myth: The reports can be used to determine the level of control over all IT risks.
This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit riskinsightsblogcast.substack.com
Hosted on Acast. See acast.com/privacy for more information.