ISO 17799
Home > Ask the Security Experts > Security Management Questions & Answers > How do ISO 17799 and SAS 70 differ?
Ask The Security Expert: Questions & Answers
EMAIL THIS

How do ISO 17799 and SAS 70 differ?

Mike Rothman EXPERT RESPONSE FROM: Mike Rothman

Pose a Question
Other Security Categories
Meet all Security Experts
Become an Expert for this site


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


>
QUESTION POSED ON: 03 December 2007
Our organization is bidding on a contract that requires a SAS 70 audit. As a young company, we can't provide this. Under what circumstances is it possible to submit an ISO 17799 in lieu of the SAS 70 audit? Are the two largely equivalent?

>
EXPERT RESPONSE
Actually, SAS 70 and ISO 17799 are very different, so it's unlikely that the contract you are pursuing would accept a 17799 program instead of SAS 70. From a simple definitions standpoint, SAS 70 is a process for auditors to determine if a corporation has the proper control objectives and activities in place. There really isn't a firm definition of SAS 70, since each individual company sits down with its auditors at the beginning of the process and figures out the most appropriate set of controls to implement.

ISO 27002, which has superseded ISO 17799, is a set of best practices to be adopted by organizations in order to implement proper information security. You can be certified against the 27002 standard, as specified in ISO 27001, which would indicate adherence to the best practices.

There is one scenario where ISO 27002 could be used in lieu of a SAS 70, but it's a minor distinction. You could sit down with your auditor at the beginning of the SAS 70 audit and agree that ISO 27002 provides a proper set of control objectives for what you are trying to achieve. To be clear, this would not eliminate the requirement to provide a SAS 70 audit; it would just use the ISO standard as a control objective. You'd still have to spend the money on the SAS 70 audit.

Which brings up another, more important question: can your organization fulfill this contract without the resources to provide the SAS 70 audit? Requiring this kind of infrastructure can sometimes be a boilerplate request, but in reality it provides a filter for smaller organizations that wouldn't be able to execute the contract successfully.

For more information:

  • Richard Mackey explains how ISO 27002 can help to comply with PCI DSS and provide more structure to an overall compliance program.
  • In this expert answer, Mike Rothman discusses whether ISO 17799 should be involved in the risk assessment process.


  • Sound Off! -   Be the first to post a message to Sound Off!


    Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


    RELATED CONTENT
    Security Management
    Is it against HIPAA regulations to permanently store sensitive information?
    Two-tier distributed systems vs. three-tier distributed systems
    How to prevent software piracy
    Has FFIEC made any VoIP-specific mandates?
    What is the best way to administer exams to students via computer?
    Should computer exams be transmitted as PDF files or Word files?
    Is it against HIPAA regulations to display client names?
    Getting started on a career in penetration testing
    Are there security management products that can track compliance objectives?
    What Web security initiatives can be taken on a college campus?

    ISO 17799
    How to apply ISO 27002 to PCI DSS compliance
    How to migrate from SAS 70 to ISO 27001
    Should ISO 17799 play a role in risk assessment?
    ISO 17799: A methodical approach to partner and service provider security management
    Embarking on the ISO 17799 certification trail
    How is ISO 17799 different from SAS 70?
    Mapping the path toward information security program maturity
    Developing an information security program using SABSA, ISO 17799
    Regulatory Compliance and ISO 27001
    Management Support

    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary



    Search and Browse the Expert Answer Center
    Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
    Browse our Expert Advice

    TechTarget Security Media
    Information Security View this month\\'s issue and subscribe today.
    Information Security Decisions Apply online for free conference admission.
    SearchSecurity.com
    HomeNewsMagazineWebcastsWhite PapersLearningAdviceTopicsEventsAbout Us

    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




    All Rights Reserved, Copyright 2003 - 2008, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts