Contact Us
Services
Services
Crypto and Digital Trust
Crypto and Digital Trust
Schellman Training
Schellman Training
Sustainability Services
Sustainability Services
AI Services
AI Services
About Us
About Us
Leadership Team
Leadership Team
Corporate Social Responsibility
Corporate Social Responsibility
Careers
Careers
Strategic Partnerships
Strategic Partnerships

The Schellman Blog

Blog Feature

SOC Examinations

By: Ryan Buckner
March 1st, 2014

In my line of work, it is not only advisable to have a mastery of the facts, but prudence would suggest that a good dose of foresight and reason based on actual experience can often times be as valuable a tool. Since the days of the SAS 70, we have seen several subjective opinions about both the appropriateness and/or the ineffectiveness of the SAS 70 report. Even today, there continues to be concerns on how SOC 1 reports, also known as SSAE 16 examinations, are being used in situations that fail to have bearing on internal controls over financial reporting.

Blog Feature

Education | ISO Certifications

By: Ryan Mackie
December 9th, 2013

Undoubtedly, the ISO 27001 Certification is recognized globally and revered as one of the highest and most comprehensive certifications an organization can attain. The high esteem that the certification is held is substantiated by the effort and dedication that is required by an organization to attain ISO 27001 certification. As an internationally accepted certification, ISO 27001 represents an organization's ability to effectively manage information security risks with a certified information security management system (ISMS).

Blog Feature

Cloud Computing | Payment Card Assessments

By: Douglas Barbin
April 11th, 2013

By Eric Sampson and Doug Barbin In a previous article, we provided a summary of the key components of the PCI DSS Cloud Computing Guidelines (“cloud supplement”). That article focused on roles, responsibilities, agreements, and audit considerations. This article speaks more to the technical considerations.

Blog Feature

Cloud Computing | SOC Examinations

By: Douglas Barbin
December 17th, 2012

DevOps, like Agile development before it, accents the continuous evolving state of software development, particularly in cloud-base software. Like any technology change, there is no surprise that auditor and security professionals are challenged as the traditional separation of duties become more and more gray. As someone who oversaw product management in an Agile / SaaS development environment and now manages audits and certifications for leading edge cloud solution providers, I offer my perspective.

Blog Feature

Cloud Computing | FedRAMP | Federal Assessments

By: Douglas Barbin
August 9th, 2012

I am delighted that Schellman is now an accredited FedRAMP 3rd Party Assessment Organization (3PAO). This is a testament to our extensive experience in the cloud service provider (CSP) space and the qualifications and experience of a licensed CPA firm, PCI QSA company, and ISO 27001 certification body.

Blog Feature

ISO Certifications | TPRM

By: Jenelle Tamura
April 26th, 2012

If your organization is seeking ISO 27001 certification, and you outsource physical hosting to a third-party vendor, you may be wondering if and how to include them in the scope of your Information Security Management System (ISMS).

Blog Feature

Cloud Computing | ISO Certifications | SOC Examinations

By: Ryan Buckner
May 23rd, 2011

In October, I posted an article on the various alternatives for CPA attestation reports. This past week, the AICPA issued its guidance on Service Organization Controls (SOC) 2 reports and an update to that post was in order. Here is what the newly released SOC 2 guidance states:

{