こんにちは、丸山満彦です。いろいろと業務が立て込んでおり、ブログの更新が滞っていますが、気まぐれ日記ということで。。。
夏井先生のブログの記事
・2010.08.13 現在存在しているリスク評価基準は,パブリッククラウドのリスク評価には使えない
で参照しているPROCESSORの記事
・2010.08.13 The Risks Of The Cloud (CloudAudit & AICPA Independently Tackle Cloud Security Controls)
に次のように記載されています。
=====
“A lot of people over time have misused SAS 70 for reasons never intended,” says Amy Pawlicki, the AICPA’s director of business reporting assurance and advisory services. “Third-party service providers are trying to say that current and prospective customers can trust that they have the controls in place for security, availability, privacy, confidentiality, and processing integrity. The standard covering that is AICPA Attestation 101. AT 101 isn’t restricted to financial controls [as SAS 70 is]. It covers controls regarding security, availability, privacy, confidentiality, and processing integrity. Third-party providers have tried to use SAS 70 instead of AT 101.”
=====
Recent Comments