SAS 70 Solutions Session at Cloud Expo
Dear Cloud:
Hello! Can you hear me? I know you can. Yes, yes...no one likes an auditor
and I am even worse. I am that CPA who spent the last decade working in
information security, both as a security consultant and as someone who
managed the product lines of a global managed services business. So whether
or not you want to open up those big APIs of yours and listen to me, this is
what I have to say...
I know who you are and where you live.
Your name is "the cloud." I will admit that you are the catchiest IT buzzword
since Java. Although you claim to live in the gated community called Web 2.0,
I know better. You actually live in an unmarked windowless datacenter, with
complex networks, servers, applications, policies, contracts, and worst of
all, people!
You are unique, just like everyone else.
Your predecessors, such as the A... (more)
Another day and another set of Google Alerts on SAS 70. Most links are press
releases saying that a cloud computing provider has been SAS 70 certified,
SAS 70 secured or some other mischaracterization of what SAS 70 was actually
intended to do. Other links are blog posts blasting these same marketers (and
indirectly the CPAs) about how a SAS 70 is insufficient and not prescriptive
enough to "secure the cloud."
For several years, I ran the product lines for one of the largest managed
security service providers in the world. I was always being asked about
security controls, whethe... (more)