Is your cloud provider "SAS 70 compliant" and is that even correct? How is cardholder data protected in the cloud and is PCI compliance even possible? And what about that seemingly unattainable ISO 27001 certification?
If you have spent anytime considering cloud services, you have likely heard the terms SAS 70, PCI DSS, and ISO 27001. These are the most common assessments undertaken by cloud providers today. What started as mandated audit requirements have evolved and expanded to become tools that cloud providers use to differentiate themselves in the marketplace.
Link to this comment:
All Comments (0)