Search
Topics
  Create an account Home  ·  Topics  ·  Downloads  ·  Your Account  ·  Submit News  ·  Top 10  
Modules
· Home
· Downloads
· FAQ
· Feedback
· Forums
· Papers
· Statistics
· Surveys
· Top 10
· Topics
· Web Links
· Your Account

Who's Online
There are currently, 16 guest(s) and 0 member(s) that are online.

You are Anonymous user. You can register for free by clicking here

ISO17799 Search



Languages
Select Interface Language:


ISO 17799 Resources
There are now quite a few BS7799, ISO27001 and ISO 17799 portals on the web offering commercial tools & products. Possibly the most complete is ISO 17799 and ISO 27001 Central.

Call for Papers
We are shortly to launch a content section for papers and articles on ISO 17799 implementation, BS7799, AS4444, ISO 27001, UNE71502, and information security generally. If you have produced a paper and would like us to publish it, please contact us via the feedback form above.

ISO 27001, ISO 27002 & ISO17799 User Group: Forums

17799.Com :: View topic - ISO27001/BS7799 Certification vs Sarbox Compliance
 Forum FAQForum FAQ   SearchSearch   UsergroupsUsergroups   ProfileProfile   Log in to check your private messagesLog in to check your private messages   Log inLog in 

ISO27001/BS7799 Certification vs Sarbox Compliance

 
Post new topic   Reply to topic    17799.Com Forum Index -> ISO17799 Discussion and Debate
View previous topic :: View next topic  
Author Message
Lou
Newbie
Newbie


Joined: Jun 21, 2006
Posts: 2

PostPosted: Thu Jun 22, 2006 1:52 am    Post subject: ISO27001/BS7799 Certification vs Sarbox Compliance Reply with quote

Can anyone name an authoritative source that says that an ISO27001/BS7799 certification is an acceptable alternative to a SAS70 for Sarbox compliance purposes?
Back to top
View user's profile
Calvin
Newbie
Newbie


Joined: Aug 30, 2005
Posts: 39

PostPosted: Thu Jun 22, 2006 3:04 am    Post subject: Reply with quote

I dont think such a source exist as ISO27001/BS7799 is not considered equivalent to SAS70 type I or II for SOX compliance.
Back to top
View user's profile
Lou
Newbie
Newbie


Joined: Jun 21, 2006
Posts: 2

PostPosted: Thu Jun 22, 2006 3:32 am    Post subject: Reply with quote

Then is there an authoritative source that says that?
Back to top
View user's profile
schellman
Newbie
Newbie


Joined: Oct 05, 2006
Posts: 1

PostPosted: Fri Oct 06, 2006 1:27 am    Post subject: Reply with quote

Yes, there is. PCAOB Audit Standard 2, which is freely available for download at pcaobus.org. It identifies a service auditors report (which is a type 2 SAS 70 report in the United States) as being the only acceptable report for inter-auditor communication. An ISO or BS 7799 certification has a completely different purpose, and does not necessarily address control objectives that are relavant to user organizations' internal controls over financial reporting. At best, it would only be good for informational purposes to a third party. Financial statement auditors would be prohibited from using any security "certification" for assessing control risk or SOX financial reporting controls.

There are also authoritative sources in the auditing world, but I will spare you the details.

I hope this helps.

Chris Schellman, CPA, CIA, CISA
Co-Founder
SAS 70 Solutions, Inc.
Back to top
View user's profile Visit poster's website
mcarecho
Newbie
Newbie


Joined: Oct 17, 2009
Posts: 1

PostPosted: Sun Oct 18, 2009 11:20 am    Post subject: SAS 70 vs ISO 27001 ????? Reply with quote

Could someone help me in order to know if I am able to use the ISO 27001 controls objectives for the SAS 70.
Actualy the company I work for has been ISO 27001 certified by the last month and for the following month it will be audit for the SAS 70.

I am trying to understand whether we could use the same controls objectives of the ISO 27001 for the SAS 70 IT general contols since 27001 is a very abroad standard?

You may also answer to my personal e-mail: marianacarecho@gmail.com

Regards,
MC
Back to top
View user's profile
Display posts from previous:   
Post new topic   Reply to topic    17799.Com Forum Index -> ISO17799 Discussion and Debate All times are GMT + 10 Hours
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum

Powered by phpBB 2.0.8 © 2001 phpBB Group
phpBB port v2.1 based on Tom Nitzschner's phpbb2.0.6 upgraded to phpBB 2.0.4 standalone was developed and tested by:
ArtificialIntel, ChatServ, mikem,
sixonetonoffun and Paul Laudanski (aka Zhen-Xjell).

Version 2.1 by Nuke Cops © 2003 http://www.nukecops.com

Forums ©

 
The ISO 17799 Implementation Forum: A BS7799 / ISO27001, ISO17799 and ISO 27000 User Group
All logos and trademarks are property of their respective owner. Comments are property of their posters. The rest © 2005 ISO17799 / ISO 27002 Forum
AKA: BS 7799, SPE 20003, SS 627799, JIS X 5080, AS/NZS 4444, ISO 27001. Other links: UKAS accreditation body. SV
Website source phpnuke.org (c) 2003, and is Free Software under GNU / GPL licence. All Rights Are Reserved.