Most CSPs are not forthcoming with their audit results
I’m starting to wonder if a secure cloud is like pornography—it’s very hard to define but you’ll know it when you see it. To this end, I was discussing cloud security with an executive from Telx last week. We were talking about how cloud service providers (CSP) often use their SAS-70 audited colocation facilities. This got me thinking about the SAS-70 label and how it might tell you a lot about the colocation facility security and potentially very little about the security of the CSP.
It was a Homer Simpson “Doh!” moment for me, since SAS-70 is one of the only ways to gain visibility into the efficacy of the CSPs security controls, especially since SAS-70 only evaluates in-place controls. The good news is that a quick review of a SAS-70 audit will clearly define its scope. SAS-70 audits typically consist of five major sections, including:
-Control environment: organizational, process, chain of command and internal audit effectiveness
-Risk assessment: management and preparation for all potential risks
-Control activities: policies and procedures to make sure managements’ response to risk is planned and acted upon
-Information/Communication: information processing, control and distribution
-Monitoring: monitoring of controls and maintaining status at all times
The reality is we don’t really know the scope of most CSP SAS-70 audits since most CSPs are not forthcoming with their audit results. As a prospective cloud provider, we must push CSPs to disclose their audit findings as a precursor to entering into a commercial agreement.




