Gartner Says SAS 70 Is Not Proof of Security, Continuity or Privacy Compliance - Insurance News | InsuranceNewsNet

InsuranceNewsNet — Your Industry. One Source.™

Sign in
  • Subscribe
  • About
  • Advertise
  • Contact
Home Now reading Newswires
Topics
    • Advisor News
    • Annuity Index
    • Annuity News
    • Companies
    • Earnings
    • Fiduciary
    • From the Field: Expert Insights
    • Health/Employee Benefits
    • Insurance & Financial Fraud
    • INN Magazine
    • Insiders Only
    • Life Insurance News
    • Newswires
    • Property and Casualty
    • Regulation News
    • Sponsored Articles
    • Washington Wire
    • Videos
    • ———
    • About
    • Meet our Editorial Staff
    • Advertise
    • Contact
    • Newsletters
  • Exclusives
  • NewsWires
  • Magazine
  • Newsletters
Sign in or register to be an INNsider.
  • AdvisorNews
  • Annuity News
  • Companies
  • Earnings
  • Fiduciary
  • Health/Employee Benefits
  • Insurance & Financial Fraud
  • INN Exclusives
  • INN Magazine
  • Insurtech
  • Life Insurance News
  • Newswires
  • Property and Casualty
  • Regulation News
  • Sponsored Articles
  • Video
  • Washington Wire
  • Life Insurance
  • Annuities
  • Advisor
  • Health/Benefits
  • Property & Casualty
  • Insurtech
  • About
  • Advertise
  • Contact
  • Editorial Staff

Get Social

  • Facebook
  • X
  • LinkedIn
Newswires
Newswires RSS Get our newsletter
Order Prints
July 21, 2010 Newswires
Share
Share
Post
Email

Gartner Says SAS 70 Is Not Proof of Security, Continuity or Privacy Compliance

By 2012, No Customers of Cloud Providers Will Accept SAS 70 Alone as Proof of Effective Security and Compliance

STAMFORD, Conn. - Statement on Auditing Standards (SAS) 70 is being misused by many vendors, and often their customers and certified public accountants (CPAs), in the hosted-application, software as a service (SaaS) and cloud computing spaces, according to Gartner, Inc.

Gartner analysts said SAS 70 is too often treated by vendors and their customers as a certification "proving" security and compliance with privacy or other regulations that require enterprises to monitor their exposure to vendor risks.

"SAS 70 is basically an expensive auditing process to support compliance with financial reporting rules like the Sarbanes-Oxley Act (SOX)" said French Caldwell, research vice president at Gartner. "Chief information security officers (CISOs), compliance and risk managers, vendor managers, procurement professionals, and others involved in the purchase or sale of IT services and software need to recognize that SAS 70 is not a security, continuity or privacy compliance standard"

Published by the American Institute of Certified Public Accountants (AICPA), SAS 70 provides a service provider's auditor with guidance on how it should report on process-related risks relevant to financial statements and transaction processing. Intended for use by the customer's auditor, the result of a SAS 70 is either a Type I attestation that the processes as documented are sufficient to meet specific control objectives, or a Type II attestation, which additionally includes an on-site evaluation to determine whether the processes and controls actually function as anticipated.

"Many providers of traditional application hosting, SaaS and cloud computing are currently treating SAS 70 as if it were a form of certification, which it is not" said Jay Heiser, research vice president at Gartner. "Furthermore, some claim that SAS 70 addresses security, privacy and continuity, which is misleading. Instead, it is only a generic guideline for the preparation, procedure and format of an auditing report. SAS 70 always places the onus on the service recipient, or more precisely, on the recipient's auditor, to ensure that all controls relevant to the recipient's requirements are examined"

In its intended context of financial reporting and transaction services, buyers' auditors could reasonably be expected to know what controls are needed to meet buyers' contractual requirements, and to identify gaps, but this is not the case with alternative computing delivery models. Gartner does not consider the auditing profession as being the most appropriate provider for all forms of IT risk assessment.

"Given that SAS 70 cannot be considered as proof that an offered IT service is secure, it should be a matter of suspicion when a vendor insists that it is" Mr. Heiser said. "Vendor claims to be 'SAS 70 certified' indicate either ignorance or deception, neither of which is a good basis for trust. The only thing that can conclusively be said about having a SAS 70 Type II attestation is that an auditing firm has agreed that the service provider is effectively performing those controls that they paid the auditing firm to evaluate"

Nevertheless, Gartner analysts said a SAS 70 Type II evaluation does provide a very high degree of assurance that the examined controls are effective. The performance of controls is evaluated over a period of time; it is not just a snapshot of control effectiveness. However, customers should never assume that the provider has implemented all the appropriate controls, and they must review the controls documentation at a minimum and, ideally, review the complete evaluation report.

SAS 70 is one of several mechanisms that can be used to evaluate a service provider's control environment. Gartner recommends a mix of the following methods that can be used to supplement or serve as an alternative to SAS 70: background and reference checks; vendor self-assessment and attached evidence (evidence could include SAS 70, Payment Card Industry security assessments, self-testing, and records from other external audits and assessors); on-site audit or assessment by the enterprise's own security assessors or internal auditors and application of direct controls on the services provider, for example having vendor employees undertake the organization's ethics training and sign off on the code-of-conduct policy.

Enterprises may also want to evaluate alternative assessment standards for vendor security, compliance and risk management, such as International Organization for Standardization (ISO) standard certifications, BITS Shared Assessments (which are provided by a consortium of service providers, their customers, audit firms and other third-party assessors), SysTrust and WebTrust (which are formal security certifications that are sponsored by the AICPA and carried out by CPA-qualified auditors), and AT Section 101, which is a flexible attestation procedure sponsored by AICPA that can be used by any CPA-qualified auditor.

"Standards organizations are in the process of adapting their standards to better address the unique risk issues of cloud computing. Their efforts are iterative, and service providers, customers and auditors must ensure that the standards and assessment procedures that they adopt align with the specific cloud environment of the service provider" Mr. Caldwell said. "To ensure that vendor controls are effective for security, privacy compliance and vendor risk management, SAS 70, its successor Statement on Standards for Attestation Engagements (SSAE) 16, and other national audit standard equivalents should be supplemented with self-assessments and agreed-upon audit procedures"

Additional detail is available in the Gartner report "SAS 70 Is Not Proof of Security, Continuity or Privacy Compliance" The report is available on Gartner's website at http://www.gartner.com/resId=1390444

Advisor News

  • Demonstrating the value of life insurance to Gen Z
  • Poor money habits are a dealbreaker in a new relationship
  • DC plan sponsors see opportunity in alternatives
  • The American Dream: Redefined as financial stability
  • Partial annuitization: How advisors can help clients balance income, growth
More Advisor News

Annuity News

  • CA judge certifies class action in teachers’ lawsuit over in-plan annuity fees
  • Globe Life Inc. (NYSE: GL) Records 52-Week High Thursday Morning
  • AM Best Managing Director Joins ‘Target Topics’ Podcast to Discuss State of Delegated Underwriting Authority Enterprises Market
  • KBRA Assigns Rating to TruSpire Retirement Insurance Company
  • Partial annuitization: How advisors can help clients balance income, growth
More Annuity News

Health/Employee Benefits News

  • CEO: Medicaid work requirements will hurt Iowa healthcare
  • Copay assistance is meant to defray patient drug costs. Some insurers keep it instead
  • Amid claims of 'playing politics,' Auburn council amends city manager's contract
  • OCWNY to hold seminar for disability beneficiaries Friday
  • Atrium pushes back after State Health Plan leaves healthcare network out of Tier 1
More Health/Employee Benefits News

Life Insurance News

  • Globe Life Inc. (NYSE: GL) Records 52-Week High Thursday Morning
  • AM Best Upgrades Credit Ratings of Sagicor Financial Company Ltd. and Most of Its Subsidiaries
  • Trust, technology and the future of claims
  • New York Life Launches an Indemnity Benefit for its Asset Flex Long-Term Care Insurance Solution
  • AM Best Affirms Credit Ratings of DB Insurance Co., Ltd.
More Life Insurance News

NEWS INSIDE

  • Companies
  • Earnings
  • Economic News
  • INN Magazine
  • Insurtech News
  • Newswires Feed
  • Regulation News
  • Washington Wire
  • Videos

FEATURED OFFERS

Press Releases

  • Prosperity Life GroupSM Launches Prosperity PathWaySM Series, Bringing Greater Choice and Flexibility to Retirement Income Planning
  • Senior Market Sales® Fortifies Annuity Reach With Acquisition of Retirement Planning Firm Stratton & Company
  • RFP #T01625
  • Rockwood Programs Appoints Kerry Ladouceur as Vice President, Financial Lines
More Press Releases > Add Your Press Release >

How to Write For InsuranceNewsNet

Find out how you can submit content for publishing on our website.
View Guidelines

Topics

  • Advisor News
  • Annuity Index
  • Annuity News
  • Companies
  • Earnings
  • Fiduciary
  • From the Field: Expert Insights
  • Health/Employee Benefits
  • Insurance & Financial Fraud
  • INN Magazine
  • Insiders Only
  • Life Insurance News
  • Newswires
  • Property and Casualty
  • Regulation News
  • Sponsored Articles
  • Washington Wire
  • Videos
  • ———
  • About
  • Meet our Editorial Staff
  • Advertise
  • Contact
  • Newsletters

Top Sections

  • AdvisorNews
  • Annuity News
  • Health/Employee Benefits News
  • InsuranceNewsNet Magazine
  • Life Insurance News
  • Property and Casualty News
  • Washington Wire

Our Company

  • About
  • Advertise
  • Contact
  • Meet our Editorial Staff
  • Magazine Subscription
  • Write for INN

Sign up for our FREE e-Newsletter!

Get breaking news, exclusive stories, and money- making insights straight into your inbox.

select Newsletter Options
Facebook Linkedin Twitter
© 2026 InsuranceNewsNet.com, Inc. All rights reserved.
  • Terms & Conditions
  • Privacy Policy
  • InsuranceNewsNet Magazine

Sign in with your Insider Pro Account

Not registered? Become an Insider Pro.
Insurance News | InsuranceNewsNet