<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xml:base="http://www.fastcompany.com" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
 <title></title>
 <link>http://www.fastcompany.com/member_recent_content/120925</link>
 <description>Member recent activity block for member profile page</description>
 <language>en</language>
<item>
 <title>MasterCard Site Data Protection Program (SDP) | Attention Merchants | PCI DSS </title>
 <link>http://www.fastcompany.com/blog/charles-denyer/sas-70-audits-resource-portal-type-i-type-ii-audits/mastercard-site-data-protect</link>
 <description>&lt;p&gt;MasterCard is now requiring both Level 1 and Level 2 Merchants to undertake an annual on-site assessment by a Qualified Security Assessor, known as a QSA. This is significant because there are a large number of Merchants that used to able to &quot;self assess&quot; with a self assessment questionnaire. This is no longer the case and merchants will have to become compliant with this new provision by December 31, 2010. &lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;http://www.fastcompany.com/blog/charles-denyer/sas-70-audits-resource-portal-type-i-type-ii-audits/mastercard-site-data-protect&quot;&gt;read more&lt;/a&gt;&lt;/p&gt;</description>
 <category domain="http://www.fastcompany.com/tag/mastercard-site-data-protection">MasterCard Site Data Protection</category>
 <category domain="http://www.fastcompany.com/tag/sdp">SDP</category>
 <category domain="http://www.fastcompany.com/tag/pci-dss">PCI DSS</category>
 <category domain="http://www.fastcompany.com/tag/merchants">merchants</category>
 <category domain="http://www.fastcompany.com/tag/level-2">Level 2</category>
 <category domain="http://www.fastcompany.com/tag/qualified-security-assessor">Qualified Security Assessor</category>
 <category domain="http://www.fastcompany.com/tag/qsa">QSA</category>
 <category domain="http://www.fastcompany.com/tag/payment-card-industry-data-security-standards">payment card industry data security standards</category>
 <category domain="http://www.fastcompany.com/tag-0" />
 <category domain="http://www.fastcompany.com/tag/technology-1">Technology</category>
 <category domain="http://www.fastcompany.com/tag/management-1">Management</category>
 <pubDate>Mon, 24 Aug 2009 16:33:26 -0400</pubDate>
 <dc:creator>charles denyer</dc:creator>
 <guid isPermaLink="false">1338149 at http://www.fastcompany.com</guid>
</item>
<item>
 <title>PCI Merchant Levels | What You Need to Know about PCI DSS Compliance</title>
 <link>http://www.fastcompany.com/blog/charles-denyer/sas-70-audits-resource-portal-type-i-type-ii-audits/pci-merchant-levels-what-you</link>
 <description>&lt;p&gt;For Merchants, there are essentially four (4) levels that any organization may fall into regarding compliance. If you fall into the Level 1 category, then be prepared to have an actual on-site Payment Card Industry Data Security Standards (PCI DSS) assessment conducted. The same can be said for Service Providers who have been identified as a Level 1.&lt;/p&gt;
&lt;p&gt;Follow these helpful links for learning all you need to about about the varying levels of compliance and what their specific requirements are:&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;http://www.fastcompany.com/blog/charles-denyer/sas-70-audits-resource-portal-type-i-type-ii-audits/pci-merchant-levels-what-you&quot;&gt;read more&lt;/a&gt;&lt;/p&gt;</description>
 <category domain="http://www.fastcompany.com/tag/merchants">merchants</category>
 <category domain="http://www.fastcompany.com/tag/service-providers">service providers</category>
 <category domain="http://www.fastcompany.com/tag/pci-dss">PCI DSS</category>
 <category domain="http://www.fastcompany.com/tag/payment-card-industry-data-security-standards">payment card industry data security standards</category>
 <category domain="http://www.fastcompany.com/tag/pci-merchant-levels">PCI merchant Levels</category>
 <category domain="http://www.fastcompany.com/tag/technology-1">Technology</category>
 <category domain="http://www.fastcompany.com/tag/management-1">Management</category>
 <pubDate>Wed, 08 Jul 2009 08:07:35 -0400</pubDate>
 <dc:creator>charles denyer</dc:creator>
 <guid isPermaLink="false">1305883 at http://www.fastcompany.com</guid>
</item>
<item>
 <title>SAS 70 Sample Report | Obtain an Example SAS 70 Type II Report to Learn about SAS 70 Audits</title>
 <link>http://www.fastcompany.com/blog/charles-denyer/sas-70-audits-resource-portal-type-i-type-ii-audits/sas-70-sample-report-obtain-</link>
 <description>&lt;p&gt;&lt;a title=&quot;Sampe and Example SAS 70 Type II audit report&quot; href=&quot;http://www.scribd.com/doc/17068540/Sample-SAS-70-Type-II-Audit-Report&quot;&gt;&lt;strong&gt;Obtaining a sample SAS 70 Type II Report &lt;/strong&gt;&lt;/a&gt;is quite simply the best and most practical way to truly learn and understand what a SAS 70 audit encompasses.&amp;nbsp; Many service organizations today are having to comply with the growing surge of regulatory compliance mandates, and &lt;a title=&quot;SAS 70 Resource Guide&quot; href=&quot;http://www.sas70.us.com&quot;&gt;&lt;strong&gt;SAS 70 Type II&lt;/strong&gt;&lt;/a&gt; compliance is quickly becoming one of the most common and well-recog&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;http://www.fastcompany.com/blog/charles-denyer/sas-70-audits-resource-portal-type-i-type-ii-audits/sas-70-sample-report-obtain-&quot;&gt;read more&lt;/a&gt;&lt;/p&gt;</description>
 <category domain="http://www.fastcompany.com/tag/sas-70-type-ii-sample-report">sas 70 type II sample report</category>
 <category domain="http://www.fastcompany.com/tag/sas-70-example-report-pdf">sas 70 example report in pdf</category>
 <category domain="http://www.fastcompany.com/tag/sas70">sas70</category>
 <category domain="http://www.fastcompany.com/tag/type-i">Type I</category>
 <category domain="http://www.fastcompany.com/tag/type-ii">Type II</category>
 <category domain="http://www.fastcompany.com/tag/charles-denyer">Charles Denyer</category>
 <category domain="http://www.fastcompany.com/tag/internal-controls">internal controls</category>
 <category domain="http://www.fastcompany.com/tag/technology-1">Technology</category>
 <category domain="http://www.fastcompany.com/tag/management-1">Management</category>
 <pubDate>Mon, 06 Jul 2009 11:33:23 -0400</pubDate>
 <dc:creator>charles denyer</dc:creator>
 <guid isPermaLink="false">1304697 at http://www.fastcompany.com</guid>
</item>
<item>
 <title>Comment on Node  ant</title>
 <link>http://www.fastcompany.com/comment/comment-node-ant-5729</link>
 <description>&lt;p&gt;great blog on sas 70&lt;/p&gt;
</description>
 <pubDate>Fri, 15 May 2009 15:35:23 -0400</pubDate>
 <dc:creator>charles denyer</dc:creator>
 <guid isPermaLink="false">1282150 at http://www.fastcompany.com</guid>
</item>
<item>
 <title>SAS 70 Audits | Advice on Scoping for Type I or Type II SAS 70 Compliance</title>
 <link>http://www.fastcompany.com/blog/charles-denyer/sas-70-audits-resource-portal-type-i-type-ii-audits/sas-70-audits-advice-scoping</link>
 <description>&lt;p&gt;Normal&lt;br /&gt;
0&lt;/p&gt;
&lt;p&gt;false&lt;br /&gt;
false&lt;br /&gt;
false&lt;/p&gt;
&lt;p&gt;EN-US&lt;br /&gt;
X-NONE&lt;br /&gt;
X-NONE&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;http://www.fastcompany.com/blog/charles-denyer/sas-70-audits-resource-portal-type-i-type-ii-audits/sas-70-audits-advice-scoping&quot;&gt;read more&lt;/a&gt;&lt;/p&gt;</description>
 <category domain="http://www.fastcompany.com/tag/sas-70">sas 70</category>
 <category domain="http://www.fastcompany.com/tag/type-i">Type I</category>
 <category domain="http://www.fastcompany.com/tag/sas-70-type-ii">SAS 70 Type II</category>
 <category domain="http://www.fastcompany.com/tag/cost-sas-70-audit">cost sas 70 audit</category>
 <category domain="http://www.fastcompany.com/tag/charles-denyer">Charles Denyer</category>
 <category domain="http://www.fastcompany.com/tag/cpa">CPA</category>
 <category domain="http://www.fastcompany.com/tag-0" />
 <category domain="http://www.fastcompany.com/tag/innovation-2">Innovation</category>
 <category domain="http://www.fastcompany.com/tag/technology-1">Technology</category>
 <category domain="http://www.fastcompany.com/tag/leadership-2">Leadership</category>
 <category domain="http://www.fastcompany.com/tag/management-1">Management</category>
 <pubDate>Fri, 15 May 2009 15:34:25 -0400</pubDate>
 <dc:creator>charles denyer</dc:creator>
 <guid isPermaLink="false">1282148 at http://www.fastcompany.com</guid>
</item>
<item>
 <title>SAS 70 Certification | Expert Advice on Pricing and Audit Scope | Type I and Type II Audits</title>
 <link>http://www.fastcompany.com/blog/charles-denyer/sas-70-audits-resource-portal-type-i-type-ii-audits/sas-70-certification-expert-</link>
 <description>&lt;p&gt;
&lt;a href=&quot;http://www.slideshare.net/sas70pciauditor/sas-70&quot; title=&quot;sas 70 certification&quot;&gt;SAS 70&lt;/a&gt; certification (more technically known as SAS 70 &amp;quot;compliance&amp;quot;) is gaining momentum and recognition in many industries today. The growth of regulatory compliance, security and governance has pushed SAS 70 audits to the forefront of business, and it&#039;s not going away.  Rather, we will continue to see a upswing in SAS 70 audits performed on organizations along with growth in almost any type of audit or assessment revolving around internal controls.
&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;http://www.fastcompany.com/blog/charles-denyer/sas-70-audits-resource-portal-type-i-type-ii-audits/sas-70-certification-expert-&quot;&gt;read more&lt;/a&gt;&lt;/p&gt;</description>
 <category domain="http://www.fastcompany.com/tag/sas-70-certification">sas 70 certification</category>
 <category domain="http://www.fastcompany.com/tag/sas70-type-i">sas70 type i</category>
 <category domain="http://www.fastcompany.com/tag/charles-denyer">Charles Denyer</category>
 <category domain="http://www.fastcompany.com/tag/type-ii-audits">Type II audits</category>
 <category domain="http://www.fastcompany.com/tag-0" />
 <category domain="http://www.fastcompany.com/tag/technology-1">Technology</category>
 <category domain="http://www.fastcompany.com/tag/management-1">Management</category>
 <pubDate>Thu, 07 May 2009 16:43:39 -0400</pubDate>
 <dc:creator>charles denyer</dc:creator>
 <guid isPermaLink="false">1279015 at http://www.fastcompany.com</guid>
</item>
<item>
 <title>PCI Merchant Levels  for VISA | Expert Advice from a PCI DSS Assessor</title>
 <link>http://www.fastcompany.com/blog/charles-denyer/sas-70-audits-resource-portal-type-i-type-ii-audits/pci-merchant-levels-visa-exp</link>
 <description>&lt;p&gt;&lt;span&gt;Listed below ar the PCI Merchant Levels for VISA.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;http://www.fastcompany.com/blog/charles-denyer/sas-70-audits-resource-portal-type-i-type-ii-audits/pci-merchant-levels-visa-exp&quot;&gt;read more&lt;/a&gt;&lt;/p&gt;</description>
 <category domain="http://www.fastcompany.com/tag/pci-merchant-levels">PCI merchant Levels</category>
 <category domain="http://www.fastcompany.com/tag/visa">visa</category>
 <category domain="http://www.fastcompany.com/tag/mastercard">MasterCard</category>
 <category domain="http://www.fastcompany.com/tag/american-express">American Express</category>
 <category domain="http://www.fastcompany.com/tag/discover-card">Discover Card</category>
 <category domain="http://www.fastcompany.com/tag/jcb">JCB</category>
 <category domain="http://www.fastcompany.com/tag/charles-denyer">Charles Denyer</category>
 <category domain="http://www.fastcompany.com/tag/pci-qsa">PCI QSA</category>
 <category domain="http://www.fastcompany.com/tag/pci-merchant-transaction-levels">PCI Merchant Transaction Levels</category>
 <category domain="http://www.fastcompany.com/tag/technology-1">Technology</category>
 <category domain="http://www.fastcompany.com/tag/management-1">Management</category>
 <pubDate>Fri, 10 Apr 2009 21:38:44 -0400</pubDate>
 <dc:creator>charles denyer</dc:creator>
 <guid isPermaLink="false">1263599 at http://www.fastcompany.com</guid>
</item>
<item>
 <title>SAS 70 Control Objectives | Expert Advice from a SAS 70 Auditor</title>
 <link>http://www.fastcompany.com/blog/charles-denyer/sas-70-audits-resource-portal-type-i-type-ii-audits/sas-70-control-objectives-e-0</link>
 <description>&lt;p&gt;
SAS 70 control objectives are essentially the statements and assertions that your organization is adhering to for purposes of a SAS 70 audit. In simpler terms, they are the cornerstone of the audit that help frame the overall auditing process that is undertaken.  Thus, whatever your control objective states,  your organization should be able to prove that very assertion. 
&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;http://www.fastcompany.com/blog/charles-denyer/sas-70-audits-resource-portal-type-i-type-ii-audits/sas-70-control-objectives-e-0&quot;&gt;read more&lt;/a&gt;&lt;/p&gt;</description>
 <category domain="http://www.fastcompany.com/tag/sas-70-control-objectives">sas 70 control objectives</category>
 <category domain="http://www.fastcompany.com/tag/charles-denyer">Charles Denyer</category>
 <category domain="http://www.fastcompany.com/tag/sas-70-type-i">sas 70 Type I</category>
 <category domain="http://www.fastcompany.com/tag/type-ii">Type II</category>
 <category domain="http://www.fastcompany.com/tag/sample-sas-70-audit-report">sample SAS 70 audit report</category>
 <category domain="http://www.fastcompany.com/tag/technology-1">Technology</category>
 <category domain="http://www.fastcompany.com/tag/management-1">Management</category>
 <pubDate>Wed, 01 Apr 2009 15:32:39 -0400</pubDate>
 <dc:creator>charles denyer</dc:creator>
 <guid isPermaLink="false">1255988 at http://www.fastcompany.com</guid>
</item>
<item>
 <title>SAS 70 Control Objectives | Expert Advice from a SAS 70 Auditor</title>
 <link>http://www.fastcompany.com/blog/charles-denyer/sas-70-audits-resource-portal-type-i-type-ii-audits/sas-70-control-objectives-ex</link>
 <description>&lt;p&gt;
SAS 70 control objectives are essentially the statements and assertion that your organization are adhering to for purposes of a SAS 70 audit. In simpler terms, they are the cornerstone of the audit that help frame the overall auditing process that is undertaken. 
&lt;/p&gt;
&lt;p&gt;
A number of best of breed, predefined control objectives are currently utilized by CPA firms who conduct SAS 70 audits. Sure, they may differ in how they are actually stated, but in reality, they &amp;quot;should&amp;quot; be similiar in application.
&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;http://www.fastcompany.com/blog/charles-denyer/sas-70-audits-resource-portal-type-i-type-ii-audits/sas-70-control-objectives-ex&quot;&gt;read more&lt;/a&gt;&lt;/p&gt;</description>
 <category domain="http://www.fastcompany.com/tag/charles-denyer">Charles Denyer</category>
 <category domain="http://www.fastcompany.com/tag/sas-70-sample-report">sas 70 sample report</category>
 <category domain="http://www.fastcompany.com/tag/sas-70-control-objectives">sas 70 control objectives</category>
 <category domain="http://www.fastcompany.com/tag/type-i">Type I</category>
 <category domain="http://www.fastcompany.com/tag/type-ii-audit">type II audit</category>
 <category domain="http://www.fastcompany.com/tag/control-objectives">control objectives</category>
 <category domain="http://www.fastcompany.com/tag-0" />
 <category domain="http://www.fastcompany.com/tag/technology-1">Technology</category>
 <category domain="http://www.fastcompany.com/tag/management-1">Management</category>
 <pubDate>Wed, 01 Apr 2009 15:30:39 -0400</pubDate>
 <dc:creator>charles denyer</dc:creator>
 <guid isPermaLink="false">1255984 at http://www.fastcompany.com</guid>
</item>
<item>
 <title>SAS 70 Controls for Type I and Type II Audits | What you Need to Know</title>
 <link>http://www.fastcompany.com/blog/charles-denyer/sas-70-audits-resource-portal-type-i-type-ii-audits/sas-70-controls-type-i-and-t</link>
 <description>&lt;p&gt;
&lt;a href=&quot;http://www.sas70.us.com&quot; title=&quot;SAS 70 Resource Guide&quot;&gt;&lt;strong&gt;As a SAS 70 auditor&lt;/strong&gt;&lt;/a&gt;, i&#039;m often asked about SAS 70 controls, that is, what are they, how do you develop them, are their industry benchmarks and best of breed controls currently in use, etc.?  All good questions, no doubt. However, with that said, there are a number of key themes you need to be aware of regarding SAS 70 controls, and they are:
&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;http://www.fastcompany.com/blog/charles-denyer/sas-70-audits-resource-portal-type-i-type-ii-audits/sas-70-controls-type-i-and-t&quot;&gt;read more&lt;/a&gt;&lt;/p&gt;</description>
 <category domain="http://www.fastcompany.com/tag/sas-70-controls">sas 70 controls</category>
 <category domain="http://www.fastcompany.com/tag/type-i">Type I</category>
 <category domain="http://www.fastcompany.com/tag/type-ii-audits">Type II audits</category>
 <category domain="http://www.fastcompany.com/tag/control-objectives">control objectives</category>
 <category domain="http://www.fastcompany.com/tag/charles-denyer">Charles Denyer</category>
 <category domain="http://www.fastcompany.com/tag/third-party-administrator">Third Party Administrator</category>
 <category domain="http://www.fastcompany.com/tag/tpa">TPA</category>
 <category domain="http://www.fastcompany.com/tag/technology-1">Technology</category>
 <category domain="http://www.fastcompany.com/tag/management-1">Management</category>
 <pubDate>Sun, 29 Mar 2009 09:06:16 -0400</pubDate>
 <dc:creator>charles denyer</dc:creator>
 <guid isPermaLink="false">1247248 at http://www.fastcompany.com</guid>
</item>
</channel>
</rss>
