|
That's an interesting question. These two are kind of like apples and oranges, since a Tier III data center is concerned with how the hosting provider deals with redundant cooling and power from an uptime and availability perspective, and SAS 70 (especially Type 2) assessments really evaluate the controls' effectiveness.
An SAS 70 data center will have undergone a process to assess its security controls against a set of controls mutually agreed upon by the auditor and the data center.
So the choice depends on whether availability or security is the key attribute in a hosting provider. Most organizations say both, and they are probably right. But if it has to be one or the other, a SAS 70 data center focuses on security controls, and a Tier III is concerned with ensuring availability.
More information:
|