Seguridad Mania.com - España y América Latina
Portal sobre tecnologías para la seguridad física
- Destacamos »
- software Anti Blanqueo
SAN FRANCISCO, CA -- (Marketwire) -- 02/25/13 -- The Cloud Security Alliance today released a position paper on the American Institute of CPA's reporting framework, as a means of educating its members and providing guidance on selecting the most appropriate reporting option. The position paper is the latest step in CSA's previously announced Open Certification Framework and STAR Attestation initiatives.
The AICPA's reporting framework, known as Service Organization Control Reports, consists of three major document types. The first -- the SOC 1(SM) report -- deals with controls over financial reporting. The SOC 2(SM) report focuses on controls that bear on a service provider's security, processing integrity and operating availability, as well as the confidentiality and privacy of data moving through its systems. A third report, SOC 3(SM), is a compressed version of the SOC 2(SM) and is designed for public distribution.
In the position paper, the CSA highlights that for most cloud providers, the combination of leveraging the criteria in the CSA Cloud Controls Matrix with a SOC 2(SM) report is likely to meet the assurance and reporting needs of the majority of users of cloud services. The paper offers guidance to members on when a SOC 1(SM) report is necessary, when a SOC 2(SM) report is called for, and when both engagement types may be required.
"Technology-related compliance and operating integrity audits are becoming increasingly important as businesses now routinely adopt cloud-based services," said Jim Reavis, executive director of the CSA. "The Cloud Controls Matrix is designed to be used in conjunction with existing standards, and this is one such example where the combination provides a comprehensive view that should suit most users reporting needs."
"We're delighted that the CSA recognizes our reporting framework as a mechanism to meet this critical reporting challenge, and complement the security principles in its Cloud Controls Matrix," said Susan Coffey, CPA, CGMA, senior vice president for public practice and global alliances at the AICPA.
Reavis continued, "The CSA Security Trust & Assurance Registry (STAR) serves as the standard for demonstrating transparent alignment with CSA security best practices, and this paper is a major step forward in leveraging AICPA's popular reporting framework to consolidate attestation requirements and layer third party trust on top of CSA STAR."
The full position paper can be found at https://cloudsecurityalliance.org/research/collaborate/#_aicpa
About the CSA
The Cloud Security Alliance (CSA) is a not-for-profit organization with a mission to promote the use of best practices for providing security assurance within Cloud Computing, and to provide education on the uses of Cloud Computing to help secure all other forms of computing. The Cloud Security Alliance is led by a broad coalition of industry practitioners, corporations, associations and other key stakeholders.
Add to Digg Bookmark with del.icio.us Add to Newsvine
Media Contact
Kari Walker
ZAG Communications for the CSA
Email Contact
Publicamos interesante Informe de más de 48 págs y varios videos demostrativos sobre los posibles ataques a los robots de montaje de las fábricas. ... Leer más ►
Publicado el 22-Jun-2017 • 10.48hs
Publicado el 20-Jun-2017 • 20.22hs
Dirigido tanto a los principiantes, como a los expertos en seguridad informática y sistemas de control industrial (ICS), este libro ayudará a los lectores a comprender mejor la protección de normas de control interno de las amenazas electrónicas. ... Leer más ►
Publicado el 3-Ene-2012 • 20.16hs
Publicado el 25-Set-2009 • 01.26hs
Publicado el 17-Dic-2008 • 08.32hs
Publicado el 11-Oct-2016 • 12.48hs
Publicado el 15-Mar-2016 • 11.59hs
Publicado el 2-Feb-2017 • 11.38hs
Publicado el 20-Jun-2014 • 17.17hs
Publicado el 31-May-2011 • 05.13hs
Publicado el 25-Set-2008 • 17.54hs
Publicado el 1-Set-2016 • 16.11hs
Publicado el 31-Ago-2016 • 18.53hs
Publicado el 19-Ene-2017 • 15.47hs
Publicado el 4-Jul-2016 • 18.51hs