SlideShare a Scribd company logo
1 of 2
Is your SaaS system in line with SOX
         compliance requirements?
Adoption rates for Software as a Service (SaaS) have grown exponentially in the past few years,
and with reason. A SaaS vendor can help companies implement software more quickly and less
expensively than IT systems that require local installs. Many SaaS products also allow universal
access and real-time updates. The benefits of SaaS systems are numerous, but one overarching
concern has hampered the potential for universal SaaS adoption: data security. Many businesses
are uncomfortable with trusting their internal data to an external location and relying on a
SaaS vendor’s infrastructure to keep information safe from corruption and theft. In addition,
there are legal implications involved with storing company data off-site. Sarbanes-Oxley
Act (SOX) compliance requirements stipulate that a company is fully responsible for its own
data, regardless of whether the data is stored on-site or entrusted to an outside vendor.

So how do you maximize the benefits of SaaS while minimizing the risk of data issues or legal
trouble?

SaaS and data security

There is a major misconception related to SaaS -- that it’s more vulnerable than internally stored
data systems. While it’s true that SaaS data can be compromised, it’s more accurate to view SaaS
security threats as “different” rather than “more extensive.”

In fact, in-house storage systems may be less secure than your average SaaS software. Whereas
the SaaS vendor’s business model is built on data storage and security, these considerations are
incidental for many other businesses. Also, consider the fact that in-house solutions require
constant upkeep and maintenance, which the average IT personnel might have difficulty
completing. Good SaaS vendors can eliminate this problem by offering regular updates and
knowledgeable maintenance in the event of a malfunction.

SOX compliance requirements are the concern for most publicly traded companies, particularly
when it comes to financial data storage. The reason for this is very simple: A company’s signing
officers are responsible for fair and complete financial statements to remain SOX compliant. If
there is a discrepancy between reported and actual data, they could face severe punishments, up
to and including jail time.

Obviously, if such a company is considering external data storage that has any relation
whatsoever to financial information, it’s going to require assurance that the data is secure.
Fortunately, there are ways to check for that security and determine the trustworthiness of
potential SaaS vendors.
SAS 70: A cure for the common corruption

If a company uses a SaaS vendor, that vendor should be required to submit a SAS 70 audit
report. The SAS 70 report demonstrates the accuracy and completeness of a vendor’s internal
controls. Further, it can obviate a company’s physical audit of said vendor, saving time and
money.

There are two types of SAS 70 audits: Type I and Type II. The Type I audit determines the
adequacy of a SaaS vendor’s internal controls, and whether or not they have been fairly and
completely described. Type II audits look at the same controls but take it further by testing them.
A Type II audit is much sounder and may even be required by a company’s own auditors. But
many vendors begin with a Type I audit and then undergo a Type II audit should the need arise.
A company should examine the sensitivity of data being stored with a SaaS vendor, and then
determine what type of audit is preferable. If it makes more sense, the company can conduct a
Type II audit later.

A SAS 70 report is an excellent method of evaluation, but it isn’t a substitute for a solid contract
between a company and a SaaS vendor. In addition to making sure that auditors accept the
report, a company must determine that the report has been read and understood.

When it comes time to solidify a business relationship, a company might want to consider some
of the following stipulations in the SaaS contract:

       Advanced warning of system notifications, along with set time requirements and who
       must be notified.
       Uptime percentage guarantees.
       Notification of outages, including a resolution plan and timetable.
       List of backup procedures.
       Tech support policies and procedures.
       Physical security procedures.
       Device and media controls.
       Use of system monitoring tools.

Take these security measures into account, and SaaS should not pose a more significant threat
than on-site data storage. If you have the opportunity to introduce SaaS systems into your
organization, it is certainly worth the examination to determine the extent to which it can
streamline your company. Odds are it will match up with some or all of your data needs.

Reference Link: http://searchcompliance.techtarget.com/tip/Is-your-SaaS-system-in-line-with-
SOX-compliance-requirements

More Related Content

More from williamsjohnseoexperts

Time bound customer service communication
Time bound customer service communicationTime bound customer service communication
Time bound customer service communication
williamsjohnseoexperts
 
Five common sense time management mistakes in project accounting — and tips t...
Five common sense time management mistakes in project accounting — and tips t...Five common sense time management mistakes in project accounting — and tips t...
Five common sense time management mistakes in project accounting — and tips t...
williamsjohnseoexperts
 
Entrepreneur interview curt finch, journyx
Entrepreneur interview curt finch, journyxEntrepreneur interview curt finch, journyx
Entrepreneur interview curt finch, journyx
williamsjohnseoexperts
 
REDUCING STRUCTURE FOR IMPROVED PERFORMANCE
REDUCING STRUCTURE FOR IMPROVED PERFORMANCE REDUCING STRUCTURE FOR IMPROVED PERFORMANCE
REDUCING STRUCTURE FOR IMPROVED PERFORMANCE
williamsjohnseoexperts
 
Understanding True CRM Costs before Implementing an Enterprise Solution
Understanding True CRM Costs before Implementing an Enterprise SolutionUnderstanding True CRM Costs before Implementing an Enterprise Solution
Understanding True CRM Costs before Implementing an Enterprise Solution
williamsjohnseoexperts
 
Compensation Compliance for Federal Contractors: The Rules Have Changed!
Compensation Compliance for Federal Contractors: The Rules Have Changed!Compensation Compliance for Federal Contractors: The Rules Have Changed!
Compensation Compliance for Federal Contractors: The Rules Have Changed!
williamsjohnseoexperts
 
Project portfolio management and what it means for your company
Project portfolio management and what it means for your companyProject portfolio management and what it means for your company
Project portfolio management and what it means for your company
williamsjohnseoexperts
 
How to Achieve Per-Project Profitability
How to Achieve Per-Project ProfitabilityHow to Achieve Per-Project Profitability
How to Achieve Per-Project Profitability
williamsjohnseoexperts
 
7 ways to get your company organized by simply tracking time
7 ways to get your company organized by simply tracking time7 ways to get your company organized by simply tracking time
7 ways to get your company organized by simply tracking time
williamsjohnseoexperts
 

More from williamsjohnseoexperts (20)

Time bound customer service communication
Time bound customer service communicationTime bound customer service communication
Time bound customer service communication
 
Five common sense time management mistakes in project accounting — and tips t...
Five common sense time management mistakes in project accounting — and tips t...Five common sense time management mistakes in project accounting — and tips t...
Five common sense time management mistakes in project accounting — and tips t...
 
Entrepreneur interview curt finch, journyx
Entrepreneur interview curt finch, journyxEntrepreneur interview curt finch, journyx
Entrepreneur interview curt finch, journyx
 
REDUCING STRUCTURE FOR IMPROVED PERFORMANCE
REDUCING STRUCTURE FOR IMPROVED PERFORMANCE REDUCING STRUCTURE FOR IMPROVED PERFORMANCE
REDUCING STRUCTURE FOR IMPROVED PERFORMANCE
 
PERFECT YOUR PARTNERSHIPS
PERFECT YOUR PARTNERSHIPSPERFECT YOUR PARTNERSHIPS
PERFECT YOUR PARTNERSHIPS
 
Understanding True CRM Costs before Implementing an Enterprise Solution
Understanding True CRM Costs before Implementing an Enterprise SolutionUnderstanding True CRM Costs before Implementing an Enterprise Solution
Understanding True CRM Costs before Implementing an Enterprise Solution
 
Death by interview
Death by interviewDeath by interview
Death by interview
 
Defining Web 2.0
Defining Web 2.0Defining Web 2.0
Defining Web 2.0
 
Compensation Compliance for Federal Contractors: The Rules Have Changed!
Compensation Compliance for Federal Contractors: The Rules Have Changed!Compensation Compliance for Federal Contractors: The Rules Have Changed!
Compensation Compliance for Federal Contractors: The Rules Have Changed!
 
Small Business News and Information
Small Business News and InformationSmall Business News and Information
Small Business News and Information
 
Getting beyond the water cooler
Getting beyond the water coolerGetting beyond the water cooler
Getting beyond the water cooler
 
Project portfolio management and what it means for your company
Project portfolio management and what it means for your companyProject portfolio management and what it means for your company
Project portfolio management and what it means for your company
 
JOURNYX IS MORE THAN A TIMESHEET
JOURNYX IS MORE THAN A TIMESHEETJOURNYX IS MORE THAN A TIMESHEET
JOURNYX IS MORE THAN A TIMESHEET
 
JOURNYX PINTEREST
JOURNYX PINTERESTJOURNYX PINTEREST
JOURNYX PINTEREST
 
How to Achieve Per-Project Profitability
How to Achieve Per-Project ProfitabilityHow to Achieve Per-Project Profitability
How to Achieve Per-Project Profitability
 
Bring Your Own… Communication?
Bring Your Own… Communication?Bring Your Own… Communication?
Bring Your Own… Communication?
 
Google drive and skydrive and dropbox
Google drive and skydrive and dropboxGoogle drive and skydrive and dropbox
Google drive and skydrive and dropbox
 
WE DID SOMETHING OUT OF THE ORDINARY
WE DID SOMETHING OUT OF THE ORDINARYWE DID SOMETHING OUT OF THE ORDINARY
WE DID SOMETHING OUT OF THE ORDINARY
 
Coordinating pm os and executives
Coordinating pm os and executivesCoordinating pm os and executives
Coordinating pm os and executives
 
7 ways to get your company organized by simply tracking time
7 ways to get your company organized by simply tracking time7 ways to get your company organized by simply tracking time
7 ways to get your company organized by simply tracking time
 

Recently uploaded

Chandigarh Escorts Service 📞8868886958📞 Just📲 Call Nihal Chandigarh Call Girl...
Chandigarh Escorts Service 📞8868886958📞 Just📲 Call Nihal Chandigarh Call Girl...Chandigarh Escorts Service 📞8868886958📞 Just📲 Call Nihal Chandigarh Call Girl...
Chandigarh Escorts Service 📞8868886958📞 Just📲 Call Nihal Chandigarh Call Girl...
Sheetaleventcompany
 
Russian Call Girls In Rajiv Chowk Gurgaon ❤️8448577510 ⊹Best Escorts Service ...
Russian Call Girls In Rajiv Chowk Gurgaon ❤️8448577510 ⊹Best Escorts Service ...Russian Call Girls In Rajiv Chowk Gurgaon ❤️8448577510 ⊹Best Escorts Service ...
Russian Call Girls In Rajiv Chowk Gurgaon ❤️8448577510 ⊹Best Escorts Service ...
lizamodels9
 
unwanted pregnancy Kit [+918133066128] Abortion Pills IN Dubai UAE Abudhabi
unwanted pregnancy Kit [+918133066128] Abortion Pills IN Dubai UAE Abudhabiunwanted pregnancy Kit [+918133066128] Abortion Pills IN Dubai UAE Abudhabi
unwanted pregnancy Kit [+918133066128] Abortion Pills IN Dubai UAE Abudhabi
Abortion pills in Kuwait Cytotec pills in Kuwait
 
FULL ENJOY Call Girls In Mahipalpur Delhi Contact Us 8377877756
FULL ENJOY Call Girls In Mahipalpur Delhi Contact Us 8377877756FULL ENJOY Call Girls In Mahipalpur Delhi Contact Us 8377877756
FULL ENJOY Call Girls In Mahipalpur Delhi Contact Us 8377877756
dollysharma2066
 
Call Girls in Delhi, Escort Service Available 24x7 in Delhi 959961-/-3876
Call Girls in Delhi, Escort Service Available 24x7 in Delhi 959961-/-3876Call Girls in Delhi, Escort Service Available 24x7 in Delhi 959961-/-3876
Call Girls in Delhi, Escort Service Available 24x7 in Delhi 959961-/-3876
dlhescort
 
Call Girls In Noida 959961⊹3876 Independent Escort Service Noida
Call Girls In Noida 959961⊹3876 Independent Escort Service NoidaCall Girls In Noida 959961⊹3876 Independent Escort Service Noida
Call Girls In Noida 959961⊹3876 Independent Escort Service Noida
dlhescort
 
Call Girls Kengeri Satellite Town Just Call 👗 7737669865 👗 Top Class Call Gir...
Call Girls Kengeri Satellite Town Just Call 👗 7737669865 👗 Top Class Call Gir...Call Girls Kengeri Satellite Town Just Call 👗 7737669865 👗 Top Class Call Gir...
Call Girls Kengeri Satellite Town Just Call 👗 7737669865 👗 Top Class Call Gir...
amitlee9823
 
Call Girls From Raj Nagar Extension Ghaziabad❤️8448577510 ⊹Best Escorts Servi...
Call Girls From Raj Nagar Extension Ghaziabad❤️8448577510 ⊹Best Escorts Servi...Call Girls From Raj Nagar Extension Ghaziabad❤️8448577510 ⊹Best Escorts Servi...
Call Girls From Raj Nagar Extension Ghaziabad❤️8448577510 ⊹Best Escorts Servi...
lizamodels9
 
Call Girls In Nangloi Rly Metro ꧂…….95996 … 13876 Enjoy ꧂Escort
Call Girls In Nangloi Rly Metro ꧂…….95996 … 13876 Enjoy ꧂EscortCall Girls In Nangloi Rly Metro ꧂…….95996 … 13876 Enjoy ꧂Escort
Call Girls In Nangloi Rly Metro ꧂…….95996 … 13876 Enjoy ꧂Escort
dlhescort
 
Nelamangala Call Girls: 🍓 7737669865 🍓 High Profile Model Escorts | Bangalore...
Nelamangala Call Girls: 🍓 7737669865 🍓 High Profile Model Escorts | Bangalore...Nelamangala Call Girls: 🍓 7737669865 🍓 High Profile Model Escorts | Bangalore...
Nelamangala Call Girls: 🍓 7737669865 🍓 High Profile Model Escorts | Bangalore...
amitlee9823
 

Recently uploaded (20)

Call Girls Zirakpur👧 Book Now📱7837612180 📞👉Call Girl Service In Zirakpur No A...
Call Girls Zirakpur👧 Book Now📱7837612180 📞👉Call Girl Service In Zirakpur No A...Call Girls Zirakpur👧 Book Now📱7837612180 📞👉Call Girl Service In Zirakpur No A...
Call Girls Zirakpur👧 Book Now📱7837612180 📞👉Call Girl Service In Zirakpur No A...
 
Falcon Invoice Discounting: Unlock Your Business Potential
Falcon Invoice Discounting: Unlock Your Business PotentialFalcon Invoice Discounting: Unlock Your Business Potential
Falcon Invoice Discounting: Unlock Your Business Potential
 
(Anamika) VIP Call Girls Napur Call Now 8617697112 Napur Escorts 24x7
(Anamika) VIP Call Girls Napur Call Now 8617697112 Napur Escorts 24x7(Anamika) VIP Call Girls Napur Call Now 8617697112 Napur Escorts 24x7
(Anamika) VIP Call Girls Napur Call Now 8617697112 Napur Escorts 24x7
 
Famous Olympic Siblings from the 21st Century
Famous Olympic Siblings from the 21st CenturyFamous Olympic Siblings from the 21st Century
Famous Olympic Siblings from the 21st Century
 
Chandigarh Escorts Service 📞8868886958📞 Just📲 Call Nihal Chandigarh Call Girl...
Chandigarh Escorts Service 📞8868886958📞 Just📲 Call Nihal Chandigarh Call Girl...Chandigarh Escorts Service 📞8868886958📞 Just📲 Call Nihal Chandigarh Call Girl...
Chandigarh Escorts Service 📞8868886958📞 Just📲 Call Nihal Chandigarh Call Girl...
 
Russian Call Girls In Rajiv Chowk Gurgaon ❤️8448577510 ⊹Best Escorts Service ...
Russian Call Girls In Rajiv Chowk Gurgaon ❤️8448577510 ⊹Best Escorts Service ...Russian Call Girls In Rajiv Chowk Gurgaon ❤️8448577510 ⊹Best Escorts Service ...
Russian Call Girls In Rajiv Chowk Gurgaon ❤️8448577510 ⊹Best Escorts Service ...
 
unwanted pregnancy Kit [+918133066128] Abortion Pills IN Dubai UAE Abudhabi
unwanted pregnancy Kit [+918133066128] Abortion Pills IN Dubai UAE Abudhabiunwanted pregnancy Kit [+918133066128] Abortion Pills IN Dubai UAE Abudhabi
unwanted pregnancy Kit [+918133066128] Abortion Pills IN Dubai UAE Abudhabi
 
FULL ENJOY Call Girls In Mahipalpur Delhi Contact Us 8377877756
FULL ENJOY Call Girls In Mahipalpur Delhi Contact Us 8377877756FULL ENJOY Call Girls In Mahipalpur Delhi Contact Us 8377877756
FULL ENJOY Call Girls In Mahipalpur Delhi Contact Us 8377877756
 
Falcon Invoice Discounting platform in india
Falcon Invoice Discounting platform in indiaFalcon Invoice Discounting platform in india
Falcon Invoice Discounting platform in india
 
Call Girls in Delhi, Escort Service Available 24x7 in Delhi 959961-/-3876
Call Girls in Delhi, Escort Service Available 24x7 in Delhi 959961-/-3876Call Girls in Delhi, Escort Service Available 24x7 in Delhi 959961-/-3876
Call Girls in Delhi, Escort Service Available 24x7 in Delhi 959961-/-3876
 
Call Girls Service In Old Town Dubai ((0551707352)) Old Town Dubai Call Girl ...
Call Girls Service In Old Town Dubai ((0551707352)) Old Town Dubai Call Girl ...Call Girls Service In Old Town Dubai ((0551707352)) Old Town Dubai Call Girl ...
Call Girls Service In Old Town Dubai ((0551707352)) Old Town Dubai Call Girl ...
 
Call Girls In Noida 959961⊹3876 Independent Escort Service Noida
Call Girls In Noida 959961⊹3876 Independent Escort Service NoidaCall Girls In Noida 959961⊹3876 Independent Escort Service Noida
Call Girls In Noida 959961⊹3876 Independent Escort Service Noida
 
Call Girls Kengeri Satellite Town Just Call 👗 7737669865 👗 Top Class Call Gir...
Call Girls Kengeri Satellite Town Just Call 👗 7737669865 👗 Top Class Call Gir...Call Girls Kengeri Satellite Town Just Call 👗 7737669865 👗 Top Class Call Gir...
Call Girls Kengeri Satellite Town Just Call 👗 7737669865 👗 Top Class Call Gir...
 
Call Girls From Raj Nagar Extension Ghaziabad❤️8448577510 ⊹Best Escorts Servi...
Call Girls From Raj Nagar Extension Ghaziabad❤️8448577510 ⊹Best Escorts Servi...Call Girls From Raj Nagar Extension Ghaziabad❤️8448577510 ⊹Best Escorts Servi...
Call Girls From Raj Nagar Extension Ghaziabad❤️8448577510 ⊹Best Escorts Servi...
 
Call Girls In Nangloi Rly Metro ꧂…….95996 … 13876 Enjoy ꧂Escort
Call Girls In Nangloi Rly Metro ꧂…….95996 … 13876 Enjoy ꧂EscortCall Girls In Nangloi Rly Metro ꧂…….95996 … 13876 Enjoy ꧂Escort
Call Girls In Nangloi Rly Metro ꧂…….95996 … 13876 Enjoy ꧂Escort
 
SEO Case Study: How I Increased SEO Traffic & Ranking by 50-60% in 6 Months
SEO Case Study: How I Increased SEO Traffic & Ranking by 50-60%  in 6 MonthsSEO Case Study: How I Increased SEO Traffic & Ranking by 50-60%  in 6 Months
SEO Case Study: How I Increased SEO Traffic & Ranking by 50-60% in 6 Months
 
Falcon Invoice Discounting: The best investment platform in india for investors
Falcon Invoice Discounting: The best investment platform in india for investorsFalcon Invoice Discounting: The best investment platform in india for investors
Falcon Invoice Discounting: The best investment platform in india for investors
 
Organizational Transformation Lead with Culture
Organizational Transformation Lead with CultureOrganizational Transformation Lead with Culture
Organizational Transformation Lead with Culture
 
Nelamangala Call Girls: 🍓 7737669865 🍓 High Profile Model Escorts | Bangalore...
Nelamangala Call Girls: 🍓 7737669865 🍓 High Profile Model Escorts | Bangalore...Nelamangala Call Girls: 🍓 7737669865 🍓 High Profile Model Escorts | Bangalore...
Nelamangala Call Girls: 🍓 7737669865 🍓 High Profile Model Escorts | Bangalore...
 
Lundin Gold - Q1 2024 Conference Call Presentation (Revised)
Lundin Gold - Q1 2024 Conference Call Presentation (Revised)Lundin Gold - Q1 2024 Conference Call Presentation (Revised)
Lundin Gold - Q1 2024 Conference Call Presentation (Revised)
 

Is your saas system in line with sox compliance requirements

  • 1. Is your SaaS system in line with SOX compliance requirements? Adoption rates for Software as a Service (SaaS) have grown exponentially in the past few years, and with reason. A SaaS vendor can help companies implement software more quickly and less expensively than IT systems that require local installs. Many SaaS products also allow universal access and real-time updates. The benefits of SaaS systems are numerous, but one overarching concern has hampered the potential for universal SaaS adoption: data security. Many businesses are uncomfortable with trusting their internal data to an external location and relying on a SaaS vendor’s infrastructure to keep information safe from corruption and theft. In addition, there are legal implications involved with storing company data off-site. Sarbanes-Oxley Act (SOX) compliance requirements stipulate that a company is fully responsible for its own data, regardless of whether the data is stored on-site or entrusted to an outside vendor. So how do you maximize the benefits of SaaS while minimizing the risk of data issues or legal trouble? SaaS and data security There is a major misconception related to SaaS -- that it’s more vulnerable than internally stored data systems. While it’s true that SaaS data can be compromised, it’s more accurate to view SaaS security threats as “different” rather than “more extensive.” In fact, in-house storage systems may be less secure than your average SaaS software. Whereas the SaaS vendor’s business model is built on data storage and security, these considerations are incidental for many other businesses. Also, consider the fact that in-house solutions require constant upkeep and maintenance, which the average IT personnel might have difficulty completing. Good SaaS vendors can eliminate this problem by offering regular updates and knowledgeable maintenance in the event of a malfunction. SOX compliance requirements are the concern for most publicly traded companies, particularly when it comes to financial data storage. The reason for this is very simple: A company’s signing officers are responsible for fair and complete financial statements to remain SOX compliant. If there is a discrepancy between reported and actual data, they could face severe punishments, up to and including jail time. Obviously, if such a company is considering external data storage that has any relation whatsoever to financial information, it’s going to require assurance that the data is secure. Fortunately, there are ways to check for that security and determine the trustworthiness of potential SaaS vendors.
  • 2. SAS 70: A cure for the common corruption If a company uses a SaaS vendor, that vendor should be required to submit a SAS 70 audit report. The SAS 70 report demonstrates the accuracy and completeness of a vendor’s internal controls. Further, it can obviate a company’s physical audit of said vendor, saving time and money. There are two types of SAS 70 audits: Type I and Type II. The Type I audit determines the adequacy of a SaaS vendor’s internal controls, and whether or not they have been fairly and completely described. Type II audits look at the same controls but take it further by testing them. A Type II audit is much sounder and may even be required by a company’s own auditors. But many vendors begin with a Type I audit and then undergo a Type II audit should the need arise. A company should examine the sensitivity of data being stored with a SaaS vendor, and then determine what type of audit is preferable. If it makes more sense, the company can conduct a Type II audit later. A SAS 70 report is an excellent method of evaluation, but it isn’t a substitute for a solid contract between a company and a SaaS vendor. In addition to making sure that auditors accept the report, a company must determine that the report has been read and understood. When it comes time to solidify a business relationship, a company might want to consider some of the following stipulations in the SaaS contract: Advanced warning of system notifications, along with set time requirements and who must be notified. Uptime percentage guarantees. Notification of outages, including a resolution plan and timetable. List of backup procedures. Tech support policies and procedures. Physical security procedures. Device and media controls. Use of system monitoring tools. Take these security measures into account, and SaaS should not pose a more significant threat than on-site data storage. If you have the opportunity to introduce SaaS systems into your organization, it is certainly worth the examination to determine the extent to which it can streamline your company. Odds are it will match up with some or all of your data needs. Reference Link: http://searchcompliance.techtarget.com/tip/Is-your-SaaS-system-in-line-with- SOX-compliance-requirements