<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>The SSAE 16 Reporting Standard - SOC 1 - SOC 2 - SOC 3</title>
	<atom:link href="http://www.ssae-16.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.ssae-16.com</link>
	<description>Support and Guidance for SSAE16, SOC 1, SOC 2, and SOC 3 reporting standards</description>
	<lastBuildDate>Wed, 16 May 2012 05:41:32 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>SSAE 16 Preparation Checklist</title>
		<link>http://www.ssae-16.com/ssae-16/ssae-16-preparation-checklist/</link>
		<comments>http://www.ssae-16.com/ssae-16/ssae-16-preparation-checklist/#comments</comments>
		<pubDate>Wed, 16 May 2012 05:41:32 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[SSAE 16]]></category>
		<category><![CDATA[SSAE 16 Preparation]]></category>
		<category><![CDATA[checklist]]></category>
		<category><![CDATA[control activities]]></category>
		<category><![CDATA[control objectives]]></category>
		<category><![CDATA[readiness assessment]]></category>
		<category><![CDATA[SAS 70]]></category>
		<category><![CDATA[SAS70]]></category>
		<category><![CDATA[scope]]></category>
		<category><![CDATA[ssae 16 audit checklist]]></category>
		<category><![CDATA[ssae 16 checklist]]></category>
		<category><![CDATA[ssae 16 process mapping guide]]></category>
		<category><![CDATA[ssae 16 report]]></category>
		<category><![CDATA[SSAE 16 Review]]></category>
		<category><![CDATA[ssae 16 review checklist]]></category>
		<category><![CDATA[ssae 16 testing definition]]></category>

		<guid isPermaLink="false">http://www.ssae-16.com/?p=135</guid>
		<description><![CDATA[I&#8217;ve been hearing from various people in the marketplace that they were interested in learning about some steps, at a high level, that they need to take to get off the ground and on their way to completing their SSAE 16 Report Type I or Type II. So, I will give you guys a breakdown of [...]]]></description>
			<content:encoded><![CDATA[<p>I&#8217;ve been hearing from various people in the marketplace that they were interested in learning about some steps, at a high level, that they need to take to get off the ground and on their way to completing their <a href="http://www.ssae-16.com/">SSAE 16</a> Report Type I or Type II. So, I will give you guys a breakdown of some of the things you should be doing now, and some things to think about down the line as you progress.<br />
<br/><br />
This SSAE 16 <a href="http://www.ssae-16.com/ssae-16/ssae-16-preparation-checklist/">Checklist</a> is geared towards service organizations whom have never done a SAS 70 in the past and will be taking up the task this coming year when SSAE 16 will be in full effect. A more detailed version geared towards companies that have some experience being audited will be coming down the line.</p>
<ul>
<li>Do your research.
<ul>
<li>You have already come across our site, so you have begun the process of researching SSAE 16 and the responsibilities that come with performing one. I would continue to search for SAS 70 related information as well, as most of that knowledge is applicable.</li>
</ul>
</li>
<li> Find a few CPA firms who perform SSAE 16&#8242;s (or SAS 70).
<ul>
<li>You will want to research a number of firms that could perform and sign off on your SSAE 16 Report, which, only CPA firms are permitted to do. This process should be handled with the <span style="text-decoration: underline;">utmost</span> care as you are putting a lot of trust into the company you choose, they can make or break you.</li>
<li>Some things to consider:
<ol>1. The size of your company &#8211; You may not be able to afford a large CPA firm.</ol>
<ol>2. The clientele you are attracting &#8211; Some companies will not feel secure with the quality of your SSAE 16 if it was performed by a firm that isn&#8217;t well known.</ol>
<ol>3. Total SSAE 16&#8242;s or SAS 70&#8242;s performed &#8211; You do not want to use a company who has never done such work in the past, unless they are comprised of former employees of another quality firm and have decided to take off on their own.</ol>
<ol>4. The methodology employed &#8211; You will want to quiz the companies and gain comfort around their methods and ensure you are comfortable with their responses and agree based upon your research.</ol>
</li>
</ul>
</li>
<li>Narrow your search.
<ul>
<li>Based upon how you felt about each company, the people, the methodology, their previous experience, and of course, cost,  you should narrow down your search to the top 2 companies.</li>
<li>Pricing for SSAE 16&#8242;s and SAS 70&#8242;s can vary greatly depending upon the company performing the work and the size of your organization, however, I wouldn&#8217;t expect to pay any less than $25,000-$30,000.
<ul>
<li>You should look for a fixed rate fee so there is no potential for them to raise rates on you as the project progresses.</li>
</ul>
</li>
</ul>
</li>
<li>Define the scope.
<ul>
<li>Once you have engaged a firm to perform the work, make sure you define the scope of the audit early on in the process. Not doing so could lead to excessive delays and potential cost overruns.</li>
</ul>
</li>
<li>Define your control objectives and activities.
<ul>
<li>In conjunction with your CPA firm, define the controls and test steps to be tested and make sure that they have been reviewed by process owners and any of the stakeholders at the CPA firm who may be reviewing and/or signing off on the report to ensure everyone is in agreeance. <span style="text-decoration: underline;">If this isn&#8217;t completed prior to testing, you are asking for a world of trouble.</span></li>
</ul>
</li>
<li>Perform a Readiness Assessment.
<ul>
<li>You can either choose to perform a readiness assessment on your own, based upon the test steps already defined, or, if you do not have the capacity or ability to do so internally, you can look towards either the firm performing your review or another firm who is skilled in preparing companies for audits.</li>
</ul>
</li>
</ul>
<p>These steps laid out here will set you on your way to getting your SSAE 16 started up and going and should help to guide you through the toughest parts of the process. Once you have completed all of the steps we have laid out, you should be able to rely on the knowledge of your CPA firm to take you through the finish line.</p>
<p>If you have any further questions please <a href="http://www.ssae-16.com/contact-form/">Contact Us</a>!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.ssae-16.com/ssae-16/ssae-16-preparation-checklist/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Why have an SSAE 16 Review Performed?</title>
		<link>http://www.ssae-16.com/ssae-16/why-have-an-ssae-16-review-performed/</link>
		<comments>http://www.ssae-16.com/ssae-16/why-have-an-ssae-16-review-performed/#comments</comments>
		<pubDate>Mon, 07 May 2012 05:21:34 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[SSAE 16]]></category>
		<category><![CDATA[SSAE 16 Type II]]></category>
		<category><![CDATA[is ssae 16 needed]]></category>
		<category><![CDATA[reports]]></category>
		<category><![CDATA[reviewing ssae 16]]></category>
		<category><![CDATA[ssae 16 audit review]]></category>
		<category><![CDATA[SSAE 16 Review]]></category>
		<category><![CDATA[ssae 16 review checklist]]></category>
		<category><![CDATA[ssae 16 reviews]]></category>
		<category><![CDATA[ssae review]]></category>
		<category><![CDATA[ssae reviews]]></category>
		<category><![CDATA[SSAE16]]></category>
		<category><![CDATA[ssae16 review]]></category>
		<category><![CDATA[standards]]></category>
		<category><![CDATA[third party ssae guidance review]]></category>
		<category><![CDATA[who is required to have a ssae 16]]></category>
		<category><![CDATA[who is required to have ssae 16]]></category>

		<guid isPermaLink="false">http://www.ssae-16.com/?p=53</guid>
		<description><![CDATA[Some organizations have heard of SAS 70 or SSAE 16, but, don&#8217;t really know WHY they need to pay to have a bunch of auditors trounce through their company for a month or two during the year, especially right after their financial audit just finished. The answer is simple: Many companies will not even think [...]]]></description>
			<content:encoded><![CDATA[<p>Some organizations have heard of SAS 70 or <a href="http://www.ssae-16.com/">SSAE 16</a>, but, don&#8217;t really know WHY they need to pay to have a bunch of auditors trounce through their company for a month or two during the year, especially right after their financial audit just finished.<br />
The answer is simple: Many companies will not even think about using your company to perform services for them without a clean Type II Report in place.<br />
<strong>Some benefits of having an SSAE 16 performed</strong>:</p>
<ul>
<li>Ability to perform outsourcing services for Public Companies.
<ul>
<li>If performing financially significant duties for a Public Company, they are required to use a SSAE 16 qualified provider as it is the only way to give investors assurance over controls that are not performed by the Company in question.</li>
</ul>
</li>
<li>Public and Private companies are more likely to trust your organization with their data.
<ul>
<li>If you were to trust a company with your data, you would want complete assurance it will be handled with the utmost care</li>
</ul>
</li>
<li>A year round accessible knowledge source (your auditors).
<ul>
<li>As a service organization, large or small, you will always have questions regarding your business and having a set of auditors in place with access to a wide array of business knowledge, it will allow you to bounce your questions and concerns off of a group of trusted individuals.</li>
</ul>
</li>
<li>A third party to review your controls and activities to ensure they are functioning appropriately, and give advice on how to improve upon them.
<ul>
<li>Sometimes your internal audit department is good, but, not always as stringent as they should be. This will help to serve as a check on their work, as well as your staff. Additionally, if there were any findings noted, your auditors are in a great position to give you some tricks and tips to improve to ensure everything functions well the following period.</li>
</ul>
</li>
<li>Improving performance of the organization.
<ul>
<li>Just the knowledge that a review is being performed of an employee&#8217;s work that can have far reaching consequences for the company as a whole. No more, &#8220;Oh, I didn&#8217;t realize that reviewing user access was THAT important to do this month, sorry&#8221;, now, everyone knows that if it&#8217;s not done, the success or failure of the organization could rest upon them.</li>
</ul>
</li>
</ul>
<p>Think of the SSAE 16 as an annual investment into your company, increasing potential <strong><em>new clients</em>, <em>productivity</em> and <em>accountability</em>.</strong></p>
]]></content:encoded>
			<wfw:commentRss>http://www.ssae-16.com/ssae-16/why-have-an-ssae-16-review-performed/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SSAE 16 Terminology &#8211; Carve-out Method</title>
		<link>http://www.ssae-16.com/ssae-16/ssae-16-terminology-carve-out-method/</link>
		<comments>http://www.ssae-16.com/ssae-16/ssae-16-terminology-carve-out-method/#comments</comments>
		<pubDate>Fri, 04 May 2012 05:21:33 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[SSAE 16]]></category>
		<category><![CDATA[SSAE 16 Terminology]]></category>
		<category><![CDATA[carve out method sas 70]]></category>
		<category><![CDATA[carve out methode]]></category>
		<category><![CDATA[carve out methodology]]></category>
		<category><![CDATA[carve out process]]></category>
		<category><![CDATA[Carve-out Method]]></category>
		<category><![CDATA[sas 70 carve out method]]></category>
		<category><![CDATA[ssae 16 carve out]]></category>
		<category><![CDATA[ssae 16 carve-out method]]></category>
		<category><![CDATA[ssae 16 terms]]></category>
		<category><![CDATA[ssae carve out method]]></category>
		<category><![CDATA[ssae16 carve out]]></category>
		<category><![CDATA[ssae16 carve out method]]></category>
		<category><![CDATA[Subservice Organization]]></category>
		<category><![CDATA[what is carve out method]]></category>

		<guid isPermaLink="false">http://www.ssae-16.com/?p=30</guid>
		<description><![CDATA[When performing a SSAE 16 Review, you will be inundated with various terms that you may have never heard of before. We plan on continuing with a serious of posts dedicated to explaining the various terminology that you should be aware of to ensure when the auditors are explaining things to you, you don&#8217;t lost [...]]]></description>
			<content:encoded><![CDATA[<p>When performing a <a href="http://www.ssae-16.com/">SSAE 16</a> Review, you will be inundated with various terms that you may have never heard of before. We plan on continuing with a serious of posts dedicated to explaining the various terminology that you should be aware of to ensure when the auditors are explaining things to you, you don&#8217;t lost in the jargon.</p>
<p>Today we will discuss the <strong>Carve-out Method</strong>.<br />
<br/>When management is in the process of writing their description of their system (&#8216;management&#8217;s description of the service organization&#8217;s system&#8217;), there are various ways to address controls or functions relevant to the processes that are outsourced to another organization (&#8216;subservice organization&#8217;). Using the <a href="http://www.ssae-16.com/ssae-16/ssae-16-terminology-carve-out-method/">carve-out method</a>, you would exclude the subservice organization&#8217;s relevant control objectives and related controls from management&#8217;s description and scope of the service auditor&#8217;s engagement.<br />
<br/>Now, this doesn&#8217;t mean you don&#8217;t need to address the controls that take place at a subservice organization, what it means is that you will need to have controls in place to monitor the effectiveness of the controls at the subservice organization. The most typical way to address this would be to obtain an SSAE 16 from the subservice organization, assuming the relevant controls were covered within their report. </p>
]]></content:encoded>
			<wfw:commentRss>http://www.ssae-16.com/ssae-16/ssae-16-terminology-carve-out-method/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SSAE 16 Type I Report Background Information</title>
		<link>http://www.ssae-16.com/ssae/ssae-16-type-i-report-background-information/</link>
		<comments>http://www.ssae-16.com/ssae/ssae-16-type-i-report-background-information/#comments</comments>
		<pubDate>Tue, 01 May 2012 05:20:42 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[SSAE]]></category>
		<category><![CDATA[SSAE 16 Type I]]></category>
		<category><![CDATA[Type I Report]]></category>
		<category><![CDATA[in an ssae 16 report where are the findings listed?]]></category>
		<category><![CDATA[sample ssae 16]]></category>
		<category><![CDATA[sample ssae 16 report]]></category>
		<category><![CDATA[SSAE 16]]></category>
		<category><![CDATA[ssae 16 report]]></category>
		<category><![CDATA[ssae 16 report example]]></category>
		<category><![CDATA[ssae 16 reports]]></category>
		<category><![CDATA[ssae 16 sample report]]></category>
		<category><![CDATA[ssae 16 sample reports]]></category>
		<category><![CDATA[ssae 16 type]]></category>
		<category><![CDATA[ssae 16 type 1]]></category>
		<category><![CDATA[ssae 16 type 1 report]]></category>
		<category><![CDATA[ssae 16 type i]]></category>
		<category><![CDATA[ssae16 sample report]]></category>
		<category><![CDATA[type 1 report]]></category>

		<guid isPermaLink="false">http://www.ssae-16.com/?p=18</guid>
		<description><![CDATA[There are significant differences between a Type I and Type II report, however, we aren&#8217;t going to discuss that here, thats for another day. We will discuss the basics of a SSAE 16 Type I Report and some areas that should be focused on if this is the direction your company wants to take. While [...]]]></description>
			<content:encoded><![CDATA[<p>There are significant differences between a Type I and Type II report, however, we aren&#8217;t going to discuss that here, thats for another day. We will discuss the basics of a <strong><a href="http://www.ssae-16.com/">SSAE 16</a> Type I Report</strong> and some areas that should be focused on if this is the direction your company wants to take.<br />
<br/>While the <a href="http://www.ssae-16.com/category/type-i-report/">Type I Report</a> doesn&#8217;t carry much weight, there are benefits, and that&#8217;s why it exists as an option. A <a href="http://www.ssae-16.com/category/type-i-report/">Type I Report</a> is specifically defined by the SSAE 16 guidance as a &#8220;report on a description of a service organization&#8217;s system and the suitability of the design of controls&#8221;, essentially, a determination of if your company&#8217;s controls designed appropriately. When performing a Type I report, the auditors will test the design effectiveness of your company&#8217;s defined controls by examining a sample of 1 item per control. This provides a user organization with some comfort that your company (the service organization) has at least some controls in place. This can be useful when trying to obtain a contract and to show good faith to the potential user organization that your company is moving in the right direction. Most user organizations will require a Type II Report before contracting your company as a service organization of theirs.<br />
<br/>The Type I Report is made up of 3 major areas, per the SSAE No. 16 Guidance:</p>
<blockquote><p>a description of the service organization&#8217;s system prepared by management of the service organization.</p></blockquote>
<p>- Management will need to prepare a description of the control objectives that are in place and being tested at their organization, as it relates to the process that is being reviewed for use by a User Organization. This will read sort of like a narrative of the process and how your control objectives tie in to each other and the process as a whole, giving a User Organization an overview of what and how, at a high level, their data will be handled.<br />
<br/>a written assertion by the Service Organization&#8217;s management about whether, in all material respects, and based on suitable <a href="http://www.ssae-16.com/terminology/criteria/">criteria</a>: </p>
<blockquote><p>1. the description of the service organization&#8217;s system fairly presents the service organization&#8217;s system that was designed and implemented as of a specified date.<br />
2. the controls related to the control objectives stated in the description were suitably designed to achieve those control objectives as of the specified date. </p></blockquote>
<p>- Management will need to prepare a written assertion attesting to the fair presentation and design of controls.  Previously under SAS 70, it was the auditors who reported directly on the controls and management was not required to attest to anything. (There will be a separate post describing this in detail as this is a major difference)</p>
<p><br/>The final component: </p>
<blockquote><p>a service auditor&#8217;s report that expresses an opinion on the matters in b1-2.</p></blockquote>
<p>- The auditors that are hired to perform the testing will need to review the Management&#8217;s assessment of the design of controls and attest to the validity of Management&#8217;s opinion. The auditors will walk through the control objectives and control activities in place at your company and verify they are, in fact, designed as Management noted. This is where the auditors will obtain a sample of 1 to support each control activity and express the results of their testing. </p>
<p><br/>Specifics of reporting details for a SSAE Type I will be discussed later on!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.ssae-16.com/ssae/ssae-16-type-i-report-background-information/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>SSAE 16, The New Standard</title>
		<link>http://www.ssae-16.com/ssae/ssae-16-the-new-standard/</link>
		<comments>http://www.ssae-16.com/ssae/ssae-16-the-new-standard/#comments</comments>
		<pubDate>Sat, 28 Apr 2012 05:17:02 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[SOC 1]]></category>
		<category><![CDATA[SSAE]]></category>
		<category><![CDATA[SSAE 16]]></category>
		<category><![CDATA[description of new ssae16]]></category>
		<category><![CDATA[effective date of ssae 16]]></category>
		<category><![CDATA[effective date ssae 16]]></category>
		<category><![CDATA[new ssae 16]]></category>
		<category><![CDATA[SAS70]]></category>
		<category><![CDATA[soc 1]]></category>
		<category><![CDATA[ssae 16 effective date]]></category>
		<category><![CDATA[ssae 16 implementation date]]></category>
		<category><![CDATA[ssae 16 standard]]></category>
		<category><![CDATA[ssae 16 type 2]]></category>
		<category><![CDATA[ssae 16 type ii]]></category>
		<category><![CDATA[ssae 16 type ii report]]></category>
		<category><![CDATA[SSAE No. 16]]></category>
		<category><![CDATA[ssae-16 type ii]]></category>
		<category><![CDATA[SSAE16]]></category>

		<guid isPermaLink="false">http://www.ssae-16.com/?p=4</guid>
		<description><![CDATA[So you have been performing a SAS 70 for the last couple years, or, are getting ready prepared to embark on your first SAS 70, and all of a sudden you hear that a brand new standard has been issued! Don&#8217;t worry about it! SSAE 16 is an improvement to the current standard for Reporting [...]]]></description>
			<content:encoded><![CDATA[<p>So you have been performing a SAS 70 for the last couple years, or, are getting ready prepared to embark on your first SAS 70, and all of a sudden you hear that a brand new standard has been issued!<br />
<br/>Don&#8217;t worry about it!<br/><br />
<strong>SSAE 16</strong> is an improvement to the current standard for Reporting on Controls at a Service Organization, the SAS70, with some changes that will help bring your company and the rest of the companies in the US up to date with new international service organization reporting standards, <a href="http://www.ssae-16.com/isae-3402/">ISAE 3402</a>.  This will help allow you and your counterparts in the US be able to compete on an international level, allowing for companies around the world to be able to use YOU as their service organization with complete comfort.<br/><br />
One very important issue that you should be very aware of is that <a href="http://www.ssae-16.com/">SSAE 16</a> will formally be issued in <strong><em>June 2010 with an effective date of June 15, 2011</em></strong>, meaning that if you are not on top of this new standard soon, you need to be. Many organizations have a 12 month testing period that begins in July, and if this sounds like your company, you will be required to be compliant with the New Standards as of July 1, 2010.<br/><br/></p>
<h2>Major differences between SAS 70 and the New Standard, SSAE 16 and ISAE 3042:</h2>
<p><br/>1)	Management of the Service Organization will be required to provide the service auditor with a written assertion about the following, when performing either a Type I or Type II engagement, which the service auditor will then attest to:</p>
<ul>
<li> The fairness of the presentation of the description of the service organization&#8217;s system;</li>
<li> The suitability of the design of the controls to achieve the related control objectives stated in the description; and</li>
<li> The operating effectiveness of those controls to achieve the related control objectives stated in the description (<em>Type II Only</em>)</li>
</ul>
<p>2)	During the process of understanding the service organization&#8217;s system, the Service Auditor would be required to obtain information that would identify risks that the description of the service organization&#8217;s system is not fairly presented or that the control objectives stated in the description were not achieved due to intentional actions by service organization personnel.<br/><br/></p>
<h2>Changes that Directly Impact Type II Engagements</h2>
<p><br/>1)	 The Service Auditor&#8217;s opinion on the fairness of the presentation of description of the service organization&#8217;s system and on the suitability of the design of the controls would be for a full period, as opposed to a specified date. (i.e. Your report would be for the 6 months covering July 2010 through December 2010.)</p>
<ul>
<li> The Type II report would identify the customers to whom use of the report is restricted as &#8220;customers of the service organization&#8217;s system during some or all of the period covered by the service auditor&#8217;s report&#8221;</li>
</ul>
<p>2)	Evidence obtained in prior engagements related to the satisfactory operation of controls in prior periods will not be sufficient to reduce the amount of testing performed.<br />
<br/><br />
<H2>Expected Change Which Didn&#8217;t Occur:</h2>
<p><br/>While it was expected that SSAE 16 would build upon the previous SAS 70 standard of reporting only on financial reporting activities and allow a service organization to branch out in to other areas of their business, such as regulatory compliance and performance metrics, this was not included within the initial final version of the New Standard and there has been no guidance as to when it would be expected, if ever, to be. </p>
]]></content:encoded>
			<wfw:commentRss>http://www.ssae-16.com/ssae/ssae-16-the-new-standard/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>SSAE 16 Preparation Tips</title>
		<link>http://www.ssae-16.com/ssae-16/ssae-16-preparation-tips/</link>
		<comments>http://www.ssae-16.com/ssae-16/ssae-16-preparation-tips/#comments</comments>
		<pubDate>Wed, 25 Apr 2012 05:16:43 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[SOC 1]]></category>
		<category><![CDATA[SSAE 16]]></category>
		<category><![CDATA[SSAE 16 Preparation]]></category>
		<category><![CDATA[SSAE 16 Type II]]></category>
		<category><![CDATA[controls]]></category>
		<category><![CDATA[report writing]]></category>
		<category><![CDATA[ssae 16 report]]></category>
		<category><![CDATA[SSAE No. 16]]></category>

		<guid isPermaLink="false">http://www.ssae-16.com/?p=165</guid>
		<description><![CDATA[This tip is focused on designing controls that reflect the process being testing, if they don&#8217;t, a headache of massive proportions will be created once testing begins. What do you do to make sure you don&#8217;t screw this up? Have as many meetings as it takes to get it right. What you need to do [...]]]></description>
			<content:encoded><![CDATA[<p>This tip is focused on designing controls that reflect the process being testing, if they don&#8217;t, a headache of massive proportions will be created once testing begins.<br/><br />
What do you do to make sure you don&#8217;t screw this up? Have as many meetings as it takes to get it right.<br/><br />
What you need to do is sit down with the auditors, the department lead, the main employees responsible for performing the process, and anyone else whom could either play a role in testing or modifying the control in the future. Once that is done, Management should discuss what they determined the control to be and how it should operate, that is then reviewed by the auditors, and then the employees performing the tasks should be reconsulted to verify that the control still reflects their process accurately. <br/><br />
Many times people try to speed this process up and half-ass it, leaving many open items which upon testing could easily blow up into a huge problem. When the control isn&#8217;t 100% agreed upon prior to testing and a deviation is noted, it&#8217;s a tough call between failing the control and the ability to adjust it to accurately reflect the process. The problem is modifying a control after testing has begun is not proper and needs to be avoided at all costs. <br/><br />
Locking the controls locked down early on could save weeks in wrapping up your new <a href="http://www.ssae-16.com/">SSAE 16</a> Report.<br/><br />
We have seen issues like this cause delays in issuing of the report to the client and running additional fees, since adjusting controls isn&#8217;t free. Coming from the perspective of the auditor, we can let you know the pitfalls, consequences and how to best navigate the audit process. If you have any comments or questions please leave them below!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.ssae-16.com/ssae-16/ssae-16-preparation-tips/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Example SSAE 16 Controls &#8211; Firewall</title>
		<link>http://www.ssae-16.com/controls/example-ssae-16-controls-firewall/</link>
		<comments>http://www.ssae-16.com/controls/example-ssae-16-controls-firewall/#comments</comments>
		<pubDate>Sun, 22 Apr 2012 05:14:05 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[controls]]></category>
		<category><![CDATA[example of ssae 16 report]]></category>
		<category><![CDATA[example ssae 16 report]]></category>
		<category><![CDATA[firewall]]></category>
		<category><![CDATA[sample soc 2 report]]></category>
		<category><![CDATA[sample ssae 16 report]]></category>
		<category><![CDATA[sixteen control]]></category>
		<category><![CDATA[soc 3 example]]></category>
		<category><![CDATA[sop template ssae-16]]></category>
		<category><![CDATA[SSAE 16]]></category>
		<category><![CDATA[ssae 16 controls]]></category>
		<category><![CDATA[ssae 16 example]]></category>
		<category><![CDATA[ssae 16 examples]]></category>
		<category><![CDATA[ssae 16 report example]]></category>
		<category><![CDATA[ssae 16 sample controls]]></category>
		<category><![CDATA[ssae 16 sample report]]></category>

		<guid isPermaLink="false">http://www.ssae-16.com/?p=155</guid>
		<description><![CDATA[Another series we will have periodic posts about will be related to potential controls that would be expected to be in place, almost regardless of the entity in question. This will be a real basic one to help get everyone up to speed, we will delve into other areas that may be a little more [...]]]></description>
			<content:encoded><![CDATA[<p>Another series we will have periodic posts about will be related to potential controls that would be expected to be in place, almost regardless of the entity in question. <br/><br />
This will be a real basic one to help get everyone up to speed, we will delve into other areas that may be a little more advanced in the future.<br/><br />
Example: <strong>Firewalls are in place at all externally facing access points.</strong><br/><br />
The point of this control is to ensure that firewalls are being used at the organization to help prevent hacking attempts, thus, the theft of data. Companies outsourcing their workloads want to have comfort that the company performing the work has adequate security measures in place to lower the chance of their data being stolen. <br/><br />
Firewalls are some of the most basic devices that need to be in place at a business to protect data and if your business does not currently employ firewalls on their network, it is a must do and should be looked into immediately. </p>
]]></content:encoded>
			<wfw:commentRss>http://www.ssae-16.com/controls/example-ssae-16-controls-firewall/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SSAE 16 Terminology &#8211; Criteria</title>
		<link>http://www.ssae-16.com/ssae-16-terminology/criteria/</link>
		<comments>http://www.ssae-16.com/ssae-16-terminology/criteria/#comments</comments>
		<pubDate>Fri, 13 Apr 2012 05:13:00 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[SOC 1]]></category>
		<category><![CDATA[SSAE 16 Terminology]]></category>
		<category><![CDATA[Criteria]]></category>
		<category><![CDATA[determine best practices criterion]]></category>
		<category><![CDATA[requirements for ssae 16]]></category>
		<category><![CDATA[sase 16 requirements]]></category>
		<category><![CDATA[soc 1]]></category>
		<category><![CDATA[SSAE 16]]></category>
		<category><![CDATA[ssae 16 criteria]]></category>
		<category><![CDATA[ssae 16 criteria manual]]></category>
		<category><![CDATA[ssae 16 definitions glossary]]></category>
		<category><![CDATA[ssae 16 guidance]]></category>
		<category><![CDATA[ssae 16 requirements]]></category>
		<category><![CDATA[SSAE No. 16]]></category>
		<category><![CDATA[ssae standards]]></category>
		<category><![CDATA[ssae16 availability criteria]]></category>
		<category><![CDATA[ssae16 criteria]]></category>

		<guid isPermaLink="false">http://www.ssae-16.com/?p=71</guid>
		<description><![CDATA[Criteria, as defined by the SSAE 16 guidance are: The standards or benchmarks used to measure and present the subject matter and against which the service auditor evaluates the subject matter. Criteria are the overreaching goals that the control objectives and activities that are in place are designed to meet and that the final report [...]]]></description>
			<content:encoded><![CDATA[<p><strong>Criteria</strong>, as defined by the <a href="http://www.ssae-16.com/">SSAE 16</a> guidance are:</p>
<blockquote><p>The standards or benchmarks used to measure and present the subject matter and against which the service auditor evaluates the subject matter.</p></blockquote>
<p></br><br />
<a href="http://www.ssae-16.com/terminology/criteria/">Criteria</a> are the overreaching goals that the control objectives and activities that are in place are designed to meet and that the final report is to give assurance on, for example, &#8220;The system is protected against unauthorized access (both physical and logical).&#8221; To meet this criteria, a company may decide to include controls such as &#8220;Firewalls are installed at all external entry points&#8221; or &#8220;A User Access Review of Access Badges is performed on a Monthly Basis&#8221;. Criteria are used as a benchmark to assess the design and operating effectiveness of internal controls at an organization, however, Management is responsible for making sure that the controls in place support the defined criteria sufficiently.<br />
<br/><br />
There are best practice criteria available for most industries that reflect prevailing internal controls best practices and requirements from around the world, some of these can be found on the <a href="http://www.aicpa.org">AICPA </a>website if you would like some additional examples.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.ssae-16.com/ssae-16-terminology/criteria/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>SOC 3 Report &#8211; WebTrust and SysTrust</title>
		<link>http://www.ssae-16.com/at-101/soc-3-report-webtrust-and-systrust/</link>
		<comments>http://www.ssae-16.com/at-101/soc-3-report-webtrust-and-systrust/#comments</comments>
		<pubDate>Tue, 10 Apr 2012 05:10:04 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[AT-101]]></category>
		<category><![CDATA[SOC 3]]></category>
		<category><![CDATA[are soc and systrust the same]]></category>
		<category><![CDATA[availability]]></category>
		<category><![CDATA[confidentiality]]></category>
		<category><![CDATA[processing integrity]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[soc 2 vs webtrust]]></category>
		<category><![CDATA[SOC 3 Report]]></category>
		<category><![CDATA[soc 3 reporting]]></category>
		<category><![CDATA[SOC3]]></category>
		<category><![CDATA[SOC3 report]]></category>
		<category><![CDATA[ssae 16 soc 3 report]]></category>
		<category><![CDATA[systrust]]></category>
		<category><![CDATA[systrust report]]></category>
		<category><![CDATA[webtrust]]></category>
		<category><![CDATA[webtrust vs systrust]]></category>

		<guid isPermaLink="false">http://www.ssae-16.com/?p=375</guid>
		<description><![CDATA[The SOC 3 Report , just like SOC 2, is based upon the Trust Service Principles and performed under AT101, the difference being that a SOC 3 Report can be freely distributed (general use) and only reports on if the entity has achieved the Trust Services criteria or not (no description of tests and results [...]]]></description>
			<content:encoded><![CDATA[<p>The<strong> <a href="http://www.ssae-16.com/soc-3">SOC 3</a> Report </strong>, just like <a href="http://www.ssae-16.com/soc-2">SOC 2</a>, is based upon the <a href="http://www.ssae-16.com/soc-2">Trust Service Principles</a> and performed under AT101, the difference being that a SOC 3 Report can be freely distributed (general use) and only reports on if the entity has achieved the Trust Services <a href="http://www.ssae-16.com/terminology/criteria/">criteria</a> or not (no description of tests and results or opinion on description of the system). The lack of a detailed report requires that a SOC 3 be performed as a Type II, unlike <a href="http://www.ssae-16.com/soc-1">SOC 1</a> and SOC 2 where there is a Type I option. SOC 3 reports can be issued on one or multiple Trust Services principles (security, availability, processing integrity, confidentiality and privacy) and allow the organization to place a seal on their website upon successful completion. </p>
<p>The <strong>Trust Service Principles</strong> were designed with a focus on e-commerce systems due to the amount of private/confidential/financial information that flows across the internet daily. When a customer processes a transaction (online retailer), builds a business on your service (SaaS providers), or submits private information, they want to know best practices are being followed by the company to guard against security leaks, lost sales, and damaged data. The most common reports based upon the trust principles are referred to as <strong><a href="http://www.ssae-16.com/soc-3">WebTrust</a> and SysTrust</strong>. </p>
<p>The <strong><a href="http://www.ssae-16.com/soc-3">SysTrust</a> </strong>review encompasses a combination of the following principles:</p>
<ul>
<li><strong>Security</strong>: The system is protected against unauthorized access (both physical and logical).</li>
<li><strong>Availability</strong>: The system is available for operation and use as committed or agreed.</li>
<li><strong>Processing Integrity</strong>: System processing is complete, accurate, timely, and authorized.</li>
<li><strong>Confidentiality</strong>: Information designated as confidential is protected as committed or agreed.</li>
</ul>
<p>The <strong>WebTrust </strong>certification can fall into the following four categories:</p>
<ul>
<li>
<strong>WebTrust</strong>. The scope of the engagement includes any combination of the trust principles and criteria .</li>
<li><strong>WebTrust Online Privacy</strong>. The scope of the engagement is based upon the online privacy principle and criteria.</li>
<li>
<strong>WebTrust Consumer Protection</strong>. The scope of the engagement is based upon the processing integrity and relevant online privacy principles and criteria.</li>
<li>
<strong>WebTrust for Certification Authorities</strong>. The scope of the engagement is based upon specific principles and related criteria unique to certification authorities.</li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.ssae-16.com/at-101/soc-3-report-webtrust-and-systrust/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SOC 2 Report &#8211; Trust Services Principles</title>
		<link>http://www.ssae-16.com/at-101/soc-2-report-trust-services-principles/</link>
		<comments>http://www.ssae-16.com/at-101/soc-2-report-trust-services-principles/#comments</comments>
		<pubDate>Sat, 07 Apr 2012 05:09:48 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[AT-101]]></category>
		<category><![CDATA[SOC 2]]></category>
		<category><![CDATA[at101]]></category>
		<category><![CDATA[soc 2]]></category>
		<category><![CDATA[soc 2 controls]]></category>
		<category><![CDATA[soc 2 principles]]></category>
		<category><![CDATA[soc 2 report]]></category>
		<category><![CDATA[soc 2 report user]]></category>
		<category><![CDATA[soc 2 reports]]></category>
		<category><![CDATA[soc 2 trust principles]]></category>
		<category><![CDATA[soc2]]></category>
		<category><![CDATA[ssae 16 five principles]]></category>
		<category><![CDATA[ssae 16 soc 2]]></category>
		<category><![CDATA[ssae 16 soc 3]]></category>
		<category><![CDATA[ssae 16 soc2]]></category>
		<category><![CDATA[SSAE16]]></category>
		<category><![CDATA[trust service principles]]></category>
		<category><![CDATA[what is a soc 2 report]]></category>

		<guid isPermaLink="false">http://www.ssae-16.com/?p=350</guid>
		<description><![CDATA[The Service Organization Control (SOC) 2 Report will be performed in accordance with AT 101 and based upon the Trust Services Principles, with the ability to test and report on the design (Type I) and operating (Type II) effectiveness of a service organization&#8217;s controls (just like SOC 1 / SSAE 16). The SOC 2 report [...]]]></description>
			<content:encoded><![CDATA[<p>The Service Organization Control <strong>(SOC) 2</strong> Report will be performed in accordance with AT 101 and based upon the Trust Services Principles, with the ability to test and report on the design (Type I) and operating (Type II) effectiveness of a service organization&#8217;s controls (just like <a href="http://www.ssae-16.com/soc-1">SOC 1</a> / <a href="http://www.ssae-16.com/">SSAE 16</a>). The <a href="http://www.ssae-16.com/soc-2">SOC 2</a> report focuses on a business&#8217;s non-financial reporting controls as they relate to security, availability, processing integrity, confidentiality, and privacy of a system, as opposed to SOC 1/SSAE 16 which is focused on the financial reporting controls. <img src="http://www.ssae-16.com/wp-content/uploads/2011/09/SOC_2_Trust_Service_Principles_4.jpg" alt="SOC2-Security: The system is protected, both logically and physically, against unauthorized access.Availability: The system is available for operation and use as committed or agreed to.Processing Integrity:  System processing is complete, accurate, timely, and authorized.Confidentiality:  Information that is designated confidential is protected as committed or agreed.Privacy: Personal information is collected, used, retained, and disclosed in conformity with the commitments in the entity’s privacy notice  and with the privacy principles put forth by the American Institute of Certified Public Accountants (AICPA) and the Canadian Institute of Chartered Accountants (CICA)." title="SOC_2_Trust_Service_Principles" width="300" height="350" class="alignright size-full wp-image-351" /></p>
<p>The <a href="http://www.ssae-16.com/soc-2">Trust Service Principles</a> which <strong>SOC 2</strong> is based upon are modeled around four broad areas: Policies, Communications, Procedures, and Monitoring. Each of the principles have defined <a href="http://www.ssae-16.com/terminology/criteria/">criteria</a> (controls) which must be met to demonstrate adherence to the principles and produce an unqualified opinion (no significant exceptions found during your audit). The great thing about the trust principles is that the criteria businesses must meet are predefined, making it easier for business owners to know what compliance needs are required and for users of the report to read and assess the adequacy. </p>
<p>Many entities outsource tasks or entire functions to service organizations that operate, collect, process, transmit, store, organize, maintain and dispose of information for user entities. SOC 2 was put in place to address demands in the marketplace for assurance over non-financial controls to prevent SOC 1 from being misused just like SAS 70 was. </p>
<p>Did you know? A business isn&#8217;t required to address all the principles, the reviews can be limited only to the principles that are relevant to the outsourced service being performed. Some example industries that might have a need for a SOC 2 include: SaaS Providers, <a href="http://www.ssae-16.com/find-a-us-ssae-16-data-center/">Data Center</a>/ Colocations, Document Production, and Data Analytics providers.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.ssae-16.com/at-101/soc-2-report-trust-services-principles/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

