Create an account Home  ·  Topics  ·  Downloads  ·  Your Account  ·  Submit News  ·  Top 10  
Modules
· Home
· Content
· Directory
· Downloads
· FAQ
· Forums
· Search
· Sox_Admin
· Statistics
· Submit News
· Surveys
· Top 10
· Your Account

Sarbox Compliance
The appropriately named Sarbanes-Oxley Compliance Toolkit includes a whole range of materials specifically put together to both introduce, and take you through this most important of legislation.

For detailed information see the toolkit's own website: Sarbanes-Oxley Compliance


SOX Act and Security
As security is such a major theme on the Act, many organizations are using the international ISO standards. The ISO 27001 Portal outlines these. A copy of the standards, and security policies, can be obtained via the ISO 17799 Toolkit.

The SOX email storage requirements can be fulfilled using the GFI MailArchiver


SOX Advertisers


Sarbanes What?
Our server logs indicate some interesting mis-spellings: Sarbannes Oxley, Sorbane Oxley, Sarbanne Oxley, Sarbaines Oxley, Sarbanesoxley, Sorbanes Oxley, Sabanes Oxley, Sarbane Oxley, and Sarbanes Oaxley, to name but a few!

Sarbanes-Oxley Act Forum: Forums

The Sarbanes Oxley Act :: View topic - SAS70 requirements
 Forum FAQForum FAQ   SearchSearch   UsergroupsUsergroups   ProfileProfile   Login to check your private messagesLogin to check your private messages   LoginLogin 

SAS70 requirements

 
Post new topic   Reply to topic    The Sarbanes Oxley Act Forum Index -> Sarbanes-Oxley: IT Issues
View previous topic :: View next topic  
Author Message
mmouse
Newbie
Newbie


Joined: Jan 15, 2010
Posts: 1

PostPosted: Fri Jan 15, 2010 2:46 am    Post subject: SAS70 requirements Reply with quote

We have received an SAS70 type II report compared to our other SAS70 report in this report the user consideration section is missing. I thought this section was a requirement for SAS70. Does anyone know whether this is a requirement or not?

Also the testing period is untill the end of november instead of december; we have requested a confirmation letter on december but the auditor told us that that's no requirement. Does anyone know whether this is a requirement or not?
Back to top
View users profile
NC_Sox
Soxer
Soxer


Joined: Oct 06, 2009
Posts: 28
Location: USA

PostPosted: Mon Jan 18, 2010 8:08 am    Post subject: Reply with quote

My understanding is that the SAS 70 report must be completed close enough to your company's year-end that the third-party controls described in the report can be expected to remain in place at the end of your company's fiscal year.

Interesting about the absence of a User Control Considerations section. I don't believe I've run across one that didn't include that. Maybe someone else has seen this before. If it truly doesn't have this, then you may not be able to rely on the SAS 70 and may need to perform your own testing of this process.
Back to top
View users profile
gmerkl
MasterSoxer
MasterSoxer


Joined: May 26, 2008
Posts: 187
Location: Switzerland

PostPosted: Tue Jan 19, 2010 11:47 am    Post subject: User considerations in an SAS 70 report. Reply with quote

You can check SAS 70 on the PCAOB website at pcaobus.org/standards/interim_standards/auditing_standards/au_324.html

Section 54 says that it should be assumed that the report contains an attachment that includes a description of the service organization's controls that may be relevant to a user organization's internal control as it relates to an audit of financial statements.

Is that what you are looking for?
Back to top
View users profile


Display posts from previous:   
Post new topic   Reply to topic    The Sarbanes Oxley Act Forum Index -> Sarbanes-Oxley: IT Issues All times are GMT - 6 Hours
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
Forums ©

 
Trademarks referenced on the SOX Act Forum are property of their respective owners. Comments are property of their respective posters.
Sarbanes-Oxley Act Implementation Portal: Sarbanes Oxley compliance, information, software, & internal audit committee resources. Sarbox.
Site source is copyright nuke (c)2003, and is Free Software under the GNU / GPL licence agreement. All Rights Are Reserved.