<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: BS Filtering for CISOs: Vendors and Third Parties</title>
	<atom:link href="http://daveshackleford.com/?feed=rss2&#038;p=192" rel="self" type="application/rss+xml" />
	<link>http://daveshackleford.com/?p=192</link>
	<description>Musings on Security &#38; Other Stuff</description>
	<lastBuildDate>Wed, 08 Sep 2010 10:33:27 -0700</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: admin</title>
		<link>http://daveshackleford.com/?p=192&#038;cpage=1#comment-133</link>
		<dc:creator>admin</dc:creator>
		<pubDate>Tue, 09 Jun 2009 02:23:21 +0000</pubDate>
		<guid isPermaLink="false">http://daveshackleford.com/?p=192#comment-133</guid>
		<description>Good points, Mr. D.</description>
		<content:encoded><![CDATA[<p>Good points, Mr. D.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: James DeLuccia IV</title>
		<link>http://daveshackleford.com/?p=192&#038;cpage=1#comment-131</link>
		<dc:creator>James DeLuccia IV</dc:creator>
		<pubDate>Sun, 07 Jun 2009 22:59:35 +0000</pubDate>
		<guid isPermaLink="false">http://daveshackleford.com/?p=192#comment-131</guid>
		<description>Dave,

Great points - though I would embellish the first two bullets a bit to avoid being tricked by their IT Staff through &quot;shock and awe&quot;.  
-  SAS 70 are based on management determined controls, so to depend on them YOU must verify the controls being audited (i.e., don&#039;t accept the Executive Cover Letter, but require review of the actual control tests).  Second to make a SAS 70 Type II useful - verify the scope of the audit includes your concerns.  (this leads me to bullet #2).

- Audit results are great - beware of SCOPE.  Most organizations will try to secure data carefully, but when 3rd party validations occur they are restricted to specific types of control checks that are designed to prevent specific types of risks.  Unless your data falls under those &quot;specifics&quot; you need to look beyond the standards advertised.

Other thoughts?

James DeLuccia IV</description>
		<content:encoded><![CDATA[<p>Dave,</p>
<p>Great points &#8211; though I would embellish the first two bullets a bit to avoid being tricked by their IT Staff through &#8220;shock and awe&#8221;.<br />
-  SAS 70 are based on management determined controls, so to depend on them YOU must verify the controls being audited (i.e., don&#8217;t accept the Executive Cover Letter, but require review of the actual control tests).  Second to make a SAS 70 Type II useful &#8211; verify the scope of the audit includes your concerns.  (this leads me to bullet #2).</p>
<p>- Audit results are great &#8211; beware of SCOPE.  Most organizations will try to secure data carefully, but when 3rd party validations occur they are restricted to specific types of control checks that are designed to prevent specific types of risks.  Unless your data falls under those &#8220;specifics&#8221; you need to look beyond the standards advertised.</p>
<p>Other thoughts?</p>
<p>James DeLuccia IV</p>
]]></content:encoded>
	</item>
</channel>
</rss>
