Entries Tagged as 'certification'
by Jay Heiser | June 3, 2013 | 1 Comment
Life in the cloud would be so much easier if there were only some sort of ‘cloud risk seal of approval’. Most public cloud services seem to offer a reasonable risk proposition, but its extremely difficult to provide defensible evidence of this. A comprehensive and well-accepted ‘standard’ would go a long way towards bridging this [...]
Category: Cloud security Tags: certification, Hype Cycle, standards
by Jay Heiser | July 14, 2010 | 1 Comment
Gartner analysts have claimed that SAS 70 is being misused by many vendors and their customers.
Category: Cloud IT Governance risk management security Tags: AICPA, certification, Cloud, SAS 70, SAS70, security
by Jay Heiser | July 5, 2010 | 4 Comments
SAS 70 is a) not a certification, b) not a standard, and c) isn’t meant to be applied the way it is being applied now. To be fair, all service providers are under huge customer pressure to provide SAS 70, but instead of explaining their security, continuity, and recovery capabilities in more appropriate terms, most [...]
Category: Cloud IT Governance risk management security Vendor Contracts Tags: AICPA, certification, SAS 70, SAS70, standards
by Jay Heiser | June 30, 2010 | 4 Comments
Ideally, there would be no sensitive data in email, or it would be encrypted. Email is an unsafe, and unreliable service, and it leaks like a sieve. It was never meant to be ‘secure’, and it is not. While careful administration and reliable technology can protect stored email from unauthorized access, hacking into PST files [...]
Category: Applications Cloud risk management security Vendor Contracts Tags: 25999, 27001, certification, email, SaaS, SAS70, security