Compliance for Colocation Services & Data Centers
Colocation services and data centers have become a popular option for companies with midsize IT needs because it allows the company’s IT staff to focus on the actual work being done, instead of the infrastructure needed to support the system. The increased outsourcing of IT infrastructure has escalated the need for colocation and data centers to obtain a third-party assurance over the controls for security, privacy and regulatory compliance.
In the latter half of 2011 when the AICPA released its Service Organization Controls reporting structure, some believed that the new SOC 2® concept would play a prominent role in reporting the controls for data centers. In part this belief was because the new SOC 2® concept provided guidance to service organizations that wanted to provide their customers with assurance about controls that did not affect their customers’ internal controls over financial reporting. Some people in the compliance industry made the argument that internal controls of data centers had no relevance to internal controls over the financial reporting of another company. A detailed review of the standards reveals that this argument is lacking authoritative support; the AICPA’s SOC 1® directly contradicts this argument when it provides examples of valid candidates, such as Internet service providers, web hosting providers and application service provider (including those that provide services similar to traditional mainframe data center service bureaus).
Bottom line is if your colocation or data center performs outsourced services that are relevant to internal controls over the financial reporting of another company; your organization should be examined under the SSAE 18 standard for SOC 1®. ‘Services that are relevant to internal controls over financial reporting’ can range from providing access controls over financial data to recording or manipulating financial data for the user organization. In the remote situation where your colocation or data center is performing outsourced services that are not relevant to internal controls over the financial reporting of your customers, the logical choice for your attestation would be the SOC 2® standard.
Colocation and Data Center’s SOC 1® attestation involves the following critical areas:
- Control Environment: the organizational level controls also known as “tone at the top” which consists of management’s oversight and internal operational level controls.
- Physical Security: the protection of information systems as it relates to third party data.
- Environmental Security: the protection of information systems and data from environmental threats.
- Network Support: the network services are designed and monitored to ensure network availability.
Colocation and data centers not involved in internal controls over the financial reporting for their customers can meet their customers’ compliance requirements by obtaining a SOC 2® service auditor’s report.
Colocation and Data Center’s SOC 2® attestation involves the following critical areas:
- Security: the system is protected against unauthorized access (both physical and logical).
- Availability: the system is available for operation and use as committed or agreed.
- Processing Integrity: system processing is complete, accurate, timely and authorized.
- Confidentiality: information designated as confidential is protected as committed or agreed.
- Privacy: personal information is collected, used, retained, disclosed and destroyed in conformity with commitments in the organization’s privacy notice and with criteria set forth in generally accepted privacy principle issued by the AICPA and CICA.
The scope of the SOC 1® and SOC 2® attestations are determined by the colocation and data center. Accordingly, a well scoped attestation can clearly demonstrate your organization’s quality of service and ensure that sufficient information is provided to your user organizations to communicate your stringent controls over physical security, environmental security, authorized access and continuous availability of services.
Compliance Process
We tailor every attestation engagement to our client’s requirements. However, we have a fundamental four phase process that normally meets our clients’ needs and creates an efficient, unobtrusive attestation engagement that enables you to focus on your business while we focus on your compliance.
Project Timeline: Four Phase Attestation
For More Information Speak to a Service Auditor at Roosa CPA, LLC (877) 410-8516