Compliance for Managed Service Providers
Managed service providers have become a popular option for companies in order to outsource their day-to-day IT management responsibilities as a strategic way to improve operations. The increased outsourcing of IT operations has escalated the need for managed service providers to obtain a third-party assurance over the controls for security, privacy and regulatory compliance.
Today companies are outsourcing everything from production support to lifecycle build/maintenance activities to managed service providers. These activities are relevant to internal controls over the financial reporting of the managed service provider’s customers and should be examined under the SSAE 18 standard for SOC 1®. ‘Services that are relevant to internal controls over financial reporting’ can range from providing access controls over financial data to recording or manipulating financial data for the user organization.
Managed Service Provider’s SOC 1® attestation involves the following critical areas:
- Control Environment: the organizational level controls also known as “tone at the top” which consists of management’s oversight and internal operational level controls.
- Physical Security: the protection of information systems as it relates to third party data.
- Environmental Security: the protection of information systems and data from environmental threats.
- Data backups: the availability and protection of third parties’ data.
- System Availability: the availability of information systems to user organizations.
- Application Change Control: the processing and procedures used to ensure that systems function per user requirements.
- Information Security: the logical protection of data from unauthorized system access.
- Data Communication: the data maintains its integrity and security as it is transmitted between third parties and the service organization.
The scope of the SOC 1® attestation is determined by the managed service provider. Accordingly, a well scoped attestation can clearly demonstrate your organization’s quality of service and ensure that sufficient information is provided to your user organization to communicate your stringent controls over physical security, environmental security, authorized access and continuous availability of services.
SOC 1 Compliance Process
We tailor every attestation engagement to our client’s requirements. However, we have a fundamental four phase process that normally meets our clients’ needs and creates an efficient, unobtrusive attestation that enables you to focus on your business while we focus on your compliance.
Project Timeline: Four Phase Attestation
For More Information Speak to a Service Auditor at Roosa CPA, LLC (877) 410-8516