SAS 70 - One Size Wasn’t Supposed to Fit All
10 slides · 4 min read · Domain 6
SAS 70: One Size
Wasn't Supposed
to Fit All
We'll conclude Security Assessment Standards and Frameworks by shifting to SAS 70, in which one size isn't supposed to fit all.
Historically, many organizations that use outsourced services have asked for SAS 70 reports.
Few organizations understood or acknowledged that the SAS 70 report was designed for a specific purpose: to help users and their auditors to rely upon the controls over a service provider in the context of the users' Financial statement and ICFR audits.
Many of these users were concerned about areas such as security, availability, and privacy with little or no regard for financial reporting implications.
Despite the existence of other IT/ security-focused assurance tools (e.g., WebTrust, SysTrust, ISO 27001, etc.) that were arguably better suited for the purpose, users continued to ask for SAS 70 reports and service providers and their auditors accommodated With the replacement of the SAS 70 report with SOC reports, the professional guidance is now clear.
The AICPA has also provided messaging to clearly explain the different types of SOC reports and where they are applicable. In most cases, service providers that provide core Financial processing services (e.g., payroll, transaction processing, asset management, etc.) moved to the SOC 1 report in 2011. IT service providers that have no impact or an indirect impact on users' Financial reporting systems have started to move to the SOC 2 report.
The SOC 3 report has been used where there is a need to communicate a level of assurance to a broad base of users without having to disclose detailed controls and test results. Some organizations may complete a combined SOC 2/SOC 3 examination with two reports geared for different constituencies. The SOC for Cybersecurity report goes several steps further in this regard.
International Adoption of SSAE
For many reasons, the United States has been leading the international business and regulatory communities in establishing and using strong compliance assurance audit or examination processes. This led to the U.S.-based standard SAS 70 being used extensively outside of the United States.
As a result, the International Auditing and Assurance Standards Board (IAASB) saw fit to develop the International Standard on Assurance Engagements 3402 (ISAE 3402) as a global standard. The AICPA then updated the SAS 70 with a new Statement on Standards for Attestation Engagements No. 16 (SSAE 16), and again updated it with SSAE 18, both of which included a number of features and ideas based on those in ISAE 3402.
The two types of reports that can be issued for ISAE 3402/SSAE 16 are Type 1 and 2.
- A Type 1 report covers a point in time and does not address operating effectiveness of controls. Typically, a service organization undertakes a Type 1 examination in the first year as they may lack documentation supporting a Type 2
examination.
- A Type 2 report will interrogate the effectiveness of the controls by means of testing for a period of time (generally not less than six months but not more than 12).
- ISAE 3402, SSAE 16 and SSAE 18 have strong similarities in overall structure of their reports:
- Section one: Service auditor's independent report, also known as the "opinion"
- Section two: Written attestation or assertion of the control by the service organization
- Section three: Description of internal controls and control objectives by service organization
- Section four: Service auditor's information that includes test of operating effectiveness
- Section five: Additional information included that the service organization needs to supply
Industry and regionspecific standards
There are a great number of potential standards applicable to different industries or organizations, and many organizations will find themselves subject to multiple compliance frameworks. Some of these standards are listed in the table.
Standard
PCI-DSS
IEC 62443
Organization
PCI Security Standards Council
ISO/IEC
Focus
Payment card industry
Industrial controls
Cyber Essentials
CIP
National Cyber Security Centre
NERC
organizations
U.S. critical infrastructure
Text on this slide
UL 2900
STAR
ISAE 3000
Customer Security Controls Framework
Underwriters Laboratories
CSA
Electrical devices
Cloud service providers
International Auditing and Assurance Standards Board
SWIFT Network audit standard
International Financial transactions
Industry and region-specific standards
Text on this slide
Customer Security Controls Framework
SWIFT Network
International Financial transactions
Industry and region-specific standards
